3 ms·
This is incredibly scary. On my Zen 2 box (Ryzen 3600) logging the output of the exploit running as an unprivileged user while copying and pasting a string into
by eric__cartman 3y ago
This is incredibly scary. On my Zen 2 box (Ryzen 3600) logging the output of the exploit running as an unprivileged user while copying and pasting a string into a text editor in the background (I used Kate), resulted in pieces of the string being logged into the output of zenbleed. And this is after a few seconds of runtime mind you, not even a full minute.
Thankfully the exploit is highly dependent on a specific asm routine so exploiting it from JS or WASM in a browser should be extremely difficult. Otherwise a nefarious tab left open for hours in the background could exfiltrate without an issue.
I'm eagerly waiting for Fedora maintainers to push the new microcode so the kernel can update it during the boot process.
- loeg 3y ago> Thankfully the exploit is highly dependent on a specific asm routine so exploiting it from JS or WASM in a browser should be extremely difficult. Otherwise a nefarious tab left open for hours in the background could exfiltrate without an issue. At least one commentor here claims to be able to reproduce this with javascript: https://news.ycombinator.com/item?id=36849767 https://news.ycombinator.com/item?id=36849767 .
- IshKebab 3y agoA very bold claim with zero evidence.
- zekica 3y agoI tried on my zen 2 box, and the same things works even when the exploit is run in a KVM.
- kludge41 3y agoHow do you build the POC? I get "No such file or directory" and error 127 on Ubuntu.
- eric__cartman 3y agoI had to run make on the uncompressed folder. Perhaps the build-essential package doesn't come with NASM in Ubuntu? I'll need a bit more info on the error if you want me to try and help you :)
- kludge41 3y agoAfter extracting the POC and installing build-essential, I still get this: nasm -O0 -felf64 -o zenleak.o zenleak.asm make: nasm: No such file or directory make: ** [Makefile:11: zenleak.o] Error 127
- eric__cartman 3y agoInstall the nasm package. It's probably not included in build-essencial.
- kludge41 3y agoThank you. I guess I should've read the error better, but I thought nasm was the thing complaining.
- JonathonW 3y agoThe parent commenter seems to have figured this out, but to clarify a bit for posterity: build-essential does not come with nasm on Ubuntu (or upstream Debian, AFAICT). It has to be installed separately for the Zenbleed PoC to compile (if not already installed).
- slappy7 3y ago> Thankfully the exploit is highly dependent on a specific asm routine so exploiting it from JS or WASM in a browser should be extremely difficult. I assume that once/if a method is found it will be applicable broadly though. At the same time, hopefully software patches in V8 and SpiderMonkey will be able to mitigate this further and sooner. But a JS exploit would require some way to exfiltrate data and presumably doing that would be quite difficult to hide entirely.