[security] A new security flaw is revealed with 'BlindSide' on Linux affecting Intel and AMD

1 message · started by Devi Garcia on Sep 12, 2020

[security] A new security flaw is revealed with 'BlindSide' on Linux affecting Intel and AMD

From Devi Garcia · Sep 12, 2020

VUSec have published and shown an example of a newly discovered flaw present with both Intel and AMD processors when used with Linux.

Quoted reply (6 lines)
BlindSide allows attackers to “hack blind” in the Spectre era. That
is, given a simple buffer overflow in the kernel and no additional info
leak vulnerability, BlindSide can mount BROP-style attacks in

BlindSide allows attackers to “hack blind” in the Spectre era. That is, given a simple buffer overflow in the kernel and no additional info leak vulnerability, BlindSide can mount BROP-style attacks in the speculative execution domain to repeatedly probe and derandomize the kernel address space, craft arbitrary memory read gadgets, and enable reliable exploitation. 

It's quite a wide-reaching security issue too which they mentioned testing being successful across Intel Skylake, Kaby Lake and Coffee Lake microarchitectures and additionally AMD Zen+ and Zen2 microarchitectures with their testing overcoming the latest mitigations too.

Going by what they said in the full paper, the issue is present in the Linux Kernel from v3.19 up to v5.8 so that's potentially a lot of systems. They said it means that "an attacker armed with a write vulnerability can perform BlindSide attacks on a wide range of recent production Linux kernel versions even when blind to the particular kernel version".

read more:

https://www.gamingonlinux.com/2020/09/a-new-security-flaw-is-revealed-with-blindside-on-linux-affecting-intel-and-amd

View original on FreeLists


Previous thread · Next thread

Back to September 2020