ARM has leaked: an exceptional vulnerability has been discovered for speculative execution attacks

For processors across a wide range of Armv8-A architectures (Cortex-A) a unique vulnerability has emerged for side-channel attack using speculative computation algorithms. ARM itself reported this and provided patches and guidelines to mitigate the discovered vulnerability. The danger is not so great, but it should not be ignored, as ARM architecture processors are everywhere, making the risk of leaks unimaginably severe.

ARM has leaked: an exceptional vulnerability has been discovered for speculative execution attacks

The vulnerability found by Google experts has been codenamed Straight-Line Speculation (SLS) and officially designated CVE-2020-13844. According to ARM, the SLS vulnerability is one form of the Spectre vulnerability, which, along with the Meltdown vulnerability, became widely known in January 2018. In other words, it is a classic vulnerability in speculative computing mechanisms with side-channel attacks.

Speculative execution requires processing data in advance along several potential branches, even though they may later be discarded as unnecessary. Side-channel attacks allow for stealing such intermediate data before it's completely discarded. As a result, we have high-performance processors and a risk of data leakage.

The Straight-Line Speculation attack on ARM architecture processors forces the processor to revert to executing instructions found directly in memory every time there is a change in the instruction stream, instead of following the instructions in the new instruction stream. Clearly, this is not the best scenario for selecting instructions for execution that an attacker can exploit.

To ARM's credit, it not only released guidelines for developers to help prevent the risk of leakage through the Straight-Line Speculation attack, but also provided patches for major operating systems such as FreeBSD, OpenBSD, Trusted Firmware-A, and OP-TEE, and released patches for the GCC and LLVM compilers.

The company also stated that applying patches will not affect the performance of ARM platforms, as was the case with x86-compatible Intel platforms with the blocking of the Spectre and Meltdown vulnerabilities. However, we will learn more about this from third-party sources, which will provide an objective picture of the new vulnerability.



Source: 3dnews.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster