Re: [gentoo-hardened] Any hardened features t o protect from CVE-2016–5195 like vulnerabi lities?

"Tóth Attila" <[email protected]> Mon, 5 Dec 2016 08:45:06 +0100
Newsgroups gmane.linux.gentoo.hardened
Message-ID <[email protected]>
2016.December 5.(H) 07:39 időpontban Andrew Savchenko ezt írta:
> 3) Can some hardware features like Intel TSX be used to protect
> from such race conditions?

Just a sidenote on TSX: although it sounds procmising, I've been seeing
multiple reports on Intel disabling the feature on several processors by
microcode update due to various bugs since its debut. Not just some
Haswell and Broadwell, but also some Skylake prcoessors are involved as
well.

https://en.wikipedia.org/wiki/Transactional_Synchronization_Extensions
"In August 2014, Intel announced that a bug exists in the TSX
implementation on Haswell, Haswell-E, Haswell-EP and early Broadwell CPUs,
which resulted in disabling the TSX feature on affected CPUs via a
microcode update.[9][10][21] The bug was fixed in F-0 steppings of the
vPro-enabled Core M-5Y70 Broadwell CPU in November 2014.[22]"

https://www.reddit.com/r/hardware/comments/44k218/intel_disables_tsx_transactional_memory_again_in/

BR: Dw.
-- 
dr Tóth Attila, Radiológus, 06-20-825-8057
Attila Toth MD, Radiologist, +36-20-825-8057