TSA attack leads to information leakage from AMD CPU microarchitecture structures.

AMD has revealed information about a new class of microarchitectural attacks on its processors — TSA (Transient Scheduler Attack). This attack allows an attacker to bypass CPU isolation mechanisms and determine data being processed in other contexts, such as identifying information processed at the kernel level from user space, or gaining access to data used in another guest system from within a guest system.

The vulnerabilities were discovered during the development of a toolkit created by researchers from Microsoft and the Swiss Federal Institute of Technology Zurich for stress-testing microarchitectural isolation between different access control domains, such as the kernel, virtual machines, and processes.

The attack method relies on the timing dependency of some instructions on the state of microarchitectural structures. When the processor expects a quick completion of a data read instruction from memory (for example, assuming that the data is in the L1 cache), but fails to successfully obtain the data, a 'false completion' state occurs. The processor may then speculatively schedule execution of other operations dependent on the result of the memory load instruction before this state is determined.

Since the load was not completed, the data associated with it is deemed invalid by the processor, and the load operation is retried later. Dependent operations are also re-executed once correct data is available. Notably, no pipeline flush occurs after executing the instruction that recorded the 'false completion' state, allowing incorrect data to be redirected to dependent operations.

Executing such operations does not modify the state of the cache and TLB (Translation Lookaside Buffer), meaning that the data cannot be retrieved using traditional cache state determination methods. However, this data does influence the timing of other instructions. Timing analysis can be exploited as a source of information leakage from microarchitectural structures left behind after speculative execution of other operations.

Depending on the source of residual data extraction, two vulnerabilities have been identified:

  • CVE-2024-36350 (TSA-SQ — TSA Store Queue) — a buffer overflow vulnerability in the Store Queue that allows for determining the outcome of memory write instructions.
  • CVE-2024-36357 (TSA-L1 — TSA L1 Data Cache) — a leak through the L1D cache.

These vulnerabilities are present in AMD processor family (Fam19h) based on Zen 3 and Zen 4 microarchitectures. For example, the issue is found in the AMD Ryzen 5000/6000/7000/8000 series, AMD EPYC Milan/Milan-X/Genoa/Genoa-X/Bergamo/Siena, AMD Instinct MI300A, AMD Ryzen Threadripper PRO 7000 WX, AMD EPYC Embedded 7003/8004/9004/97X4, AMD Ryzen Embedded 5000/7000/V3000.

The necessary changes to mitigate the vulnerability are included in the December microcode and PI firmware updates provided to OEM manufacturers. Patches for vulnerability protection have been sent for inclusion in the Linux kernel (to disable the protection negatively impacting performance, a kernel command line option 'tsa=off' is available). Fixes have also been added to the Xen hypervisor. To block the vulnerability, both the microcode update and enabling the protection mode at the kernel or hypervisor level are required.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster