Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Devastating Speculative Execution Intel CPU Bug
#69
https://techreport.com/news/3469107/unfi...ntel-cpus/
Quote:A little over a month ago, we reported on a speculative execution vulnerability found in Intel CPUs, adding to the growing list of similar vulnerabilities. However, yesterday, a team of security researchers revealed a new kind of vulnerability in Intel CPUs. Positive Technologies published a blog post detailing a flaw in Intel’s Converged Security and Management Engine (CSME) firmware.

This flaw is located in the Read-Only-Memory (ROM), which means it is hard-coded and so cannot be fixed. This feature of the vulnerability sets it apart from all the speculative execution vulnerabilities, which can be patched. That said, according to the blog post, when the security group reached out to Intel in order to report the vulnerability, they found that Intel already knew about the vulnerability and was attempting to address it. The vulnerability was registered last year in the Common Vulnerabilities and Exposures system as CVE-2019-0090, and has a vulnerability score of 7.1 (high).

https://www.tomshardware.com/news/load-v...ntel-chips
Quote:Intel's chips have faced an onslaught of new vulnerabilities discovered by crafty researchers, and today finds the company facing yet another new flaw, Load Value Injection (LVI), that a press release from Bitdefender describes as "particularly devastating" for servers in the data center. LVI impacts all Core families spanning from the third-generation Ivy Bridge chips to the 10th-generation Comet Lake processors.

According to statements from the researchers to ZDNet, the attack builds upon the Meltdown vulnerabilities that Intel already patched in software, but the LVI still works on systems with the requisite software fixes. As such, Intel will reportedly need to employ hardware fixes to fully block the LVI attack vector.

According to experimental fixes employed by the researchers, performance reductions from potential mitigations could vary from 2x to 19x based upon workload, but that could be offset with hardware-based fixes in new silicon.
Reply


Messages In This Thread
RE: Devastating Intel CPU Bug - by SteelCrysis - 01-03-2018, 11:40 PM
RE: Devastating Intel CPU Bug - by SteelCrysis - 01-04-2018, 04:25 AM
RE: Devastating Intel CPU Bug - by SteelCrysis - 01-07-2018, 07:16 AM
RE: Devastating Intel CPU Bug - by SteelCrysis - 01-09-2018, 04:02 AM
RE: Devastating Intel CPU Bug - by SteelCrysis - 01-10-2018, 07:54 AM
RE: Devastating Intel CPU Bug - by SteelCrysis - 01-12-2018, 08:59 AM
RE: Devastating Intel CPU Bug - by SteelCrysis - 01-12-2018, 10:42 PM
RE: Devastating Intel CPU Bug - by SteelCrysis - 01-13-2018, 02:47 AM
RE: Devastating Speculative Execution Intel CPU Bug - by SteelCrysis - 03-11-2020, 07:55 AM

Forum Jump:


Users browsing this thread: 1 Guest(s)