AMD processors from 2011 to 2019 vulnerable to two new attacks

Brink

Administrator
Staff member
Local time
10:41 AM
Messages
74,889
Location
Oklahoma
Academics disclose new Collide+Probe and Load+Reload attacks on AMD CPUs.

AMD processors manufactured between 2011 and 2019 (the time of testing) are vulnerable to two new attacks, research published this week has revealed.The two new attacks impact the security of the data processed inside the CPU and allow the theft of sensitive information or the downgrade of security features.

The research team said it notified AMD of the two issues in August 2019, however, the company has not publicly addressed the two issues, nor has it released microcode (CPU firmware) updates.

An AMD spokesperson was not available for comment on this article.

THE L1D CACHE WAY PREDICTOR

The two new attacks target a feature of AMD CPUs known as the L1D cache way predictor.

Introduced in AMD processors in 2011 with the Bulldozer microarchitecture, the L1D cache way predictor is a performance-centric feature that reduces power consumption by improving the way the CPU handles cached data inside its memory.

A high-level explanation is available below:

The predictor computes a μTag using an undocumented hash function on the virtual address. This μTag is used to look up the L1D cache way in a prediction table. Hence, the CPU has to compare the cache tag in only oneway instead of all possible ways, reducing the power consumption.

The two new attacks were discovered after a team of six academics -- from the Graz University of Technology in Austria and the Univerisity of Rennes in France -- reverse-engineered this "undocumented hashing function" that AMD processors were using to handle μTag entries inside the L1D cache way predictor mechanism.

"Knowledge of these functions is the basis of our attack technique," the research team said.

Knowing these functions, allowed the researchers to recreate a map of what was going on inside the L1D cache way predictor and probe if the mechanism was leaking data or clues about what that data may be.

amd-tested-cpus.png


Read more: AMD processors from 2011 to 2019 vulnerable to two new attacks | ZDNet
 

My Computer My Computer

At a glance

64-bit Windows 11 Pro for WorkstationsIntel i7-8700K OC'd to 5 GHz64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600...ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
ooh joy that is just what we need another AMD vulnerability ....
what can we do about it?
 

My Computers My Computers

  • At a glance

    Windows 11 Pro (x64)AMD Ryzen 9 3900X 12-Core Processor32GB, 2x G.Skill 16GB (PC3200)(DDR4-2137)NVIDIA GeForce RTX 3070 Ti 8GB XC3 model by EVGA
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    [Self-built](custom-build)(June 2020)
    OS
    Windows 11 Pro (x64)
    CPU
    AMD Ryzen 9 3900X 12-Core Processor
    Motherboard
    Asus PRIME X570-PRO
    Memory
    32GB, 2x G.Skill 16GB (PC3200)(DDR4-2137)
    Graphics Card(s)
    NVIDIA GeForce RTX 3070 Ti 8GB XC3 model by EVGA
    Sound Card
    Realtek® ALC1220A 8-Channel High Definition Audio CODEC
    Monitor(s) Displays
    24" DELL Gaming Monitor - G2422HS - DisplayPort used
    Screen Resolution
    1920x1080p at 165Hz (16:9 Aspect Ratio)
    Hard Drives
    1TB Samsung 980 Pro (NVMe)(SSD)
    2TB Samsung 980 Pro (NVMe)(SSD)
    2TB Samsung 870 EVO (SSD)

    NVMe 1TB
    -- OS(Win10 Pro x64),
    -- programs,
    -- programming(MS Visual Studios 2022 Community Ed.),
    -- music

    NV
    PSU
    Thermaltake TOUGHPOWER DPS G RGB Titanium Certified 1250Watt
    Case
    Corsair Graphite Series 780T Full Tower PC Case
    Cooling
    AMD Wraith cooler (stock) & 3x Corsair case fans
    Keyboard
    Alienware Low Profile RGB Mechanical USB Gaming Keyboard - A
    Mouse
    Redragon M602 RGB Wired USB Gaming mouse
    Internet Speed
    2100Mbps Download, 350Mbps Upload
    Antivirus
    n/a aka "ABOVE TOP SECRET!" lol ;)
    Browser
    Firefox & Google Chrome
  • At a glance

    Windows 11 ProAMD Ryzen 7 5800H16GB DDR4Ryzen 7 5800H integrated AMD Radeon Graphics ...
    Computer type
    Laptop
    System Manufacturer/Model Number
    DELL G15 Ryzen edition, model 5515
    OS
    Windows 11 Pro
    CPU
    AMD Ryzen 7 5800H
    Motherboard
    DELL G15 Ryzen edition
    Memory
    16GB DDR4
    Graphics Card(s)
    Ryzen 7 5800H integrated AMD Radeon Graphics and Nvidia GeForce 3060 6GB
    Sound Card
    Realtek ALC3254 with Nahimic 3D Audio for Gamers
    Monitor(s) Displays
    built-in
    Screen Resolution
    1920x1080
    Hard Drives
    500GB NVMe SSD
    PSU
    DELL power brick.
    Case
    laptop
    Cooling
    laptop cooling
    Keyboard
    built-in
    Mouse
    Microsoft basic optical scroll mouse
    Internet Speed
    1000Mbps download, 20Mbps upload
    Browser
    Firefox & Waterfox Classic
Just stay away from unfamiliar and naughty places?
 

