Kernel Memory Leak Affects Intel CPUs on Linux, MacOS, Windows
An attack to abuse Address Space Layout Randomisation has been detailed and a defence against it been suggested by a group of boffins at Graz University, Austria.
The theory was named KAISER (Kernel Address Isolation to have Side Channels Effectively Removed).
Protection has now been written for Linux Kernel, named KPTI (Kernel Page Table Isolation), which will appear in Kernel 4.14.11 and 4.15.
Patches have been written for Windows 10, and due to be released Jan 2018 patch Tuesday, and MacOS 10.13.2.
Sources used:
https://en.wikipedia.org/wiki/Kernel_page-table_isolation
https://gruss.cc/files/kaiser.pdf
http://pythonsweetness.tumblr.com/post/169166980422/the-mysterious-case-of-the-linux-page-table
https://lkml.org/lkml/2017/12/27/2
https://lkml.org/lkml/2017/12/4/709
https://www.postgresql.org/message-id/20180102222354.qikjmf7dvnjgbkxe@alap3.anarazel.de
https://arstechnica.com/gadgets/2018/01/whats-behind-the-intel-design-flaw-forcing-numerous-patches/
https://cyber.wtf/2017/07/28/negative-result-reading-kernel-memory-from-user-mode/
https://twitter.com/brainsmoke/status/948561799875502080/photo/1
https://www.theregister.co.uk/2018/01/02/intel_cpu_design_flaw/
Like my channel? Please help support it:
Patreon: https://www.patreon.com/quidsup
Paypal: https://www.paypal.me/quidsup
Follow me on Social Media
Google+ https://google.com/+quidsup
Twitter: https://twitter.com/quidsup
Minds: https://minds.com/quidsup