4 ms·
If you have SMAP, i.e. an Haswell or newer Intel CPU, you should not be vulnerable, so that could be an explanation.
by baghira 11y ago
If you have SMAP, i.e. an Haswell or newer Intel CPU, you should not be vulnerable, so that could be an explanation.
- javanix 11y agoIs SMAP required for mitigation, or is SMEP enough? IIUC SMEP is on Sandy Bridge processors too.
- baghira 11y agoAccording the lwn comments it should be sufficient (and the post by perception-point suggests that it would at least make things more difficult), but I haven't the hardware to test for myself.
- cmurf 11y agoI have Sandy Bridge, i7-2820QM. The exploit code has been running for nearly an hour, still "Increfing..." EDIT: [chris@f23m cve20160728]$ ./cve_2016_0728 PP_KEY uid=1000, euid=1000 Increfing... finished increfing forking... finished forking caling revoke... uid=1000, euid=1000 sh-4.3$
- benmmurphy 11y agoSMEP would stop this particular exploit because it returns into usermode but SMEP is trivial to bypass on linux if there is no KASLR or other mitigation (apparently there are compiler plugins that remove popular stack pivot gadgets).