3 ms·
Has anyone actually confirmed this bug? The author seems to be an expert in low-level DMA security, but it would be nice to see independent confirmation. Readin
by computator 9y ago
Has anyone actually confirmed this bug? The author seems to be an expert in low-level DMA security, but it would be nice to see independent confirmation. Reading through the comments so far, it doesn't seem so. The closest anyone comes is this: https://news.ycombinator.com/item?id=16693599 https://news.ycombinator.com/item?id=16693599
I was hoping to see someone who said:
(1) I tested a Windows 7 X64 machine without the Meltdown patch (pre-December 2017) and couldn't read arbitrary memory.
(2) Next I tested with Microsoft's Meltdown patch KBnnnnnnn (Jan or Feb 2018) and could read arbitrary memory. The system is insecure.
(3) I then tested with Microsoft patch KBnnnnnnn (March 2018) and can no longer read arbitrary memory. They fixed it.
- caf 9y agoI did use a modified version of my short test program to actually test modifying the page tables to read a chosen physical address, which worked just fine. The bug is real.
- BrianG61UK 9y agoAnd KBnnnnnn that fixes it is which KB?
- deleted 9y ago[deleted]
- BrianG61UK 9y agoI finally found the fix. It's KB4100480. It makes the little test crash as it should. Phew!