Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Retbleed

From Wikipedia, the free encyclopedia
Speculative execution attack on x86–64 processors
See also:Transient execution CPU vulnerability
Retbleed
CVE identifier(s)CVE-2022-29900, CVE-2022-29901, CVE-2022-28693[dead link]

Retbleed is aspeculative execution attack onx86-64 andARM processors, including some recentIntel andAMD chips.[1][2] First made public in 2022, it is a variant of theSpectre vulnerability which exploitsretpoline, which was a mitigation for speculative execution attacks.[3]

According to the researchers, Retbleed mitigations require extensive changes to the system which results in up to 14% and 39% performance loss on Linux for affected AMD and Intel CPU respectively.[4] ThePoC works againstIntel Core 6th, 7th and 8th generation microarchitectures andAMD Zen 1, Zen 1+, and Zen 2 microarchitectures.

An official document from ARM informs that all ARM CPUs affected by Spectre are also affected by Retbleed.[2]

Windows is not vulnerable because the existing mitigations already tackle it.[1]Linux kernels 5.18.14 and 5.19 contain the fixes.[5][6] The 32-bit Linux kernel, which is vulnerable, will not receive updates to fix the issue.[7]

References

[edit]
  1. ^abClaburn, Thomas."AMD, Intel chips vulnerable to 'Retbleed' Spectre variant".www.theregister.com. Retrieved2022-07-12.
  2. ^abARM Developer."Q: Are Arm CPUs affected by the RETBLEED side-channel disclosed on the 13th July 2022?". Retrieved2022-07-13.
  3. ^Goodin, Dan (2022-07-12)."Intel and AMD CPUs vulnerable to a new speculative execution attack".Ars Technica. Retrieved2022-07-12.
  4. ^ETH Zurich Computer Security Group."Retbleed: Arbitrary Speculative Code Execution with Return Instructions". Retrieved2022-07-13.
  5. ^"Stable kernels 5.18.14 and 5.15.57 [LWN.net]".lwn.net. Retrieved2022-08-06.
  6. ^Sharwood, Simon (2022-07-17)."Torvalds: Linux kernel team has sorted Retbleed chip flaw".www.theregister.com. Retrieved2022-09-13.
  7. ^Michael Larabel (2022-07-24)."Linux x86 32-bit Is Vulnerable To Retbleed But Don't Expect It To Get Fixed".phoronix.com.

External links

[edit]
Variants
Topics
Hacking in the 2020s
← 2010sTimeline2030s →
Major incidents
2020
2021
2022
2023
2024
Groups
Individuals
Majorvulnerabilities
publiclydisclosed
Malware
2020
2021
2022
Retrieved from "https://en.wikipedia.org/w/index.php?title=Retbleed&oldid=1240427796"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2025 Movatter.jp