Menu
New 'CacheOut' attack targets Intel processors, with a fix arriving soon

New 'CacheOut' attack targets Intel processors, with a fix arriving soon

Intel rates CacheOut as "medium" severity, and says that mitigations to address it will be published soon.

intel-10th-gen-core-ice-lake-cpu-100797959-orig.jpg

intel-10th-gen-core-ice-lake-cpu-100797959-orig.jpg

Credit: Intel

Researchers have discovered and published information on what they’re calling CacheOut, a vulnerability in most Intel CPUs that allows an attacker to target more specific data, even stored within Intel’s secured SGX enclave.

Intel assigned what’s known as the CVE-2020-0549 vulnerability a threat level of “medium,” acknowledging the danger of a targeted attack. The company noted that CacheOut has never been used outside of a laboratory environment.

Among the threats CacheOut poses is to cloud providers, and leaking data from hypervisors (virtual machine monitors) and the virtual machines running on them. Because the researchers disclosed the CacheOut vulnerability privately to Intel some time before making it public, those cloud providers have already deployed countermeasures against CacheOut. 

Intel said that it plans to release mitigations to address the issue in the near future. These normally are sent to users in the form of BIOS or driver updates.

Virtually all Intel processors are potentially affected by CacheOut, save for processors released after the fourth quarter of 2019. AMD processors are not affected, according to details released on a dedicated CacheOut site. Processors made by IBM and ARM may be affected, but have not been confirmed. The paper, by lead author researcher Stephan van Schaik of the University of Michigan and colleagues, has also been made public. 

CacheOut is another in the line of side-channel exploits that have targeted Intel processors, taking advantage of flaws in Intel’s architecture to attack data as it moves though various data buffers. (Those came to light as part of the Spectre and Meltdown vulnerabilities.) The CacheOut authors suggest that while older speculative execution attacks have resulted in data dumps, the new vulnerability could be used to generate more targeted attacks—that when combined with data-cleaning techniques, specific data could be more easily obtained than before. The CacheOut vulnerability cannot be stopped with Intel’s Spectre/Meltdown mitigations. 

The CacheOut authors said the vulnerability can be used to attack the unmodified Linux kernel, specifically attacking kernel address space layout randomization (KASLR) and recovering secret kernel stack canaries. The latter is specifically designed to protect against stack-based buffer overflow attacks. In addition, the authors believe that the attack could be used to break virtualization, leaking info from virtual machines that run on top of the same CPU core. Finally, the attack can force Intel’s Software Guard Extensions (SGX) to flush out decrypted data into a cache, where it can be read and analyzed using data-cleaning techniques. 

While van Schaik and the other researchers suggested that CacheOut could be mitigated by disabling hyperthreading or disabling TSX within Intel’s processors, the authors also noted that Intel will release mitigations to address the problem.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags intel

Events

Featured

Slideshows

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

This year’s Reseller News 30 Under 30 Tech Awards were held as an integral part of the first entirely virtual Emerging Leaders​ forum, an annual event dedicated to identifying, educating and showcasing the New Zealand technology market’s rising stars. The 30 Under 30 Tech Awards 2020 recognised the outstanding achievements and business excellence of 30 talented individuals​, across both young leaders and those just starting out. In this slideshow, Reseller News honours this year's winners and captures their thoughts about how their ideas of leadership have changed over time.​

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners
Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security

Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security

This exclusive Reseller News Exchange event in Auckland explored the challenges facing the partner community on the cloud security frontier, as well as market trends, customer priorities and how the channel can capitalise on the opportunities available. In association with Arrow, Bitdefender, Exclusive Networks, Fortinet and Palo Alto Networks. Photos by Gino Demeer.

Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security
Reseller News welcomes industry figures at 2020 Hall of Fame lunch

Reseller News welcomes industry figures at 2020 Hall of Fame lunch

Reseller News welcomed 2019 inductees - Leanne Buer, Ross Jenkins and Terry Dunn - to the fourth running of the Reseller News Hall of Fame lunch, held at the French Cafe in Auckland. The inductees discussed the changing face of the IT channel ecosystem in New Zealand and what it means to be a Reseller News Hall of Fame inductee. Photos by Gino Demeer.

Reseller News welcomes industry figures at 2020 Hall of Fame lunch
Show Comments