Intel has published details about a new class of vulnerabilities.

Intel has released information about a new class of vulnerabilities in its processors — MDS (Microarchitectural Data Sampling). Like the previous Spectre-class attacks, these new issues could lead to the leakage of sensitive data from the operating system, virtual machines, and foreign processes. It is reported that the issues were initially discovered by Intel employees and partners during an internal audit. In June and August 2018, independent researchers also reported the problems to Intel, after which almost a year of collaborative work with manufacturers and operating system developers took place to identify possible attack vectors and deliver fixes. AMD and ARM processors are not affected by this issue.

Identified vulnerabilities:

CVE-2018-12126 — MSBDS (Microarchitectural Store Buffer Data Sampling), recovery of storage buffer contents. Used in the Fallout attack. The severity level is rated at 6.5 (CVSS);

CVE-2018-12127 — MLPDS (Microarchitectural Load Port Data Sampling), recovery of load port contents. Used in the RIDL attack. CVSS 6.5;

CVE-2018-12130 — MFBDS (Microarchitectural Fill Buffer Data Sampling), recovery of fill buffer contents. Used in the ZombieLoad and RIDL attacks. CVSS 6.5;

CVE-2019-11091 — MDSUM (Microarchitectural Data Sampling Uncacheable Memory), recovery of uncacheable memory contents. Used in the RIDL attack. CVSS 3.8.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster