View Single Post
Staro 08.03.2022., 20:57   #360
The Exiled
McG
Moj komp
 
The Exiled's Avatar
 
Datum registracije: Feb 2014
Lokacija: Varaždin
Postovi: 6,773
BHI: The newest Spectre vulnerability affecting Intel & Arm CPUs
Citiraj:
The VUSec security researchers are today -- in cooperation with Intel -- disclosing another new speculative execution vulnerability... BHI is the name and it's an offshoot from Spectre V2. BHI is short for Branch History Injection and when first discovered was coined as Spectre-BHB by the researchers. A proof-of-concept exploit exists for leaking arbitrary kernel memory on modern Intel CPUs with BHI. Arm CPUs are also affected while AMD CPUs are not believed to be affected. Roughly speaking, Intel CPUs vulnerable to Spectre Variant Two are also believed to be impacted by BHI.

Intel will be releasing software mitigations for BHI shortly -- presumably as soon as now with the embargo lifting this minute. BHI is an extensive of Spectre V2 that leverages the global history to re-introduce the exploitation of cross-privilege BTI. BHI allows exploiting systems that already have new in-hardware mitigations such as Intel eIBRS and Arm CSV2. As for whether the eBIRS and CSV2 mitigations are considered "broken", the researchers note that the mitigations work as intended but the residual attach surface is "much more significant than the vendors originally assumed." Intel has posted a list of affected CPUs confirming up through Alder Lake is indeed affected as well as Ice Lake servers.
Izvor: Phoronix
__________________
AMD Ryzen 7 Pro 4750G + Vega iGPU | be quiet! Pure Rock 2 Black | MSI B450 Tomahawk Max II | 32GB G.Skill DDR4-2666 Value | 256GB AData SX8200 Pro NVMe | 2x4TB WD Red Plus | Fractal Define 7 Compact | Corsair CX450M
The Exiled je online   Reply With Quote