PortSmash Intel CPU Side-Channel Vulnerability
Researchers have developed a new side-channel attack called PortSmash which takes advantage of a vulnerability in Intel central processing units (CPUs) with simultaneous multi-threading (SMT) enabled.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Researchers have developed a new side-channel attack called PortSmash which takes advantage of a vulnerability in Intel central processing units (CPUs) with simultaneous multi-threading (SMT) enabled.
Threat details
A proof-of-concept exploit developed by the researchers uses a timing attack to steal information from other processes running in the same CPU core with SMT enabled. Using this method, researchers were able to determine the private decryption key from an OpenSSL thread running in the same core as their exploit.
For further information:
- CVE-2018-5407
- PortSmash Proof-of-Concept
Remediation steps
| Type | Step |
|---|---|
|
At time of publication the only way to mitigate this vulnerability is by disabling SMT/Hyper-Threading via the BIOS or operating system. Users and administrators are encouraged to visit the Intel Product Security Center Advisories page and check for any advice or security updates that may become available. Users and administrators of OpenSSL are encouraged to review the security fixes for CVE-2018-0734 and CVE-2018-0735 and apply the necessary updates. |
CVE Vulnerabilities
Last edited: 17 February 2020 12:52 pm