Intel and AMD chips are under attack from a new generation of Spectre threats

Meltdown and Spectre
(Image credit: Shutterstock)

It seems as Spectre still haunts Intel and AMD processors after cybersecurity researchers found new working speculative execution attacks.

To improve their performance, modern processors try to “guess” what tasks to do next. Speculative execution attacks abuse this mechanism to trick the computer into leaking private information, like passwords or other sensitive data, while it’s working ahead of time on the wrong guesses.

The most popular attack was called Spectre - first observed in early 2018, together with a sister vulnerability called Meltdown. At the time, it was said that most computers were vulnerable to Spectre and Meltdown, and the subsequent rush to fix the flaws made an even bigger mess, with some computers completely bricked as a result.

8BASE and Everest

Now, cybersecurity researchers Johannes Wikner and Kaveh Razavi from ETH Zurich claim that years after Spectre, there are multiple similar attacks that can work around existing defenses.

Among them are two methods that work on Linux, and affect a wide range of Intel processors (Intel’s 12th, 13th, and 14th chip generations for consumers, and 5th and 6th generation of Xeon processors for servers), and many AMD chips (Zen 1, Zen 1+, Zen 2).

The attacks undermine the Indirect Branch Predictor Barrier (IBPB) on x86 processors, it was explained. IBP is pivotal in defending against speculative execution attacks.

In the meantime, the researchers notified both Intel and AMD of their findings, and both companies have acknowledged the existence of the vulnerabilities. In fact, both said they already discovered them and are working on a fix. Intel is tracking it as CVE-2023-38575, and AMD is tracking it as CVE-2022-23824. Intel fixed it with a firmware update released in March, but according to BleepingComputer, the fix has not yet reached all operating systems.

Via BleepingComputer

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
AMD logo
AMD patches high severity security flaw affecting Zen chips
AMD Ryzen 5 7600X processor
AMD confirms processor security flaws after Asus patch slips out early
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
AMD logo
Security flaw means AMD Zen CPUs can be "jailbroken"
Security
Intel slams Nvidia and AMD, claims chip giants have huge numbers of security flaws
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
Latest in Security
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
person at a computer
Many workers are overconfident at spotting phishing attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Latest in News
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
An image of the Nintendo Switch 2
Nintendo Switch 2 could have AI upscaling similar to PS5 Pro’s PSSR according to patent, and it could be a gamechanger for graphics on the upcoming console
PowerColor Red Devil AMD RX 9070 XT graphics card shown side-on
Your next GPU could be from AMD, not Nvidia, if Team Red’s success with PC gamers continues
Quordle on a smartphone held in a hand
Quordle hints and answers for Tuesday, March 18 (game #1149)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Tuesday, March 18 (game #380)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Tuesday, March 18 (game #646)