MDS: Microarchitectural Data Sampling side-channel vulnerabilities in Intel CPUs

MDS: Microarchitectural Data Sampling side-channel vulnerabilities in Intel CPUs

RIDL (Rogue In-Flight Data Load) shows attackers can exploit MDS vulnerabilities to mount practical attacks and leak sensitive data in real-world settings. By analyzing the impact on the CPU pipeline, we developed a variety of practical exploits leaking in-flight data from different internal CPU buffers (such as Line-Fill Buffers and Load Ports), used by the CPU while loading or storing data from memory. We show that attackers who can run unprivileged code on machines with recent Intel CPUs – whether using shared cloud computing resources, or using JavaScript on a malicious website or advertisement – can steal data from other programs running on the same machine, across any security boundary: other applications, the operating system kernel, other VMs (e.g., in the cloud), or even secure (SGX) enclaves.

Source: mdsattacks.com