CROSSTalk — a vulnerability in Intel CPUs that leads to data leaks between cores

A group of researchers from the Vrije Universiteit Amsterdam has identified a new vulnerability (CVE-2020-0543) microarchitectural vulnerability in Intel processors, notable for allowing the recovery of results from certain instructions executed on another CPU core. This is the first vulnerability in speculative execution mechanisms that permits data leakage between individual CPU cores (previously, leaks were limited to different threads within a single core). The researchers named the issue CROSSTalk, but in Intel documents the vulnerability is referred to as SRBDS (Special Register Buffer Data Sampling).

The vulnerability relates to the class of MDS (Microarchitectural Data Sampling) problems presented a year ago and is based on the application of side-channel analysis techniques to data in microarchitectural structures. Operating principle CROSSTalk is close to the vulnerability RIDL, but differs in the source of the leak.
The new vulnerability manipulates leakage from a previously undocumented intermediate buffer used jointly by all CPU cores.

CROSSTalk - a vulnerability in Intel CPUs that leads to data leakage between cores

The essence of the problem in that some microprocessor instructions, including RDRAND, RDSEED, and SGX EGETKEY, are implemented using an internal microarchitectural operation SRR (Special Register Reads). On vulnerable processors, the data returned for SRR resides in an intermediate buffer shared by all CPU cores, which is then transferred to a fill buffer tied to a specific physical CPU core where the read operation was initiated. Subsequently, from the fill buffer, the value is copied to registers visible to applications.

The size of the shared intermediate buffer corresponds to the cache line, which is generally larger than the size of the data being read, and different read operations affect different offsets within the buffer. Since the shared buffer is copied to the fill buffer in its entirety, not only the portion needed for the current operation is moved, but also data that remains from other operations, including those executed on other CPU cores.

CROSSTalk - a vulnerability in Intel CPUs that leads to data leakage between cores

CROSSTalk - a vulnerability in Intel CPUs that leads to data leakage between cores

In the event of a successful attack, an authenticated local user in the system may determine the result of executing the RDRAND, RDSEED, and EGETKEY instructions in another process or within an Intel SGX enclave, regardless of the CPU core on which the code is running.
Researchers who identified the issue have published a prototype exploit demonstrating the possibility of leaking information about random values obtained through the RDRAND and RDSEED instructions to recover the ECDSA private key being processed in the Intel SGX enclave after performing just one digital signature operation in the system.


Play video

The issue is susceptible to a wide range of Intel desktop, mobile, and server processors, including Core i3, i5, i7, i9, m3, Celeron (series J, G, and N), Atom (series C, E, and X), Xeon (families E3, E5, E7, W, and D), Xeon Scalable, etc. Notably, Intel was notified of the vulnerability in September 2018, and in July 2019, a prototype exploit was provided demonstrating data leakage between CPU cores, but the development of a fix was delayed due to the complexity of its implementation. The microcode update proposed today blocks the issue by modifying the behavior of the RDRAND, RDSEED, and EGETKEY instructions to excessively overwrite data in a shared buffer to prevent residual information from lingering in it. Additionally, access to the buffer is suspended until reading and rewriting operations are completed.

A side effect of such protection is an increase in latency during the execution of RDRAND, RDSEED, and EGETKEY, and a reduction in throughput when trying to execute these instructions simultaneously on different logical processors. Execution of RDRAND, RDSEED, and EGETKEY also suspends memory access from other logical processors. These features may negatively affect the performance of some server applications, which is why the firmware includes a mechanism (RNGDS_MITG_DIS) to disable the protection of the RDRAND and RDSEED instructions executed outside the Intel SGX enclave.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster