AMD: Microcode Signature Verification Vulnerability
31–40 of 107 posts
Re: AMD: Microcode Signature Verification Vulnerability
#32I don't know how exploitable this really is, as a lot of Linux systems load microcode at boot time... once it's been loaded, I don't think it's possible to load another one (outside of rebooting).
https://wiki.archlinux.org/title/Microcode#Late_loading
https://docs.kernel.org/arch/x86/microcode.html#late-loading
although quotes from this article claim that it's fine specifically on AMD systems:
Re: AMD: Microcode Signature Verification Vulnerability
#33Doesn't this give enough detail for someone to replicate easily? I'd think it would not be too hard to look at the signature and find the insecure function used.
I would speculate that the problem is less that the hash function is weak inherently (otherwise we'd have a really complicated horizon of needing to chain microcode updates since we'd eventually want to e.g. go from MD5 to SHA1 or something), and more that the implementation has a flaw (similar to things like Nintendo using strcmp and not memcmp on their hash comparisons in the Wii, so you only had to collide the function to the first \0).
Re: AMD: Microcode Signature Verification Vulnerability
#34As an end user, I wonder how my cloud provider can prove to me that they installed AMD's fix and are not simply running a malicious version of the microcode on their CPU that claims to have the fix.
Re: AMD: Microcode Signature Verification Vulnerability
#35I don't know how exploitable this really is, as a lot of Linux systems load microcode at boot time... once it's been loaded, I don't think it's possible to load another one (outside of rebooting).
It is possible, but it's generally not a good idea. https://wiki.archlinux.org/title/Microcode#Late_loading https://docs.kernel.org/arch/x86/microcode.html#late-loading although quotes from this article claim that it's fine specifically on AMD systems: https://www.phoronix.com/news/AMD-Late-Loading-Microcode
(I believe this example would also still break on AMD-based systems, AMD just hasn't killswitched a CPUID feature flag yet AFAIR...)
Re: AMD: Microcode Signature Verification Vulnerability
#36Re: AMD: Microcode Signature Verification Vulnerability
#37> A test payload for Milan and Genoa CPUs that makes the RDRAND instruction return 4 I would be tickled pink if the 4 was in reference to https://xkcd.com/221/
Hi, I'm one of the authors and yes it was :)
Re: AMD: Microcode Signature Verification Vulnerability
#38As an end user, I wonder how my cloud provider can prove to me that they installed AMD's fix and are not simply running a malicious version of the microcode on their CPU that claims to have the fix.
Try to install your own patch for RDRAND and check that it is returning 4? Of course, getting 4 multiple times doesn't mean you have succeeded [0]. [0] https://duckduckgo.com/?q=dilbert+random+generator+nine+nine... (couldn't find a good link to the comic)
Re: AMD: Microcode Signature Verification Vulnerability
#39As an end user, I wonder how my cloud provider can prove to me that they installed AMD's fix and are not simply running a malicious version of the microcode on their CPU that claims to have the fix.
In theory the PSP should probably attest the microcode but I don't know if that exists.
[0] - https://www.amd.com/content/dam/amd/en/documents/epyc-techni...