What you need to know
- Researchers discovered two new attacks that AMD processors are vulnerable to.
- AMD processors from 2011-2019 are vulnerable to the attacks.
- While the vulnerabilities lead to security risks, they are not as bad as well-known vulnerabilities Meltdown and Zombieland.
Researchers discovered two new vulnerabilities that can affect AMD processors from between 2011-2019. The attacks, called Collide+Probe and Load+Reload affect the security of data processed by affected AMD CPUs. As a result, attackers can steal information or affect security features. A team of six researchers from Graz University of Technology in Austria and the University of Rennes in France details their discoveries in an extensive document.
The team of researchers states that they contacted AMD regarding the issues in August of 2019, but AMD has not released firmware updates related to the issue since then. AMD states that the attacks "are not new speculation-based attacks." The research team disagrees with AMD's claim.
The attacks work by targetting the L1D cache way predictor. This feature improves the way CPUs handle cached data, which reduces power consumption. Below is a detailed explanation from the researchers' document:
The researchers also break down how they exploited the attacks:
AMD issued a response to the issue, in which it states, "AMD believes these are not new speculation-based attacks." AMD believes "this issue can be mitigated in software by using side-channel counter measures." The research team that discovered the attacks told ZDNet that AMD's response is "rather misleading" and added that AMD never engaged with the research team about the attacks. Additionally, the research team states that the attacks still work on full-update operating systems.
While these attacks present a security risk, Daniel Gruss, one of the researchers that discovered the attacks, stated on Twitter that they aren't as dangerous as Meltdown and Zombieload. He said in response to another Twitter user, "The attacks leak a few [bits] of meta-data. Meltdown and Zombieload leak tons of actual data."
Sean Endicott is the news writer for Windows Central. If it runs Windows, is made by Microsoft, or has anything to do with either, he's on it. Sean's been with Windows Central since 2017 and is also our resident app expert. If you have a news tip or an app to review, hit him up at firstname.lastname@example.org.
Intel will be like: "First Time?" 🤣
Get the best of Windows Central in in your inbox, every day!
Thank you for signing up to Windows Central. You will receive a verification email shortly.
There was a problem. Please refresh the page and try again.