'Inception' vulnerability could leak sensitive data on AMD Ryzen systems

DragonSlayer101

Posts: 372   +2
Staff
What just happened? Just days after reports emerged about the Zenbleed exploit affecting Zen 2-based AMD CPUs, researchers from ETH Zurich have detailed yet another critical vulnerability that affects a range of AMD processors with Zen cores. Called 'Inception,' the new security flaw can reportedly leak kernel memory and access sensitive files on Linux machines under certain conditions.

According to the report published by the researchers this week, the new vulnerability affects all AMD Ryzen CPUs with Zen cores, meaning a range of processors meant for desktops, laptops, data centers, and HEDT are vulnerable to the bug. As part of a proof-of-concept attack, researchers showed that it can leak kernel memory at a rate of up to 39 bytes per second on Zen 4 processors, enabling them to leak /etc/shadow on a Linux machine in just 40 minutes. The leaked file reportedly included hashed user account passwords and was only accessible by the root user.

In their report, the researchers said they used a previously disclosed vulnerability called 'Phantom speculation' to design a new class of transient execution attacks called Training in Transient Execution (TTE), which was then used to create Inception. Tracked as CVE-2023-20569, it is described as a speculative execution-based side-channel attack that can leak passwords and other sensitive data.

AMD has acknowledged the issue and is rolling out microcode updates to fix the problem with some of the affected processors. The company rated the severity level of Inception as 'medium' and said that the vulnerability is only exploitable locally, via downloaded malware. While that makes it relatively less dangerous than typical remote code execution flaws, it is still a cause for concern until the company is able to roll out updates for all the affected chips in its lineup. So, if you have a Zen-based AMD processor in your computer, install the latest available update as soon as possible, either from the PC vendor or as part of the OS security updates.

It is worth noting here that Inception only affects AMD chips, meaning people running Intel processors on their PCs or servers aren't affected by it. However, Team Blue is not entirely in the clear, as cybersecurity researchers have also recently detailed a side-channel attack called Downfall that affects many of its processors. According to reports, Intel's 6th-11th-gen Core processors are affected by Downfall, enabling attackers to potentially access data that should not be visible, such as cryptographic keys, etc.

Permalink to story.

 
:cold_sweat:Attention Mr. Phelps: This is yet another "security flaw" full of pre-conditions where you need to have access to the machine, it has to be running linux, and you have to have root access.

This post will self-destruct 15-seconds after you read it.
 
AMD already replied to this... and this all look like another Cyber Security propaganda stunt to get professional capital instead of really trying apply Cyber Serucity...

"AMD has received an external report titled ‘INCEPTION’, describing a new speculative side channel attack. AMD believes ‘Inception’ is only potentially exploitable locally, such as via downloaded malware, and recommends customers employ security best practices, including running up-to-date software and malware detection tools. AMD is not aware of any exploit of ‘Inception’ outside the research environment, at this time. "

https://www.phoronix.com/news/AMD-INCEPTION
 
I already have 1.2.0.A and this Inception fix comes with AGESA 1.2.0.B this month according to AMD security bulletin CVE-2023-20569.
 
In other news, Microsoft will require a new line of processors that support TPM vx.x for their newest OS release.
 
Nope will not patch this one. So sick of this crap. Why are researchers publishing the attack methods. I have no problem with them working on this quietly and telling AMD and Intel and giving generic details, put detailing how the exploit works in the public realm is criminally stupid.
 
Back