Your browser does not fully support modern features. Please upgrade for a smoother experience.
Submitted Successfully!
Thank you for your contribution! You can also upload a video entry or images related to this topic. For video creation, please contact our Academic Video Service.
Version Summary Created by Modification Content Size Created at Operation
1 handwiki Camila Xu -- 1055 2022-11-14 01:42:32

Video Upload Options

We provide professional Academic Video Service to translate complex research into visually appealing presentations. Would you like to try it?
Cite
If you have any further questions, please contact Encyclopedia Editorial Office.
HandWiki. Transient Execution CPU Vulnerability. Encyclopedia. Available online: https://encyclopedia.pub/entry/34347 (accessed on 22 September 2026).
HandWiki. Transient Execution CPU Vulnerability. Encyclopedia. Available at: https://encyclopedia.pub/entry/34347. Accessed September 22, 2026.
HandWiki. "Transient Execution CPU Vulnerability" Encyclopedia, https://encyclopedia.pub/entry/34347 (accessed September 22, 2026).
HandWiki. (2022, November 14). Transient Execution CPU Vulnerability. In Encyclopedia. https://encyclopedia.pub/entry/34347
HandWiki. "Transient Execution CPU Vulnerability." Encyclopedia. Web. 14 November, 2022.
Transient Execution CPU Vulnerability
Edit

Transient execution CPU vulnerabilities are vulnerabilities in a computer system in which a speculative execution optimization implemented in a microprocessor is exploited to leak secret data to an unauthorized party. The classic example is Spectre that gave its name to this kind of side-channel attack, but since January 2018 many different vulnerabilities have been identified.

