HomeSecurityNew side-channel Hertzbleed attack affects Intel and AMD CPUs

New Hertzbleed side-channel attack affects Intel and AMD CPUs

A new side-channel attack, known as Hertzbleed, allows remote theft of cryptographic keys by observing fluctuations in CPU triggered by dynamic voltage and frequency scaling (DVFS).

See also: Conti ransomware targeted Intel firmware for stealth attacks

side-channel Hertzbleed

This is possible because, on modern Intel (CVE-2022-24436) and AMD (CVE-2022-23823) x86 processors, dynamic frequency scaling depends on power consumption and the data being processed.

DVFS is a power management throttling feature used by modern CPUs to ensure that the system does not exceed thermal and power limits during high loads, as well as to reduce overall power consumption during low CPU loads .

Hertzbleed was discovered by a team of researchers from the University of Texas at Austin, the University of Illinois Urbana-Champaign, and the University of Washington.

"In the worst case, these attacks can allow an attacker to extract cryptographic keys from remote servers previously believed to be secure. [..] Hertzbleed is a real and practical threat to the security of cryptographic software," the researchers explain.

See also: AMD: Radeon RX 6700 now official with new driver 22.5.2
processors

Intel says this vulnerability affects all of its processors and can be remotely exploited in highly sophisticated attacks that do not require user interaction by low-privilege threat actors.

AMD also revealed that Hertzbleed affects several of its products, including desktop, mobile, Chromebook , and server CPUs using the Zen 2 and Zen 3 microarchitectures.

Processors from other vendors like ARM that also use the frequency scaling feature may also be affected by Hertzbleed, but researchers have yet to confirm whether it applies to these CPUs as well.

Neither Intel nor AMD plans to issue microcode updates to change the behavior of their processors. Instead, they are supporting the changes made by Microsoft and Cloudflare to the PQCrypto-SIDH and CIRCL cryptographic libraries, respectively.

See also: Is the Vice Society ransomware gang behind the Palermo attack?

According to AMD's guidelines, developers can use masking, hiding, or key rotation to mitigate side-channel leaks based on power analysis in Hertzbleed attacks.

The researchers also say that disabling the frequency boosting feature can mitigate Hertzbleed attacks in most cases. The frequency boosting feature is called “Turbo Boost” on Intel and “Turbo Core” or “Precision Boost” on AMD processors.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS