{"id":341807,"date":"2020-03-09T07:49:16","date_gmt":"2020-03-09T05:49:16","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=341807"},"modified":"2020-03-09T07:49:40","modified_gmt":"2020-03-09T05:49:40","slug":"critical-security-flaw-found-in-amd-processors","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/341807-critical-security-flaw-found-in-amd-processors.html","title":{"rendered":"Critical security flaw found in AMD processors"},"content":{"rendered":"<p>Researchers at the Graz University of Technology have discovered security vulnerabilities affecting AMD CPUs launched between 2011 and 2019.<\/p>\n<p>In a <a href=\"https:\/\/mlq.me\/download\/takeaway.pdf\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>paper published on the subject<\/strong><\/a>, the researchers detailed two &#8220;Take A Way&#8221; attacks which can be used to exploit side-channel vulnerabilities in Ryzen processors.<\/p>\n<p>&#8220;We reverse-engineered AMD\u2019s L1D cache way predictor in microarchitectures from 2011 to 2019, resulting in two new attack techniques,&#8221; the researchers said.<\/p>\n<p>The two side-channel attacks detailed in the paper &#8211; &#8220;Collide+Probe&#8221; and &#8220;Load+Reload&#8221; &#8211; can be used to access secret data from the chips by attacking the L1D cache predictor.<\/p>\n<p>AMD&#8217;s L1D cache predictor was implemented on these chips to reduce power consumption by predicting in which cache way a certain address is located.<\/p>\n<p>The researchers disclosed the vulnerabilities to AMD on 23 August 2019, and there is currently no dedicated firmware patch available for these vulnerabilities.<\/p>\n<h3 class=\"my-4\">AMD security advisory<\/h3>\n<p>AMD responded to the publication of these security vulnerabilities via a <a href=\"https:\/\/www.amd.com\/en\/corporate\/product-security\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>security advisory on its website<\/strong><\/a>, acknowledging the security exploits and stating they were not a new form of side-channel attack.<\/p>\n<p>&#8220;We are aware of a new white paper that claims potential security exploits in AMD CPUs, whereby a malicious actor could manipulate a cache-related feature to potentially transmit user data in an unintended way,&#8221; AMD said.<\/p>\n<p>&#8220;The researchers then pair this data path with known and mitigated software or speculative execution side-channel vulnerabilities. AMD believes these are not new speculation-based attacks.&#8221;<\/p>\n<p>AMD said it recommended users follow the steps be taken by users to help mitigate against side-channel attacks:<\/p>\n<ul>\n<li>Keep your operating system up-to-date by operating at the latest version revisions of platform software and firmware, which include existing mitigations for speculation-based vulnerabilities<\/li>\n<li>Following secure coding methodologies<\/li>\n<li>Implementing the latest patched versions of critical libraries, including those susceptible to side-channel attacks<\/li>\n<li>Utilizing safe computer practices and running antivirus software<\/li>\n<\/ul>\n<p>Following the publication of this advisory by AMD, the researchers <a href=\"https:\/\/twitter.com\/duxcode\/status\/1236769620696186882\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>stated on Twitter<\/strong><\/a> that this vulnerability remains open to exploitation.<\/p>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/341359-incredible-connection-apologises-for-personal-data-leak.html\" rel=\"bookmark\">Incredible Connection apologises for personal data leak<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Researchers at the Graz University of Technology have discovered security vulnerabilities affecting AMD CPUs launched between 2011 and 2019.<\/p>\n","protected":false},"author":341028,"featured_media":206706,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[577,40988,63511],"class_list":["post-341807","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-amd","tag-security-vulnerability","tag-side-channel-attacks"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/341807"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341028"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=341807"}],"version-history":[{"count":0,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/341807\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/206706"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=341807"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=341807"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=341807"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}