Intel processors are vulnerable to a new attack that can leak data from the internal CPU memory – also known as cache.
The attack, described as “Snoop-Assisted L1 Data Sampling”, or simply Snoop (CVE-2020-0550), was discovered by Pawel Wieczorkiewicz, a software engineer at Amazon Web Services (AWS).
Wieczorkiewicz reported the issue to Intel, and after further investigation, the company concluded that the fixes released in August 2018 for the Foreshadow (L1TF) vulnerability also apply to this new attack.
A list of Intel processors vulnerable to Snoop attacks is available here. The list includes Intel series such as Core and Xeon processors.
On a technical level, the new Snoop attack exploits CPU mechanisms such as multiple cache levels, cache coherence, and bus snooping. Below is a simple, non-technical explanation of why the attack exists and how it works.
Processors, cache levels, cache coherence and bus snooping
Today, most modern processors have multiple levels of memory (cache memory) at their disposal for storing data while it is being processed within the CPU.
Depending on the CPU specifications, there could be a level 1 (L1) temporary memory, level 2 (L2), or even level 3 (L3).
The most used cache level is L1, which is divided into two, with one part dedicated to processing user data (L1D) and the second to handling CPU instruction code (L1I).
Due to multi-core architectures and multiple cache levels, data is often stored across multiple CPU caches simultaneously, even within RAM.
Cache coherency is the process that keeps all cache levels in sync so that L2, L3, and RAM all have the same data that is present in the L1D cache, the place where it usually changes first.
The term “bus snooping” (or “snooping”) is the function by which the CPU notifies all cache levels when a change occurs in L1D.
Wieczorkiewicz discovered that under certain conditions malicious code could exploit bus snooping and cause errors that leak data from the cache coherence process – specifically cache data that is currently being modified in the L1D cache and effectively leak data from the CPU's internal memory.
Snoop attacks do not work if you apply the L1TF patches
The main drawback of this attack is that malicious code running on one CPU core can leak data from the other cores, a problem in cloud computing and virtual environments.
The good news is that this attack is incredibly difficult and does not return large amounts of data (in contrast to the original vulnerabilities Meltdown and Spectre).
Furthermore, Intel says that the attack also requires conditions that are difficult to satisfy in the real world.
“Due to the numerous complex requirements that must be met for their successful execution, Intel does not believe that Snoop Assisted L1 Data Sampling is a practical method in real-world environments where the operating system is reliable”, said Intel.
For users running high-risk, the chip maker recommends applying the Foreshadow (L1TF) patches released in August 2018.
Furthermore, disabling the Intel TSX (Transactional Synchronization Extensions) functionality also significantly reduces the overall set of vulnerabilities and makes Snoop attacks even tougher.
The Snoop attack may be difficult to carry out, but it is still notable because it exposes a new attack vector within functions , an area of modern CPU architecture that had not been tested as a potential attack before.