speculative execution vulnerabilities microprocessor

References

  1. Kocher, Paul; Horn, Jann; Fogh, Anders; Genkin, Daniel; Gruss, Daniel. "Spectre Attacks: Exploiting Speculative Execution". https://spectreattack.com/spectre.pdf. 
  2. Cutress, Dr Ian. "AMD Issues Updated Speculative Spectre Security Status: Predictive Store Forwarding". https://www.anandtech.com/show/16604/amd-issues-updated-speculative-spectre-security-status-predictive-store-forwarding. 
  3. "Benchmarking AMD Zen 3 With Predictive Store Forwarding Disabled - Phoronix". https://www.phoronix.com/scan.php?page=article&item=amd-zen3-psf&num=1. 
  4. "Rage Against the Machine Clear" (in en-US). https://www.vusec.net/projects/fpvi-scsb/. 
  5. Ltd, Arm. "Speculative Processor Vulnerability | Frequently asked questions" (in en). https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability/frequently-asked-questions. 
  6. "Transient Execution of Non-canonical Accesses". https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1010. 
  7. Musaev, Saidgani; Fetzer, Christof (2021). "Transient Execution of Non-Canonical Accesses". https://arxiv.org/ftp/arxiv/papers/2108/2108.10771.pdf. 
  8. Francisco, Thomas Claburn in San. "Boffins find if you torture AMD Zen+, Zen 2 CPUs enough, they are vulnerable to Meltdown-like attack" (in en). https://www.theregister.com/2021/08/30/amd_meltdown_zen/. 
  9. https://developer.amd.com/wp-content/resources/90343-D_SoftwareTechniquesforManagingSpeculation_WP_9-20Update_R2.pdf
  10. Lipp, Moritz; Gruss, Daniel; Schwarz, Michael (2021-10-19). "AMD Prefetch Attacks through Power and Time" (in en). USENIX Security Symposium. https://publications.cispa.saarland/3507/. 
  11. "AMD Prefetch Attacks through Power and Time". https://publications.cispa.saarland/3507/1/amd_prefetch_sec22.pdf. 
  12. "Side-channels Related to the x86 PREFETCH Instruction". https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1017. 
  13. "Affected Processors: Transient Execution Attacks & Related Security..." (in en). https://www.intel.com/content/www/us/en/develop/topics/software-security-guidance/processors-affected-consolidated-product-cpu-model.html. 
  14. "AMD Product Security | AMD". 2019-08-10. https://www.amd.com/en/corporate/product-security. 
  15. Cutress, Dr Ian. "The Ice Lake Benchmark Preview: Inside Intel's 10nm". https://www.anandtech.com/show/14664/testing-intel-ice-lake-10nm/3. 
  16. online, heise. "Intel Core i9-9900K mit 8 Kernen und 5 GHz für Gamer" (in de-DE). https://www.heise.de/newsticker/meldung/Intel-Core-i9-9900K-mit-8-Kernen-und-5-GHz-fuer-Gamer-4183783.html. 
  17. Cutress, Ian. "AMD Zen 2 Microarchitecture Analysis: Ryzen 3000 and EPYC Rome". https://www.anandtech.com/show/14525/amd-zen-2-microarchitecture-analysis-ryzen-3000-and-epyc-rome. 
  18. https://developer.amd.com/wp-content/resources/90343-B_SoftwareTechniquesforManagingSpeculation_WP_7-18Update_FNL.pdf
  19. "Spectre Returns! Speculation Attacks using the Return Stack Buffer". https://www.usenix.org/system/files/conference/woot18/woot18-paper-koruyeh.pdf. 
  20. Maisuradze, Giorgi; Rossow, Christian (2018). "ret2spec: Speculative Execution Using Return Stack Buffers". Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. pp. 2109–2122. doi:10.1145/3243734.3243761. ISBN 9781450356930. Bibcode: 2018arXiv180710364M.  https://dx.doi.org/10.1145%2F3243734.3243761
  21. https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fdf82a7856b32d905c39afc85e34364491e46346
  22. "Engineering New Protections Into Hardware" (in en). https://www.intel.com/content/www/us/en/architecture-and-technology/engineering-new-protections-into-hardware.html. 
  23. "INTEL-SA-00145". https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00145.html. 
  24. "Bounds Check Bypass Store (BCBS) Vulnerability (INTEL-OSS-10002)". https://www.intel.com/content/www/us/en/support/articles/000029382/processors.html. 
  25. "Intel Deep Dive CPUID Enumeration and Architectural MSRs". https://software.intel.com/security-software-guidance/insights/deep-dive-cpuid-enumeration-and-architectural-msrs. 
  26. "INTEL-SA-00233" (in en). https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00233.html. 
  27. danielmgmi (2020-07-15), danielmgmi/icebreak, https://github.com/danielmgmi/icebreak, retrieved 2020-07-15 
  28. "Bitdefender SWAPGS Attack Mitigation Solutions". https://www.bitdefender.com/business/swapgs-attack.html. 
  29. "Documentation/admin-guide/hw-vuln/spectre.rst - chromiumos/third_party/kernel - Git at Google". https://chromium.googlesource.com/chromiumos/third_party/kernel/+/refs/tags/v4.19.65/Documentation/admin-guide/hw-vuln/spectre.rst. 
  30. Winder, Davey (6 August 2019). "Microsoft Confirms New Windows CPU Attack Vulnerability, Advises All Users To Update Now". Forbes. https://www.forbes.com/sites/daveywinder/2019/08/06/microsoft-confirms-new-windows-cpu-attack-vulnerability--advises-all-users-to-update-now/. Retrieved 7 August 2019. 
