Re: [gentoo-hardened] Re: [gentoo-hardened] Any hard ened features to protect from CVE-2016–5195 like vulnerabi lities?
R0b0t1 <[email protected]> Tue, 6 Dec 2016 19:55:05 -0600
| Newsgroups | gmane.linux.gentoo.hardened |
|---|---|
| Message-ID | <CAAD4mYgYtmko0T7MQePKV-GTbmbQ6nfZ4GqaApqFBHJVkBo2yA@mail.gmail.com> |
On Mon, Dec 5, 2016 at 1:45 AM, "Tóth Attila" <[email protected]> wrote: > 2016.December 5.(H) 07:39 időpontban Andrew Savchenko ezt írta: >> 3) Can some hardware features like Intel TSX be used to protect >> from such race conditions? > > Just a sidenote on TSX: although it sounds procmising, I've been seeing > multiple reports on Intel disabling the feature on several processors by > microcode update due to various bugs since its debut. Not just some > Haswell and Broadwell, but also some Skylake prcoessors are involved as > well. This is a good point - the hardware needs to be properly implemented as well. There have already been cases where improper implementation and unaccounted-for physical interactions have been used to elevate permissions. > BR: Dw. > -- > dr Tóth Attila, Radiológus, 06-20-825-8057 > Attila Toth MD, Radiologist, +36-20-825-8057 > >