OSes suffer serious security hole through CPUs

Colin Percival, a FreeBSD committer and security team member, has found a local exploit against the current implementation of Intel’s Hyper-Threading Technology. “Hyper-Threading, as currently implemented on Intel Pentium Extreme Edition, Pentium 4, Mobile Pentium 4, and Xeon processors, suffers from a serious security flaw,Colin explains. “This flaw permits local information disclosure, including allowing an unprivileged user to steal an RSA private key being used on the same machine. Administrators of multi-user systems are strongly advised to take action to disable Hyper-Threading immediately.

32 Comments

  1. 2005-05-13 3:02 pm
  2. 2005-05-13 3:05 pm
  3. 2005-05-13 3:13 pm
  4. 2005-05-13 3:24 pm
  5. 2005-05-13 3:33 pm
  6. 2005-05-13 3:44 pm
  7. 2005-05-13 3:49 pm
  8. 2005-05-13 4:07 pm
  9. 2005-05-13 4:13 pm
  10. 2005-05-13 4:25 pm
  11. 2005-05-13 4:28 pm
  12. 2005-05-13 4:40 pm
  13. 2005-05-13 4:44 pm
  14. 2005-05-13 5:27 pm
  15. 2005-05-13 5:36 pm
  16. 2005-05-13 5:42 pm
  17. 2005-05-13 5:46 pm
  18. 2005-05-13 6:07 pm
  19. 2005-05-13 7:24 pm
  20. 2005-05-13 7:46 pm
  21. 2005-05-13 8:01 pm
  22. 2005-05-13 9:18 pm
  23. 2005-05-13 9:46 pm
  24. 2005-05-13 10:52 pm
  25. 2005-05-13 10:52 pm
  26. 2005-05-14 1:29 am
  27. 2005-05-14 2:14 am
  28. 2005-05-14 8:34 am
  29. 2005-05-14 9:37 am
  30. 2005-05-14 11:41 am
  31. 2005-05-15 11:10 am