4 ms·
So thanks to Sandsifter we can fuzz test CPUs. Honest question: what's the implication of these illegal and undocumented instructions discovered by hardware fuz
by devy 9y ago
So thanks to Sandsifter we can fuzz test CPUs. Honest question: what's the implication of these illegal and undocumented instructions discovered by hardware fuzzing? Do we have to worry about new security vulnerabilities because of them?
- orik 9y agoI bet if there are any useful undocumented instructions you'll start seeing (not very serious) compiler modifications to support them at your own risk.
- greglindahl 9y agoWhy, yes, if you read the full research paper it points out that some classes of instructions have security implications.
- wongarsu 9y agoThey found a bunch of instructions, but for most of them we have no idea yet what they do. At least one instruction on some system can cause the system to hang. Some instructions might have interesting behavior on hypervisors. But most likely the vast majority is very boring and does nothing new or interesting.
- CyberDildonics 9y agoNot only hang, but hang in ring 3, meaning it could potentially freeze a CPU from a VM / Hypervisor