A new vulnerability discovered in the Armv8-A (Cortex-A) CPU architecture has been reported by chipmaker Arm. The company has asked developers to help mitigate the vulnerability. The flaw is a classic side-channel attack.

This attack relies on preprocessing data by a CPU for speed and efficiency reasons and discarding unnecessary computational threads. It can allow malicious actors to intercept these temporary calculations and see what the CPU is working on.
As Arm says, the SLS flaw it discovered is a variant of Spectre. While the original Spectre flaw affected processors from all major chip makers, SLS only affects Arm's Armv-A processors.
On affected processors, while the computer is executing its processes normally, when there is a change in the Arm CPU's instruction control flow, the CPU reacts by executing instructions that are in its memory after the change in control flow.
However, while the description of the SLS bug seems quite serious, Arm says that for now, the risk of such an attack is actually low.
Patches have been released by Arm
The company has been working on a fix for this issue since last year. Engineers have contributed patches to various software programs and operating systems, including FreeBSD, OpenBSD, Trusted Firmware-A, and OP-TEE. These patches can prevent this bug from being exploited.
However, Arm has gone even further. The company has also released patches to GCC and LLVM, two of the most popular code compilers.
Unlike Spectre and Meltdown, Arm says these patches are unlikely to have an adverse impact on performance. According to Arm, the SLS vulnerability was discovered by security researchers participating in Google SafeSide, a project that investigates side-channel attacks caused by hardware-related factors.
