Meltdown and Spectre: The vulnerabilities of modern processors
An article in The Register revealed these potential vulnerabilities, initially reporting on their impact on Intel platforms, but later, a group of experts from Google's Project Zero, the companies Cyberus and Rambus, and several universities that discovered these vulnerabilities, published all the details, giving to know that their discoveries also affected processors AMD and ARM, besides Intel, manufactured during the last decade.
The vulnerabilities called Meltdown (CVE-2017-5754) and Spectre (CVE-2017-5753 and CVE-2017-5715) would take advantage of an error in the design of all the processors on the market that make use of the characteristics known as "speculative execution", consisting in that the processor executes code and arrives at a point in an algorithm in which the instructions are bifurcated in two different directions depending on the input data, these instructions save time by "speculating" with the path by which the process will continue to be executed.
The different technological companies, both at the level of processor manufacturing and operating system developers, are already working on the updates that provide solutions to these problems, although according to some developers and information, these patches could slow down the operating systems considerably.
- 02/01/2018 theregister.co.uk Kernel-memory-leaking Intel processor design flaw forces Linux, Windows redesign
- 03/01/2018 meltdownattack.com/ Meltdown and Spectre
- 04/01/2018 certsi.es Vulnerabilidades críticas en múltiples CPUs. Meltdown y Spectre
- 05/01/2018 unaaldia.hispasec.com Meltdown y Spectre: Graves vulnerabilidades en los procesadores de los principales fabricantes
- 03/01/2018 xataka.com Detectado un posible error masivo en el diseño de las CPU de Intel: solucionarlo ralentizará millones de ordenadores
- 04/01/2018 elpais.com Identificado un grave problema de seguridad en los procesadores Intel
- 04/01/2018 bbc.com Meltdown and Spectre: How chip hacks work
- 05/01/2018 krebsonsecurity.com Scary Chip Flaws Raise Spectre of Meltdown
- 10/01/2018 xataka.com Microsoft admite que sí habrá un impacto en el rendimiento de Windows ante los parches contra Spectre y Meltdown