Technology Today

AMDs processors from as early as 2011 through to 2019 are carrying vulnerabilities that are as yet unpatched, according to some freshly published research.Known as Take A Way (every security problem needs a snappy name, of course), security researchers said that they reverse-engineered the L1D cache way predictor in AMD silicon in order to discover two new potential attack vectors.Given all the attention which has been focused on the flaws in Intels CPUs in recent times vulnerabilities which havent affected AMD chips in a number of cases this might just serve as a reminder that no ones silicon is bulletproof.As spotted by Toms Hardware, Graz University of Technology released a paper detailing the vulnerabilities which AMD was informed of back in August 2019, although as mentioned, a fix has yet to be deployed.The pair of exploits, dubbed Collide+Probe and Load+Reload, are side channel attacks (in the same vein as Spectre) that manipulate the aforementioned L1D cache predictor in order to access data that should otherwise be secure and unobtainable.The paper (a PDF shared on Twitter by researcher Moritz Lipp) explains: With Collide+Probe, an attacker can monitor a victims memory accesses without knowledge of physical addresses or shared memory when time-sharing a logical core.With Load+Reload, we exploit the way predictor to obtain highly-accurate memory-access traces of victims on the same physical core.
While Load+Reload relies on shared memory, it does not invalidate the cache line, allowing stealthier attacks that do not induce any last level-cache evictions.The security researchers have already successfully leveraged these exploits on some common browsers, namely Chrome and Firefox.
One of the researchers, Michael Schwarz, said that Collide+Probe has already been demonstrated being successfully leveraged via JavaScript in a browser, requiring no user interaction.The paper doesnt just outline the problems here, though, but also provides potential solutions through both hardware and software mitigations, although no comment is made on whether software patches might be detrimental to system performance (as you may recall, there was a big fuss about this when it came to fixing Meltdown and Spectre).AMD has yet to comment on the affair, but were guessing that situation will change soon enough.As an interesting side-note, Toms observes that Hardware Unboxed spotted that additional funding for the paper came from Intel, and questions have been raised by some about potential conflicts of interest in that respect.Another of the researchers, Daniel Gruss, addressed the matter on Twitter to note that he wouldnt accept any funding which restricted his academic freedom and independence.





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Sky TV block as brand-new crackdown interrupts UK homes from viewing content totally free


Sky's biggest-ever conserving on Gigafast broadband cuts £& pound; 96 off the ultimate upgrade


Google is fixing a major issue with your Gmail inbox, and free upgrade is coming soon


Top Tech: 5 Amazon-rivalling deals from Apple, Samsung, Shark and more


Amazon Prime Day: Favourite tech gizmos and home appliances we actually use and love


Consumers can get an Echo Pop speaker for less than ₤ 6 if they do one easy thing


Sky is dispensing a huge upgrade, however just if your postcode is on this list


Amazon slashes ₤ 450 off Shark self-emptying robotic vacuum in mega Prime Day offer


Newest Kindle hits lowest ever cost in Amazon Prime Day deal with over ₤ 100 off


Samsung unveils new Galaxy, and it makes your current Android phone appearance extremely inferior


Simply hours remain on Virgin Media's complimentary 4K TV deal - act quickly


Everyone with an Android phone placed on red alert as massive new threat validated


The 'finest' smart device of 2025 confirmed - has the iPhone or Android come out on top


Amazon's best Apple deals for Prime Day consisting of iPhone, iPad and AirPods


Tech professional warns 'never state yes' to 3 questions from callers you don't recognise


Millions of Brits 'forced to function as online security guards' for elderly family members


Leading Tech: Virgin Media's totally free television giveaway ends quickly as 48-hour countdown begins


All Amazon Prime users put on high alert - you need to follow 4 new rules today


Amazon gives you 3 reasons to ditch your Fire TV Stick and try something new this week


Apple fans rush for 22% off AirPods Pro 2 as Amazon Prime Day kicks off


Paramount+ drops to £3.99 in half price sale ending this week


Amazon is handing out free Echo speakers this week and here's how to get yours


AI is the 'best organization partner' says youngest self-made female billionaire


Everyone using Amazon issued with an urgent 'don't click' warning this week


Sky is dishing out free TV channel upgrades, and here's how to watch it


Apple fans rushing for ₤ 35 iPhone 16 Pro Max as Sky uses payday deal