Re: [gentoo-hardened] Re: [gentoo-hardened] Any hard ened features to protect from CVE-2016–5195 like vulnerabi lities?

R0b0t1 <[email protected]> Tue, 6 Dec 2016 19:55:05 -0600
Newsgroups gmane.linux.gentoo.hardened
Message-ID <CAAD4mYgYtmko0T7MQePKV-GTbmbQ6nfZ4GqaApqFBHJVkBo2yA@mail.gmail.com>
On Mon, Dec 5, 2016 at 1:45 AM, "Tóth Attila" <[email protected]> wrote:
> 2016.December 5.(H) 07:39 időpontban Andrew Savchenko ezt írta:
>> 3) Can some hardware features like Intel TSX be used to protect
>> from such race conditions?
>
> Just a sidenote on TSX: although it sounds procmising, I've been seeing
> multiple reports on Intel disabling the feature on several processors by
> microcode update due to various bugs since its debut. Not just some
> Haswell and Broadwell, but also some Skylake prcoessors are involved as
> well.

This is a good point - the hardware needs to be properly implemented
as well. There have already been cases where improper implementation
and unaccounted-for physical interactions have been used to elevate
permissions.


> BR: Dw.
> --
> dr Tóth Attila, Radiológus, 06-20-825-8057
> Attila Toth MD, Radiologist, +36-20-825-8057
>
>