Re: [gentoo-hardened] Any hardened features t o protect from CVE-2016–5195 like vulnerabi lities?
"Tóth Attila" <[email protected]> Mon, 5 Dec 2016 08:45:06 +0100
| Newsgroups | gmane.linux.gentoo.hardened |
|---|---|
| Message-ID | <[email protected]> |
2016.December 5.(H) 07:39 időpontban Andrew Savchenko ezt írta: > 3) Can some hardware features like Intel TSX be used to protect > from such race conditions? Just a sidenote on TSX: although it sounds procmising, I've been seeing multiple reports on Intel disabling the feature on several processors by microcode update due to various bugs since its debut. Not just some Haswell and Broadwell, but also some Skylake prcoessors are involved as well. https://en.wikipedia.org/wiki/Transactional_Synchronization_Extensions "In August 2014, Intel announced that a bug exists in the TSX implementation on Haswell, Haswell-E, Haswell-EP and early Broadwell CPUs, which resulted in disabling the TSX feature on affected CPUs via a microcode update.[9][10][21] The bug was fixed in F-0 steppings of the vPro-enabled Core M-5Y70 Broadwell CPU in November 2014.[22]" https://www.reddit.com/r/hardware/comments/44k218/intel_disables_tsx_transactional_memory_again_in/ BR: Dw. -- dr Tóth Attila, Radiológus, 06-20-825-8057 Attila Toth MD, Radiologist, +36-20-825-8057