Gentoo Archives: gentoo-hardened

From: R0b0t1 <r030t1@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Re: [gentoo-hardened] Any hardened features to protect from CVE-2016–5195 like vulnerabilities?
Date: Wed, 07 Dec 2016 01:55:18
Message-Id: CAAD4mYgYtmko0T7MQePKV-GTbmbQ6nfZ4GqaApqFBHJVkBo2yA@mail.gmail.com
In Reply to: [gentoo-hardened] Re: [gentoo-hardened] Any hardened features to protect from CVE-2016–5195 like vulnerabilities? by "Tóth Attila"
1 On Mon, Dec 5, 2016 at 1:45 AM, "Tóth Attila" <atoth@××××××××××.hu> wrote:
2 > 2016.December 5.(H) 07:39 időpontban Andrew Savchenko ezt írta:
3 >> 3) Can some hardware features like Intel TSX be used to protect
4 >> from such race conditions?
5 >
6 > Just a sidenote on TSX: although it sounds procmising, I've been seeing
7 > multiple reports on Intel disabling the feature on several processors by
8 > microcode update due to various bugs since its debut. Not just some
9 > Haswell and Broadwell, but also some Skylake prcoessors are involved as
10 > well.
11
12 This is a good point - the hardware needs to be properly implemented
13 as well. There have already been cases where improper implementation
14 and unaccounted-for physical interactions have been used to elevate
15 permissions.
16
17
18 > BR: Dw.
19 > --
20 > dr Tóth Attila, Radiológus, 06-20-825-8057
21 > Attila Toth MD, Radiologist, +36-20-825-8057
22 >
23 >

Replies