My Computer My Computer

At a glance

W7 Ultimate 32-bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
W7 Ultimate 32-bit
Motherboard
ASUS M4N68T-M V2
PSU
Seasonic G-series 650W, can't afford the X,still Top/Line.
Case
Cooler Master Storm Scout 2, Ghost White version.
Cooling
5 fans....no liquid needed, everything under 100F
Keyboard
veteran PS2
Mouse
veteran PS2
Internet Speed
50Mps
Antivirus
AVG 2016 + TinyWall-to enhance Windows 7 firewall.
Browser
several
Just stay away from unfamiliar and naughty places?
lol yup... I spend most of my time on Facebook... and familiar sites..
 

My Computers My Computers

  • At a glance

    Windows 11 Pro (x64)AMD Ryzen 9 3900X 12-Core Processor32GB, 2x G.Skill 16GB (PC3200)(DDR4-2137)NVIDIA GeForce RTX 3070 Ti 8GB XC3 model by EVGA
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    [Self-built](custom-build)(June 2020)
    OS
    Windows 11 Pro (x64)
    CPU
    AMD Ryzen 9 3900X 12-Core Processor
    Motherboard
    Asus PRIME X570-PRO
    Memory
    32GB, 2x G.Skill 16GB (PC3200)(DDR4-2137)
    Graphics Card(s)
    NVIDIA GeForce RTX 3070 Ti 8GB XC3 model by EVGA
    Sound Card
    Realtek® ALC1220A 8-Channel High Definition Audio CODEC
    Monitor(s) Displays
    24" DELL Gaming Monitor - G2422HS - DisplayPort used
    Screen Resolution
    1920x1080p at 165Hz (16:9 Aspect Ratio)
    Hard Drives
    1TB Samsung 980 Pro (NVMe)(SSD)
    2TB Samsung 980 Pro (NVMe)(SSD)
    2TB Samsung 870 EVO (SSD)

    NVMe 1TB
    -- OS(Win10 Pro x64),
    -- programs,
    -- programming(MS Visual Studios 2022 Community Ed.),
    -- music

    NV
    PSU
    Thermaltake TOUGHPOWER DPS G RGB Titanium Certified 1250Watt
    Case
    Corsair Graphite Series 780T Full Tower PC Case
    Cooling
    AMD Wraith cooler (stock) & 3x Corsair case fans
    Keyboard
    Alienware Low Profile RGB Mechanical USB Gaming Keyboard - A
    Mouse
    Redragon M602 RGB Wired USB Gaming mouse
    Internet Speed
    2100Mbps Download, 350Mbps Upload
    Antivirus
    n/a aka "ABOVE TOP SECRET!" lol ;)
    Browser
    Firefox & Google Chrome
  • At a glance

    Windows 11 ProAMD Ryzen 7 5800H16GB DDR4Ryzen 7 5800H integrated AMD Radeon Graphics ...
    Computer type
    Laptop
    System Manufacturer/Model Number
    DELL G15 Ryzen edition, model 5515
    OS
    Windows 11 Pro
    CPU
    AMD Ryzen 7 5800H
    Motherboard
    DELL G15 Ryzen edition
    Memory
    16GB DDR4
    Graphics Card(s)
    Ryzen 7 5800H integrated AMD Radeon Graphics and Nvidia GeForce 3060 6GB
    Sound Card
    Realtek ALC3254 with Nahimic 3D Audio for Gamers
    Monitor(s) Displays
    built-in
    Screen Resolution
    1920x1080
    Hard Drives
    500GB NVMe SSD
    PSU
    DELL power brick.
    Case
    laptop
    Cooling
    laptop cooling
    Keyboard
    built-in
    Mouse
    Microsoft basic optical scroll mouse
    Internet Speed
    1000Mbps download, 20Mbps upload
    Browser
    Firefox & Waterfox Classic
ooh joy that is just what we need another AMD vulnerability ....
what can we do about it?

https://www.amd.com/en/corporate/product-security
"We are aware of a new white paper that claims potential security exploits in AMD CPUs, whereby a malicious actor could manipulate a cache-related feature to potentially transmit user data in an unintended way. The researchers then pair this data path with known and mitigated software or speculative execution side channel vulnerabilities. AMD believes these are not new speculation-based attacks."

It seems it isn't a big deal.
 

My Computer My Computer

At a glance

windows seven
Computer type
PC/Desktop
OS
windows seven
Back
Top