8 ms·
The ebpf is not the exploit. The ebpf was used in the proof of concept to generate a gadget in the victim process (in this case the kernel). Similar code patter
by twtw 8y ago
The ebpf is not the exploit. The ebpf was used in the proof of concept to generate a gadget in the victim process (in this case the kernel). Similar code patterns already existed in the kernel, the authors just used ebpf to make their own so they didn't have to hunt one down.
If you don't believe me, perhaps the document making its way into the kernel source (and the review comments) will make things clear: https://lkml.org/lkml/2018/12/21/577 https://lkml.org/lkml/2018/12/21/577
If you are still not convinced, take a look at these patches merged into Linux to mitigate a vulnerability you are arguing doesn't exist: https://lkml.org/lkml/2018/1/5/769 https://lkml.org/lkml/2018/1/5/769
Spectre V1 can be exploited by simply passing parameters to code that runs in another process. It does not require that the attacker can run code in the victim process.