Skip to main content

Foreshadow L1TF CPU Vulnerabilities

Security researchers have released details of a family of speculative execution vulnerabilities affecting modern Intel CPUs. Side-channel attacks using these vulnerabilities could be used to gain access to sensitive information from OS kernels or SGX enclaves.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security researchers have released details of a family of speculative execution vulnerabilities affecting modern Intel CPUs. Side-channel attacks using these vulnerabilities could be used to gain access to sensitive information from OS kernels or SGX enclaves.


Affected platforms

The following platforms are known to be affected:

Versions: X-series, M, 2nd, 3rd, 4th, 5th, 6th, 7th, and 8th generation

Core

Xeon Processor Scalable Family

Threat details

Introduction

Foreshadow is a family of three speculative execution vulnerabilities in Intel central processing units (CPU) that allow an attacker with local user access to extract sensitive information from Software Guard Extensions (SGX) enclaves, virtual machines, hypervisors, operating system kernel memory and System Management Mode memory.


Details

The vulnerabilities are exploited using a side-channel method that Intel specifies as L1 Terminal Fault (L1TF). When a program instruction requires a virtual memory address to be converted to a physical memory address, and the address is not marked as present in the L1 cache, an L1TF is triggered. The implementation is vulnerable because the CPU speculatively reads and executes instructions on the addressed data in L1 cache before the L1TF is resolved and the results are discarded. This provides a window of opportunity where an attacker can extract any data that is present in the L1 cache.

The effect of this vulnerability is that malicious software may be able to infer the values of data in operating system memory, memory allocated to other applications, System Management Mode memory and memory allocated to SGX enclaves. Malicious guest virtual machines may be able to infer the values of data in the hypervisor's memory and memory allocated to other guests.


Threat updates

Date Update
11 Aug 2020 Research paper identifies errors in Foreshadow understanding

Security researchers have released a white paper claiming that the underlying issues causing Foreshadow, amongst a number of other side-channel attacks, have not been properly identified. This does not currently affect any Foreshadow remediation guidance.

For further information:


Remediation advice

Users and administrators are encouraged to review Intel's INTEL-SA-00161 security advisory and apply the relevant updates that have been released for operating systems, firmware and hypervisors.



Last edited: 11 August 2020 2:14 pm