Comment 156 for bug 1040557

Revision history for this message
Arthur P. Meiners (a-p-meiners) wrote :

I don't know the full details, but believe the bug was triggered by part of the BIOS which came from an OEM for part of the hardware in these computers. If that is the case, it could be the same bug. What makes this bug so critical to fix is indeed that it is not Ubuntu which is the cause, that it can be triggered from user space. Probably these BIOS have a recognizable "fingerprint", and therefor this vulnerability could be exploited with just a few lines of code to specifically target whole series of computers. So best to certainly raise awareness with Lenovo and make sure they figure out whether it is indeed the same issue, or a similar issue, and get it fixed.