Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Are 8 new 'Spectre-class' flaws in Intel CPUs about to be exposed?
ZDNet ^ | 4 May 2018 | Liam Tung

Posted on 05/04/2018 10:48:57 AM PDT by ShadowAce

A report by German tech site heise.de says Intel's CPUs are affected by eight new "Spectre-class" vulnerabilities, including one found by Google's Project Zero, which identified the first set of CPU flaws known as Meltdown and Spectre.

The site reports that the bugs have been assigned CVE identifiers and that at least one of them will be revealed by Project Zero on May 7, a day ahead of Patch Tuesday, which Microsoft recently begun using to distribute Intel's hardware patches or microcode updates.

The site says it has concrete evidence that Intel processors are vulnerable to the new flaws and that the chipmaker has patches in the works. AMD CPUs may also be vulnerable and further research on that issue is under way.

Intel has issued a cryptic statement titled "addressing questions regarding additional security issues".

"Protecting our customers' data and ensuring the security of our products are critical priorities for us. We routinely work closely with customers, partners, other chipmakers and researchers to understand and mitigate any issues that are identified, and part of this process involves reserving blocks of CVE numbers," wrote Leslie Culbertson, Intel executive vice president.

"We believe strongly in the value of coordinated disclosure and will share additional details on any potential issues as we finalize mitigations. As a best practice, we continue to encourage everyone to keep their systems up to date."

According to Heise, four of the vulnerabilities are being treated as "high risk" and, as with the previously found Spectre flaws, they impact cloud providers due to an ability to attack a host system from a virtual machine, allowing an attacker to extract secrets and passwords from the host machine's memory.

Spectre Variant 2, a branch target injection flaw, concerns cloud providers because of the risk of it being used to enable a hypervisor bypass. Fixing it required microcode updates from Intel and AMD.

Heise notes that while the original Spectre bugs are difficult to exploit, the new Spectre vulnerabilities are more easily used.

Reports of the new bugs come just a month after Intel completed delivery of microcode updates to address Spectre Variant 2 for all chip families released in the past decade.

As of March, Microsoft has assisted Intel to deploy these updates, which were originally being deployed by hardware manufacturers.


TOPICS: Computers/Internet
KEYWORDS: intel; meltdown; spectre

1 posted on 05/04/2018 10:48:57 AM PDT by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; Ernest_at_the_Beach; ...

2 posted on 05/04/2018 10:49:32 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Spectre? Has James Bond been notified?


3 posted on 05/04/2018 10:57:02 AM PDT by Kartographer ("We mutually pledge to each other our lives, our fortunes and our sacred honor.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

SPROCKETS - “Touch my monkey”


4 posted on 05/04/2018 10:58:10 AM PDT by RinaseaofDs
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Evil exists - on every human platform - with people ready and willing to exploit weakness. Strange world.


5 posted on 05/04/2018 10:59:09 AM PDT by GOPJ ( If you want a picture of the 'Deep State' imagine a boot stamping on a human face- forever. Orwell)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

It’s not a flaw, it’s a feature!...............


6 posted on 05/04/2018 11:00:59 AM PDT by Red Badger (Remember all the great work Obama did for the black community?.............. Me neither.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Kartographer

The RosaKlebbium processor.


7 posted on 05/04/2018 11:02:30 AM PDT by MUDDOG
[ Post Reply | Private Reply | To 3 | View Replies]

To: Red Badger

> It’s not a flaw, it’s a feature!..............

Yep. That is how the Deep State keeps track of us all. Trump is exposing them.


8 posted on 05/04/2018 11:14:50 AM PDT by XEHRpa
[ Post Reply | Private Reply | To 6 | View Replies]

To: MUDDOG

That’s a Blofeld Group product isn’t it?


9 posted on 05/04/2018 11:22:11 AM PDT by Kartographer ("We mutually pledge to each other our lives, our fortunes and our sacred honor.")
[ Post Reply | Private Reply | To 7 | View Replies]

To: Kartographer

They make the hardware, Facebook the software.


10 posted on 05/04/2018 11:39:55 AM PDT by MUDDOG
[ Post Reply | Private Reply | To 9 | View Replies]

To: MUDDOG

I think ‘Q’ posted something to that affect just recently.


11 posted on 05/04/2018 11:58:39 AM PDT by Kartographer ("We mutually pledge to each other our lives, our fortunes and our sacred honor.")
[ Post Reply | Private Reply | To 10 | View Replies]

To: ShadowAce

IBM screwed the entire world by displacing the 68000 and enshrining that Intel crap.


12 posted on 05/04/2018 1:33:44 PM PDT by GingisK
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson