New security flaw discovered at Intel: Downfall

Bad news for Intel, as a new security flaw has just been discovered. This vulnerability allows the theft of data, sometimes sensitive, via the processors used by the blue chip manufacturers. It’s called CVE-2022-40982, or Downfall.

Downfall: the new security flaw in Intel processors!

Faille de sécurité Intel Downfall

The first thing you need to know is that this flaw affects a large number of processors. Models from the 6th to the 11th generation are affected, from Skylake to Rocket Lake. However, new-generation CPUs don’t seem to be affected. So no need to panic if you have a Core i12 or i13 in your PC.

Secondly, you should know that Intel has already reacted by releasing microcode aimed at correcting or mitigating the flaw. Unfortunately, depending on the workload, the patch may have a significant impact on system performance. We’re talking about a perf loss of the order of 50% on certain heavy vector workloads in AVX-2 and AVX-512… Outch!

On the other hand, this security flaw seems to be really specific, with Intel leaving the possibility of disabling the patch in the event of too negative an impact on performance. What’s more, the blueprints indicate that this is a difficult flaw to exploit outside a controlled environment such as a lab.

Finally, how does the flaw work? This is where it gets complicated. Google researcher Daniel Moghomi explains that the root of the problem lies in the memory optimization features of the Intel processors concerned. These allow malware to access data stored by other programs that should not normally be accessible. Then, via Gather instructions, vector registers can be accessed during speculative executions. These functions leak data when they are supposed to speed up access to data scattered in memory.

As a result, a whole host of data can be accessed, such as encryption keys, user data and so on. In fact, during a demo, Daniel Moghomi was able to recover 100 AES-128-bit encryption keys versus 86 AES-256-bit ones, as well as Linux kernel data. But this is specific to certain AVX-2 and AVX-512 workloads using GATHER instructions, according to Phoronix.

Last NEWS

Related articles

spot_img