A new variant of the Zombieload attack on Intel processors has been identified

Researchers from Graz University of Technology (Austria) revealed information about a new side-channel attack method ZombieLoad 2.0 (CVE-2019-11135), which allows the extraction of confidential information from other processes, the operating system, virtual machines, and protected enclaves (TEE, Trusted Execution Environment). The issue affects only Intel processors. Components to block the problem are offered in yesterday's microcode update.

The issue belongs to the MDS (Microarchitectural Data Sampling) class and is an enhanced version of disclosed in May of the ZombieLoad attack. ZombieLoad 2.0, like other MDS class attacks, relies on using side-channel analysis methods on data within microarchitectural structures (for example, in fill buffers (Line Fill Buffer) and store buffers (Store Buffer), where data used in Load and Store operations is temporarily held).

The new variation of the Zombieload attack is based on a leak that occurs during the operation of the asynchronous interrupt mechanism (TAA, TSX Asynchronous Abort), implemented in the TSX (Transactional Synchronization Extensions) extension, which provides capabilities for working with transactional memory. This allows for improved performance of multithreaded applications by dynamically excluding unnecessary synchronization operations (supporting atomic transactions that can either be committed or aborted). If an interruption occurs, operations performed with the transactional memory region are rolled back.

Transaction interruption occurs asynchronously, during which other threads may access the cache that is also used in the discarded transactional memory region. From the start to the actual completion of the asynchronous transaction interruption, there may be situations where the processor, during speculative execution of an operation, could read data from internal microarchitectural buffers and pass it to a speculatively executing operation. Then, a conflict will be identified, and the speculative operation will be discarded, but the data will remain in the cache and may be retrieved using side-channel cache recovery methods.

The attack involves opening TSX transactions and creating conditions for their asynchronous interruption, during which conditions arise for leaking contents of internal buffers, speculatively filled with data from memory read operations executed on the same CPU core. The leak is limited to the current physical CPU core (where the attacker's code is running), but since microarchitectural buffers are shared among different threads in Hyper-Threading mode, it is possible for memory operation leaks executed in other CPU threads to occur.

Attack is susceptible to affects some models of eighth, ninth, and tenth generation Intel Core processors, as well as Intel Pentium Gold, Intel Celeron 5000, Intel Xeon E, Intel Xeon W, and the second generation Intel Xeon Scalable. New Intel processors based on the Cascade Lake microarchitecture, which was originally not susceptible to RIDL and Fallout attacks, are also affected. In addition to Zombieload 2.0, researchers have also identified a way to bypass previously proposed defenses against MDS attacks, based on the use of the VERW instruction to clear the contents of microarchitectural buffers when returning from kernel to user space or when transferring control to the guest system.

Intel's report states that in systems with heterogeneous workloads, the possibility of conducting the attack is hampered as leaks from microarchitectural structures encompass all activity in the system, and the attacker cannot influence the source of the extracted data; they can only accumulate insights that arise from the leak and attempt to identify useful information among that data, without the ability to deliberately intercept data related to specific memory addresses. Nevertheless, researchers have published exploit prototype, operational on Linux and Windows, and demonstrated the possibility of using the attack to determine the hash of the root user's password.
It is possible to conduct the attack from a guest system to accumulate data that appears in operations of other guest systems, the host environment, the hypervisor, and Intel SGX enclaves.

Play video

Patches to block the vulnerability includes have been integrated into the Linux kernel code base and are included in the releases 5.3.11, 4.19.84, 4.14.154, 4.9.201, and 4.4.201. Updates with kernel and microcode have also already been released for major distributions (Debian, Arch, Ubuntu, SUSE/openSUSE, Alpine, FreeBSD). The problem was identified in April and the fix was coordinated by Intel with operating system developers.

The simplest method to block Zombieload 2.0 is to disable TSX support in the CPU. The proposed fix for the Linux kernel includes several protection options. The first option provides a parameter 'tsx=on/off/auto', allowing control over the enabling of the TSX extension in the CPU (the 'auto' value disables TSX only for vulnerable CPUs). The second protection option is activated with the parameter 'tsx_async_abort=off/full/full,nosmt' and is based on clearing microarchitectural buffers during context switching (the 'nosmt' flag additionally disables SMT/Hyper-Threads). To check the system's vulnerability, the parameter '/sys/devices/system/cpu/vulnerabilities/tsx_async_abort' is provided in sysfs.

In addition, the official blog says nothing about release dates, but the creators shared gameplay fragments from a new demo intended for internal testing. microcode has been closed another vulnerability (CVE-2018-12207) in Intel processors, which is also blocked in the latest the official blog says nothing about release dates, but the creators shared gameplay fragments from a new demo intended for internal testing. Linux kernel. The vulnerability , rather than taking focus. allows an unprivileged attacker to initiate a denial of service, leading to a system hang in a 'Machine Check Error' state.
The attack can also be performed from a guest system.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster