New Spectre-like CPU Vulnerability Bypasses Existing Defenses

Peter Reutemann <[email protected]> Mon, 12 Aug 2019 10:57:02 +1200
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12JEQM_kCf7EiuVD5DpgGDQwGXXEDHuJzn-+EwkDW_q3pA@mail.gmail.com>
'Researchers from security firm Bitdefender discovered and reported a
year ago a new CPU vulnerability that 'abuses a system instruction
called SWAPGS and can bypass mitigations put in place for previous
speculative execution vulnerabilities like Spectre,' writes Lucian
Constantin for CSO.

There are three attack scenarios involving SWAPGS, the most serious of
which 'can allow attackers to leak the contents of arbitrary kernel
memory addresses. This is similar to the impact of the Spectre
vulnerability.' Microsoft released mitigations for the vulnerability
in July's Patch Tuesday, although details were withheld until August 6
when Bitdefender released its whitepaper and Microsoft published a
security advisory.'

-- source: https://it.slashdot.org/story/19/08/10/0523206

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug