3 ms·
I understood everything up until the "suppose we flush our cache before executing the code" part which is probably the most important part. There was a comment
by styfle 9y ago
I understood everything up until the "suppose we flush our cache before executing the code" part which is probably the most important part.
There was a comment below the article that explained this part a little further:
> Imagine the value at the kernel address, which gets loaded into _w, was 0xabde3167. Then the value of _x is 0x100, and address user_mem[0x100] will end up in the cache. A subsequent load of user_mem[0x100] will be fast.
> Now imagine the value at the kernel address, which gets loaded into _w, was 0xabde3067. Then the value of _x is 0x000, and address user_mem[0x000] will end up in the cache. A subsequent load of user_mem[0x100] will be slow.
> So we can use the speed of a read from user_mem[0x100] to discriminate between the two options. Information has leaked, via a side channel, from kernel to user.
https://www.raspberrypi.org/blog/why-raspberry-pi-isnt-vulnerable-to-spectre-or-meltdown/#comment-1375375 https://www.raspberrypi.org/blog/why-raspberry-pi-isnt-vulne...
- JdeBP 9y agoYes, that is the this is left as an exercise for the reader part of the explanation. (-: The remaining part is to iterate the process over all of the bits in the word, using different bitmasks. The resultant set of 0 or 1 results for each bit yields the complete word. Then one iterates that whole process over all (useful) words in (mapped) kernel memory.
- rofex 9y agoThanks, this was the missing piece in my understanding. I was wondering how only knowing only 1 bit would be useful. Suppose the attacker wants to read this entire address (0xabde3167) using this method. Is it guaranteed that over multiple runs, this address would be the same each time at that point in execution?
- ufo 9y agoIt is certainly possible that the memory the exploit is trying to read might be changing under its nose. An actual implementation of the exploit would need to account for that.
- pqh 9y agoHow might one know which address to attack like this? I thought memory was fairly randomly laid out.
- deleted 9y ago[deleted]