AMD Ryzen CPUs vulnerable to inception attack

Share post:

Researchers from ETH Zurich have discovered a new security vulnerability in AMD Ryzen CPUs that could allow attackers to leak kernel memory and access sensitive files. The vulnerability, called “Inception,” is a speculative execution-based side-channel attack that is similar to the Spectre and Meltdown vulnerabilities that affected Intel CPUs in 2018.

Inception affects all AMD Ryzen CPUs with Zen cores, including desktop, laptop, and server processors. This would enable malevolent actors to extract the ‘/etc/shadow’ file from a Linux machine within 40 minutes. This leaked file is reported to contain encrypted user account passwords, exclusively accessible to the root user.

Researchers substantiated their findings through a proof-of-concept demonstration, showcasing the leakage of kernel memory at a up to 39 bytes per second on Zen 4 processors. The threat actors also harnessed a previously identified vulnerability, termed ‘Phantom speculation,’ to devise a new category of transient execution attacks called ‘Training in Transient Execution (TTE).’ This new approach became the foundation for ‘Inception.’ Designated as CVE-2023-20569.

AMD has acknowledged the Inception vulnerability and is working on a fix. In the meantime, users of AMD Ryzen CPUs should update their operating systems and BIOS to the latest available versions.

The sources for this piece include an article in TechSpot.

SUBSCRIBE NOW

Related articles

Exploited ChatGPT Vulnerability Poses Risks to Organizations

A server-side request forgery (SSRF) vulnerability in OpenAI's ChatGPT infrastructure, tracked as CVE-2024-27564, is being actively exploited by...

Free Online File Converters Found Installing Malware: Malwarebytes Sounds the Alarm

Cybersecurity company Malwarebytes is urging internet users to exercise caution when seeking free online file conversion tools, warning...

Researchers Crack Akira Ransomware Using High-End GPUs

The Akira ransomware group emerged in 2023 with a mix of dark humour and ruthless tactics, famously requesting...

DOGE Staffer Sends Unencrypted Personal Data

Court documents reveal that Marko Elez, a staff member of the Department of Government Efficiency (DOGE), breached Treasury...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways