Intel’s STORM team finds vulnerability in AMD’s Spectre Mitigation

This week brought news of a new Spectre BHB vulnerability that only affects Intel and Arm chips, but Intel’s investigation into these new attack routes uncovered another issue: Since 2018, one of the patches AMD deployed to fix the Spectre vulnerabilities has been broken. STORM, Intel’s security team, discovered the flaw in AMD’s solution. As a result, AMD has published a security warning and modified its guidelines to offer an alternative way for mitigating the Spectre vulnerabilities, thus resolving the problem.

As a reminder, the Spectre flaws allow attackers to gain unrestricted and undetectable access to data being processed in a CPU via a side-channel attack that can be carried out remotely. Attackers can steal passwords and encryption keys, among other things, giving them complete access to a system.

Intel’s investigation into AMD’s Spectre fix starts in a roundabout way: despite using the Enhanced Indirect Branch Restricted Speculation (eIBRS) and/or Retpoline mitigations, Intel’s processors were recently found to be vulnerable to Spectre v2-based attacks via a new Branch History Injection variant.

Intel went to other mitigation strategies in search of a fresh Spectre mitigation approach to repair the far-flung vulnerability. There are a few more possibilities, but they all come with different levels of performance sacrifices. Intel claims that AMD’s LFENCE/JMP technology was requested by its ecosystem partners. The “LFENCE/JMP” mitigation, often known as “AMD’s Retpoline,” is a Retpoline alternative.

Intel’s study revealed that the mitigation AMD has been using to patch the Spectre vulnerabilities since 2018 isn’t enough – the processors are still vulnerable. The problem affects practically every recent AMD CPU, including the EPYC series of datacenter chips and nearly the entire Ryzen line for desktop PCs and laptops (second-gen through current-gen).

Spectre
credit: Intel

The paper’s abstract, titled “You Cannot Always Win the Race: Analyzing the LFENCE/JMP Mitigation for Branch Target Injection,” identifies three Intel authors: Alyssa Milburn, Ke Sun, and Henrique Kawakami, all of whom work for Intel’s STORM security team. The abstract briefly summarises the bug discovered by the researchers:

“LFENCE/JMP is an existing software mitigation option for Branch Target Injection (BTI) and similar transient execution attacks stemming from indirect branch predictions, which is commonly used on AMD processors. However, the effectiveness of this mitigation can be compromised by the inherent race condition between the speculative execution of the predicted target and the architectural resolution of the intended target, since this can create a window in which code can still be transiently executed. This work investigates the potential sources of latency that may contribute to such a speculation window. We show that an attacker can “win the race”, and thus that this window can still be sufficient to allow exploitation of BTI-style attacks on a variety of different x86 CPUs, despite the presence of the LFENCE/JMP mitigation.”

AMD released a security bulletin (AMD-SB-1026) in reaction to the STORM team’s findings and research, stating that it is not aware of any currently operational exploits employing the method outlined in the study. Customers are also advised to use “one of the other published mitigations (V2-1 nicknamed ‘generic retpoline’ or V2-4 aka ‘IBRS’),” according to AMD. The corporation also revised its Spectre mitigation guidelines [PDF] to reflect the modifications.

Also Read:
AMD Ryzen 7 5800X3D CPUs are out but strangely they don’t support overclocking

Source

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.

More like this

AMD Ryzen 9 8940HX: Next-Gen Laptop Powerhouse Unveiled

AMD Ryzen 9 8940HX: Next-Gen Laptop Powerhouse Unveiled

Discover the AMD Ryzen 9 8940HX: a 16-core beast with 32 threads, promising to revolutionize high-performance laptops...
AMD AI Event: Advancing AI 2025 Set to Transform the Industry with Next-Gen Technology

AMD AI Event: Advancing AI 2025 Set to Transform...

AMD AI Event: AMD has just announced a major industry event that promises to reshape the artificial...
AMD and Google Cloud Launch New VMs Powered by 5th Gen EPYC Processors

AMD and Google Cloud Launch New VMs Powered by...

In a groundbreaking collaboration that’s sending ripples through the tech world, AMD and Google Cloud have unveiled...
Intel

Intel Wins Nintendo Switch 3 GPU Battle, AMD Faces...

Intel clinches a Nintendo Switch 3 GPU deal with a 18A process, while AMD grapples with a...
AMD

AMD Surges Ahead in 2025: Gains 16.6% CPU Market...

In a dramatic shift in the CPU landscape, AMD has pulled off one of its biggest wins...

LATEST NEWS

IPL 2025: KL Rahul’s Blazing 93 Silences Chinnaswamy as DC Crush RCB

Royal Challengers Bengaluru (RCB) got off to a flying start, but for the next 16 overs or so, things quickly unraveled. Just when it...

Tuk Tuk: A Supernatural Comedy That Defies Expectations

In the vibrant landscape of Indian cinema, few films dare to challenge conventional storytelling quite like Tuk Tuk. This Telugu supernatural comedy emerges as...

Thunderbolts: The Void Rises in Marvel’s Most Dangerous Team-Up

In the ever-evolving Marvel Cinematic Universe, a new breed of heroes emerges from the shadows. The Thunderbolts represent a radical departure from traditional superhero...

Hyper Knife: The Psychological Chess Match of Survival

In the intricate world of medical psychological thrillers, Hyper Knife emerges as a masterpiece of narrative complexity. The series, starring Sul Kyung-gu and Park...

Featured