Forum Moderators: open

Message Too Old, No Replies

Intel Patches high-severity CPU bug

         

engine

2:40 pm on Nov 15, 2023 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Intel has fixed a high-severity CPU bug that allows code running inside a VM to crash hypervisors, and has the potential to allow malicious exploits.

The flaw, affecting virtually all modern Intel CPUs, causes them to “enter a glitch state where the normal rules don’t apply,” Tavis Ormandy, one of several security researchers inside Google who discovered the bug, reported. Once triggered, the glitch state results in unexpected and potentially serious behavior, most notably system crashes that occur even when untrusted code is executed within a guest account of a virtual machine, which, under most cloud security models, is assumed to be safe from such faults. Escalation of privileges is also a possibility.


[arstechnica.com...]