From d175d1be525edd8fb6140680c31425c8a89cc244 Mon Sep 17 00:00:00 2001 From: raja-grewal Date: Sun, 2 Nov 2025 15:54:34 +1100 Subject: [PATCH] Add doc on entropy related failure on AMD Zen 5 CPUs --- etc/default/grub.d/40_kernel_hardening.cfg#security-misc-shared | 1 + 1 file changed, 1 insertion(+) diff --git a/etc/default/grub.d/40_kernel_hardening.cfg#security-misc-shared b/etc/default/grub.d/40_kernel_hardening.cfg#security-misc-shared index fac7117..5af1493 100644 --- a/etc/default/grub.d/40_kernel_hardening.cfg#security-misc-shared +++ b/etc/default/grub.d/40_kernel_hardening.cfg#security-misc-shared @@ -306,6 +306,7 @@ GRUB_CMDLINE_LINUX="$GRUB_CMDLINE_LINUX efi=disable_early_pci_dma" ## https://lkml.org/lkml/2022/6/5/271 ## https://lwn.net/Articles/961121/ ## https://lore.kernel.org/lkml/aPFDn-4Cm6n0_3_e@gourry-fedora-PF4VCD3F/ +## https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html ## ## KSPP=yes ## KSPP sets CONFIG_RANDOM_TRUST_BOOTLOADER=y and CONFIG_RANDOM_TRUST_CPU=y.