Intel patches a bug affecting virtually all modern Intel CPUs that lets code running inside a VM crash hypervisors, a risk to cloud providers in particular
Among other things, bug allows code running inside a VM to crash hypervisors. — Intel on Tuesday pushed microcode updates to fix …
The new issue matters especially in virtualized environments because a guest workload can affect the hypervisor layer that separates workloads. It shifts attention from confidentiality-focused CPU flaws toward cloud-service availability and isolation.
First-order effects
Cloud providers and other operators of Intel-based virtualized fleets need to apply Intel's microcode update and validate hosts, since code inside a VM can otherwise crash the hypervisor.
Cloud operators may tighten maintenance, host-validation, and tenant-isolation procedures around microcode rollouts, because a hypervisor crash can disrupt more than the workload that triggers it.
Server customers evaluating processor platforms will weigh not just performance and price but the vendor's vulnerability-response and patch-operability record, alongside Intel's earlier disclosures of enclave and cross-core flaws.
Third-order effects
If CPU issues continue to reach the virtualization boundary, hardware-security maintenance becomes a core availability requirement for multi-tenant infrastructure rather than a back-office patching task.
The pattern could favor cloud architectures that can isolate, drain, and update hosts with limited customer disruption; the corpus does not establish whether this specific flaw will change provider purchasing decisions.
The trend: CPU security is increasingly being judged through the resilience of shared cloud infrastructure and the operational quality of vendor microcode updates.
If we had Red Unlock for Ice/Tiger/Rocket Lake (the work is in progress now) we would see these currupted ROB entries via LDAT port and could suppose what and how fields are affected...
Yey SiliFuzz! “This bug was independently discovered by multiple research teams within Google, including the silifuzz team and Google Information Security Engineering.”
This has been a very interesting bug to analyze! Every day we have ideas, spend all day experimenting and finish the day with a new hypothesis. Progress can be measured by how much we've learnt (-:
@taviso @_markel___ > However, we simply don't know if we can control the corruption precisely enough to achieve privilege escalation. Intel seems to think it's possible: https://www.intel.com/...
If you like weird CPU bugs, check out Reptar CVE-2023-23583: https://lock.cmpxchg8b.com/... Affected Intel CPUs include: Ice Lake Rocket Lake Tiger Lake Raptor Lake Alder Lake Sapphire Rapids Apply those firmware updates! https://www.intel.com/...
New write-up on an Intel Ice Lake CPU vulnerability, we can effectively corrupt the RoB with redundant prefixes! 🔥 An updated microcode is available today for all affected products, cloud providers should patch ASAP. https://lock.cmpxchg8b.com/...
Popular opinion 🚨 I'd love if Intel shared the details (or some basic PoC) of the privilege escalation path that the Intel engineers found. This bug is particularly challenging to reverse engineer, I'd love to read more opinions on it. https://www.intel.com/...
We found another vulnerability inside Intel CPUs. Somehow instruction prefixes that should be ignored mess up the “fast rep mov” extension and causes invalid instruction execution: - Rent a guest VM and MCE an entire server. - EoP is possible according to Intel (Severity high)
Another great CPU vuln catch from @Google's @taviso (CVE-2023-23583)! Happy to see such a successfully coordinated disclosure with @Intel and our industry peers to secure online users: https://cloud.google.com/...
Another great CPU vuln catch from @Google's @taviso (CVE-2023-23583)! Happy to see such a successfully coordinated disclosure with @Intel and our industry peers to secure online users: https://cloud.google.com/...