Meltdown explains the mysterious page table patches
Summary
The Meltdown researchers show how speculative execution makes protected kernel memory readable via cache side channels and why KPTI helps. Meltdown was assigned CVE-2017-5754. KAISER made the attack harder as an unintended side effect.
Ideas
- Modern processors execute instructions speculatively before permission checks are complete.
- Discarded results can leave measurable traces in the cache.
- An attacker reconstructs kernel bytes from access times.
- KPTI largely removes kernel mappings from user page tables.
Insights
- Microarchitectural traces can undermine architectural access controls.
- Performance optimisations extend security models deep into hardware states.
- Operating systems can mitigate hardware flaws but pay run-time costs.
Recommendations
- Install kernel and microcode updates together.
- Measure the impact of KPTI with real workloads instead of synthetic assumptions.
References
Links to the original source and the Web Archive open in a new tab.