Downfall attacks - Major exploit in Intel CPUs discovered by Google researcher

AI summary of the linked article

Daniel Moghimi describes Downfall, a vulnerability in Intel processors that lets software on one user's machine steal data from other users sharing that computer, and in cloud environments from other customers. The flaw, tracked as CVE-2022-40982, stems from the Gather instruction leaking the content of the internal vector register file during speculative execution. Moghimi introduced Gather Data Sampling (GDS) and Gather Value Injection (GVI) techniques to exploit it, and says it took two weeks to develop an end-to-end attack stealing OpenSSL encryption keys. The article says Intel is releasing a microcode update as mitigation, and that some workloads may see up to 50% overhead according to Intel.

Recommended by 1 curator
Characters remaining: 10,000

comment guidelines