3 ms·
Where does it say that older (Intel 5th generation and earlier) versions are affected?
by btdmaster 4y ago
Where does it say that older (Intel 5th generation and earlier) versions are affected?
- adrian_b 4y agoThey have not tested CPUs older than AMD Zen 1, but based on the similar branch predictors they suppose that Bulldozer derivatives and Jaguar/Puma might also be vulnerable. Similarly, on Intel they have not tested CPUs older than Kaby Lake, but due to the similar branch predictors they suppose that Skylake, Broadwell and Haswell might also be vulnerable. Older CPUs than that might not have indirect branch predictors or the indirect branch predictors might be too simple, so this attack method might not be applicable.
- btdmaster 4y agoI'm probably doing it wrong, but I'm getting SIGILL on Haswell for ret_bti and break_kaslr from the demo: https://github.com/comsec-group/retbleed https://github.com/comsec-group/retbleed Though it seems like the code is not portable (?) between CPU microarchitectures.
- adrian_b 4y agoSince the attack method depends heavily on details of the indirect branch predictor obtained through reverse engineering, it is very likely that the code must be adapted to each different microarchitecture. The demo code probably also works in Skylake, which is almost identical to Kaby Lake, but for Haswell and Broadwell it probably must be modified, even if it is expected that this should be possible.