Indirector — a new microarchitectural attack affecting Intel Raptor Lake and Alder Lake CPUs.

Researchers from the University of California, San Diego have introduced a new method to attack the microarchitectural structures of Intel processors, applicable among others to CPUs based on the Raptor Lake and Alder Lake microarchitectures. The attack, codenamed Indirector, allows changes to the flow of speculative execution of instructions in other processes and at different privilege levels (for example, in the kernel or another virtual machine) running in the same CPU thread as the attacker's code. A prototype exploit has been developed to demonstrate the method, enabling the determination of memory address layouts to bypass the ASLR (Address Space Layout Randomization) protection mechanism. Additionally, under the MIT license, a toolkit has been released for analyzing and reverse engineering the CPU’s microarchitectural logic.

Two methods for organizing the attack have been proposed. The first method is based on distorting the contents of the IBP (Indirect Branch Predictor) buffer, used for predicting indirect branches when the address or offset for branching is still unknown and calculated in instructions preceding the branch instruction. The second method concerns the BTB (Branch Target Buffer), which contains information on recent branches.

Indirector - a new microarchitectural attack affecting Intel Raptor Lake and Alder Lake CPUs

Indirector - a new microarchitectural attack affecting Intel Raptor Lake and Alder Lake CPUs

The identified vulnerabilities allow the attacker to determine the contents of records in the IBP and BTB buffers, which contain addresses of branches used in external processes, as well as to substitute an arbitrary branch address in the data tables of the buffers. As a result, the attacker can redirect the execution flow of an external process to a desired memory address during speculative instruction execution. Once the incorrect prediction is determined, the result of speculative execution will be discarded, but the addresses and data read from memory during speculative execution will remain in the cache, and they can be extracted using one of the methods for determining the cache contents based on analyzing the change in access time to cached and non-cached data. The determination of exact indirect branch addresses can, for example, be used to bypass the ASLR protection mechanism.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster