HomeSecurityIntel CPUs are vulnerable to new side-channel attack

Intel CPUs are vulnerable to new side-channel attack

A new attack has been discovered that affects many Intel CPUs via a side channel. This attack allows data leakage via the EFLAGS.

See also: Intel: Raja Koduri leaves the company
Intel CPU

Researchers from Tsinghua University, the University of Maryland, and a computer lab (BUPT) run by the Chinese Ministry of Education discovered the new attack. This attack is different from most side-channel attacks.

The new attack differs from other side-channel attacks in that it does not rely on the cache system. Instead, it exploits a flaw in transient execution that allows the extraction of secret data from the user's memory space.

The attack acts as a side-channel to Meltdown, a major security flaw discovered in 2018 that affected many x86-based microprocessors. Meltdown exploits a performance optimization feature called “speculative execution.” This allows attackers to bypass memory isolation mechanisms and access sensitive data such as passwords, encryption keys, and other private data stored in kernel memory.

The crash has been significantly reduced through the use of software code updates, patches, and hardware upgrades. However, no solution has addressed the problem 100%, and the latest attack method can work even on fully patched systems, depending on the hardware, software , and patch configurations.

See also: Wiretapping: The Anti-Corruption Commission fined Intellexa for non-cooperation

A technical paper published on Arxiv.orgpresents the new side-channel attack. It affects the timing of JCC (jump on condition code) instructions due to a flaw in changing the EFLAGS register in transient execution.

attack

EFLAGS is a register in the computer that contains “flags” indicating the state of the processor. JCC is a processor instruction that allows branching under specific conditions, based on the flags in the EFLAGS register.

The attack is performed in two steps. First, temporary execution is enabled and the secret data is encoded via the EFLAGS register. Then, the execution time of the JCC instruction is measured to decode the data.

Experimental results showed that the attack managed to recover data (leak it) at a rate of 100% for Intel i7-6700 and Intel i7-7700, while it had some success but not 100% when attacking the newer Intel i9-10980XE processor. The experiment was conducted using Ubuntu 22.04 jammy and Linux kernel version 5.15.0.

The researchers say the attack is not as reliable as cache-state side-channel methods. To get the best results on the latest chips, the attack would have to be repeated thousands of times.

The researchers say they have not yet determined the root cause of the attack. They speculate that there is a “buffer” in the execution unit of Intel’s CPU that takes time to recover if execution needs to be interrupted. This can lead to a crash if the next instruction depends on the buffer.

See also: China: Woman smuggles 200 Intel CPUs, making her pregnant

However, they still recommend security measures, such as modifying the JCC command in the application or rewriting EFLAGS during transient execution, in order to reduce its influence on the JCC command.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS