#spectrev2 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #spectrev2, aggregated by home.social.
-
New #TONTOU #CPU attack bypasses #SpectreV2 fixes, leaks #Linux password hashes
-
New #TONTOU #CPU attack bypasses #SpectreV2 fixes, leaks #Linux password hashes
-
New #SpectreV2 attack impacts #Linux systems on #Intel #CPU
Researchers have demonstrated the "first native #Spectre v2 #exploit" for a new #speculativeexecution side-channel flaw that impacts Linux systems running on many modern Intel processors.
Current mitigations are designed around isolating exploitable gadgets to remove the attack surface. Researchers, through custom 'InSpectre Gadget' analysis tool, demonstrated that exploitable gadgets in the Linux kernel remain.
https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-impacts-linux-systems-on-intel-cpus/ -
New #SpectreV2 attack impacts #Linux systems on #Intel #CPU
Researchers have demonstrated the "first native #Spectre v2 #exploit" for a new #speculativeexecution side-channel flaw that impacts Linux systems running on many modern Intel processors.
Current mitigations are designed around isolating exploitable gadgets to remove the attack surface. Researchers, through custom 'InSpectre Gadget' analysis tool, demonstrated that exploitable gadgets in the Linux kernel remain.
https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-impacts-linux-systems-on-intel-cpus/ -
Just merged into #Linux mainline [edit: and various newly released stable/longterm #kernel like 6.1.12]:
```Certain #AMD processors are vulnerable to a cross-thread return address predictions bug. […] #SpectreV2 […] These patches introduce a KVM module parameter that, if set, will prevent the user from disabling the HLT, MWAIT and CSTATE exits```
Merge: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=82eac0c830b7d917bd2a8806eb6ed21ef1e0f84e Docs: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=493a2c2d23ca91afba96ac32b6cbafb54382c2a3
CVE-2022-27672 – Cross-Thread Return Address Predictions: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27672
-
Die Prozessorhersteller AMD und Intel stopfen im November einige Sicherheitslücken. Lenovo korrigiert sicherheitsrelevante Fehler in BIOS und Software.
Patchday: AMD, Intel und Lenovo müssen Sicherheitslecks abdichten -
Die Prozessorhersteller AMD und Intel stopfen im November einige Sicherheitslücken. Lenovo korrigiert sicherheitsrelevante Fehler in BIOS und Software.
Patchday: AMD, Intel und Lenovo müssen Sicherheitslecks abdichten