Thursday, January 4, 2018

Project Zero reporting vulnerability the CPU.


Project Zero report CPU vulnerabilities found and became the origin of the patches of machine performance KPTI decreased. Now release the project details. There are the following.

  1. The vulnerability CVE-2017-5753 Vulnerability cross-checking scope memory. Can read data roaming memory to read the rest of the process is the same, affect Haswell Xeon, AMD FX, AMD PRO , and ARM Cortex-A57

  2. vulnerability CVE-2017-5753. Read kernel memory of Haswell Xeon, and AMD PRO will be affected if the BPF JIT kernel features which are not usually open



  3. the Vulnerability CVE-2017-5715 make a guest run on KVM can read kernel memory, host machine CPU Xeon Haswell.

  4.vulnerability CVE-2017-5754. Making process users can read kernel memory was of affect Haswell Xeon.


Attack 4 format is a test of Project Zero only CPUs that are outside the test may also be affected, such as ARM to indicate that the Cortex-A15, A57, and A72 is affected by the channel. vulnerability CVE-2017-5754 The Project Zero indicates that the specific Haswell Xeon.

No comments:

Post a Comment