  31. "Cyberus Technology: TSX Asynchronous Abort" (in en). https://www.cyberus-technology.de/. 
  32. at 18:02, Shaun Nichols in San Francisco 12 Nov 2019. "True to its name, Intel CPU flaw ZombieLoad comes shuffling back with new variant" (in en). https://www.theregister.co.uk/2019/11/12/zombieload_cpu_attack/. 
  33. Cimpanu, Catalin. "Intel's Cascade Lake CPUs impacted by new Zombieload v2 attack" (in en). https://www.zdnet.com/article/intels-cascade-lake-cpus-impacted-by-new-zombieload-v2-attack/. 
  34. "Intel Deep Dive TSX Asynchronous Abort" (in en). https://software.intel.com/security-software-guidance/insights/deep-dive-intel-transactional-synchronization-extensions-intel-tsx-asynchronous-abort. 
  35. "MDS Attacks: Microarchitectural Data Sampling". https://mdsattacks.com/#ridl-nng. 
  36. "IPAS: INTEL-SA-00329" (in en-US). 2020-01-27. https://blogs.intel.com/technology/2020/01/ipas-intel-sa-00329/. 
  37. "CacheOut". https://cacheoutattack.com/. 
  38. at 17:00, Thomas Claburn in San Francisco 10 Mar 2020. "You only LVI twice: Meltdown The Sequel strikes Intel chips – and full mitigation against data-meddling flaw will cost you 50%+ of performance" (in en). https://www.theregister.co.uk/2020/03/10/lvi_reverse_meltdown_intel_attack/. 
  39. "LVI: Hijacking Transient Execution with Load Value Injection". https://lviattack.eu/. 
  40. "INTEL-SA-00334" (in en). https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00334.html. 
  41. "Deep Dive: Load Value Injection". https://software.intel.com/security-software-guidance/insights/deep-dive-load-value-injection. 
  42. "Take A Way: Exploring the Security Implications of AMD'sCache Way Predictors". https://mlq.me/download/takeaway.pdf. 
  43. March 2020, Paul Alcorn 07. "New AMD Side Channel Attacks Discovered, Impacts Zen Architecture" (in en). https://www.tomshardware.com/news/new-amd-side-channel-attacks-discovered-impacts-zen-architecture. 
  44. Alcorn, Paul (March 9, 2020). "New AMD Side Channel Attacks Discovered, Impacts Zen Architecture (AMD Responds)". https://www.tomshardware.com/uk/news/new-amd-side-channel-attacks-discovered-impacts-zen-architecture. 
  45. Cimpanu, Catalin. "AMD processors from 2011 to 2019 vulnerable to two new attacks" (in en). https://www.zdnet.com/article/amd-processors-from-2011-to-2019-vulnerable-to-two-new-attacks/. 
  46. "CROSSTalk" (in en-US). https://www.vusec.net/projects/crosstalk/. 
  47. "Deep Dive: Special Register Buffer Data Sampling". https://software.intel.com/security-software-guidance/insights/deep-dive-special-register-buffer-data-sampling. 
  48. "INTEL-SA-00320" (in en). https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00320.html. 
  49. "BlindSide" (in en-US). https://www.vusec.net/projects/blindside/. 
  50. Francisco, Thomas Claburn in San. "Don't be BlindSided: Watch speculative memory probing bypass kernel defenses, give malware root control" (in en). https://www.theregister.com/2020/09/10/dont_be_blindsided_speculative_memory/. 
  51. "INTEL-SA-00088" (in en). https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00088.html. 
  52. "INTEL-SA-00115" (in en). https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00115.html. 
  53. "Meltdown and Spectre Status Page". https://wiki.netbsd.org/security/meltdown_spectre/. 
  54. Ltd, Arm. "Speculative Processor Vulnerability | Cache Speculation Issues Update" (in en). https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability/latest-updates/cache-speculation-issues-update. 
  55. "About speculative execution vulnerabilities in ARM-based and Intel CPUs" (in en). https://support.apple.com/en-us/HT208394. 
  56. "Potential Impact on Processors in the POWER Family" (in en-US). 2019-05-14. https://www.ibm.com/blogs/psirt/potential-impact-processors-power-family/. 
More
Upload a video for this entry
Information
Subjects: Others
Contributor MDPI registered users' name will be linked to their SciProfiles pages. To register with us, please refer to https://encyclopedia.pub/register :
View Times: 2.9K
Entry Collection: HandWiki
Revision: 1 time (View History)
Update Date: 14 Nov 2022
Notice
You are not a member of the advisory board for this topic. If you want to update advisory board member profile, please contact office@encyclopedia.pub.
OK
Confirm
Only members of the Encyclopedia advisory board for this topic are allowed to note entries. Would you like to become an advisory board member of the Encyclopedia?
Yes
No
${ textCharacter }/${ maxCharacter }
Submit
Cancel
There is no comment~
${ textCharacter }/${ maxCharacter }
Submit
Cancel
${ selectedItem.replyTextCharacter }/${ selectedItem.replyMaxCharacter }
Submit
Cancel
Confirm
Are you sure to Delete?
Yes No
Academic Video Service