L1DES and VRS make Intel chips vulnerable
Summary
In January 2020 Intel disclosed two further variants of Microarchitectural Data Sampling, found by the University of Michigan and VU Amsterdam. With L1DES, alias CacheOut (CVE-2020-0549), data is evicted from the L1 data cache into the fill buffer and can be read there; with VRS, vector registers are affected. Kaby Lake, Coffee Lake, Whiskey Lake and Cascade Lake, among others, were affected, and Intel announced microcode updates.
Ideas
- Speculative execution leaves traces in internal buffers.
- Earlier MDS mitigations did not cover these variants.
- Microcode updates are the main way to mitigate hardware holes.
Insights
- Spectre and Meltdown were followed by a long series of related holes.
- Shared hardware remains a trust boundary that software can only partly protect.
Facts
- CacheOut has the identifier CVE-2020-0549.
- Server CPUs of the Cascade Lake generation were also affected.
- VRS is a variant of RIDL and has the identifier CVE-2020-0548.
References
Critique
- The report does not say how realistic an attack is outside laboratory conditions.
Recommendations
- Apply microcode updates promptly via the operating system or BIOS.
- Check the protection status under /sys/devices/system/cpu/vulnerabilities.
- Disable TSX if your applications do not use it, as the researchers recommend.
Links to the original source and the Web Archive open in a new tab.