Office

New security flaw affects cpus intel skylake and kaby lake

Table of contents:

Anonim

Security security researchers have discovered another flaw in Intel processors that could allow attackers to filter data encrypted by the processor. Dubbed PortSmash , researchers have verified the find on the Intel Skylake and Kaby Lake processors. However, they suggested that all CPUs that use a simultaneous multithreading architecture (SMT) are affected by the same failure.

Security Bugs Discovered in Intel Skylake and Kaby Lake Processors

SMT allows multiple computing threads to run in parallel on a CPU core, and with this security flaw, attackers can run a malicious process alongside those legitimate processes using the architecture's parallel thread execution capabilities. In this way, the malicious process can extract data from the other legitimate processes running on the same kernel.

Four academics from the Technological University of Tampere, in Finland, together with a researcher from the Technological University of Havana (CUJAE), Cuba, have published a proof of concept of this new attack on GitHub.

The proof of concept code is currently available on GitHub, which can be used to execute the PortSmash attack on any processor in the Intel Skylake and Kaby Lake family from the get-go. "For other SMT architectures, it may be necessary to customize spyware strategies and / or wait times, " the researchers said. As for the impact on AMD systems, the research team told ZDNet that they suspect that AMD CPUs are also affected.

It would also affect other processors, including those from AMD

Intel officially responded to this failure, arguing that Intel processors are not the only ones affected by the problem:

"Intel received notification of the investigation. This problem is not dependent on speculative execution and is therefore not related to spectrum, merger, or L1 terminal failure. We hope it is not exclusive to Intel platforms, '' said a company spokesperson.

Investigators reported this bug (CVE-2018-5407) to Intel last month.

WccftechNotebookcheck Font

Office

Editor's choice

Back to top button