Downfall is the latest Intel CPU vulnerability that'll ruin the weeks of server admins

There's a fresh Intel CPU vulnerability - Downfall - a variation of the Meltdown and Fallout vulnerabilities from the last few years. Downfall (aka CVE-2022-40982) "is a transient execution side-channel issue and impacts all processors based on Intel microarchitectures Skylake through Ice Lake" and allows an attacker to "extract sensitive information that is protected by Software Guard eXtensions (SGX)" like "passwords, encryption keys, and private data such as banking details, personal emails, and messages". This is a big deal for cloud computing setups where multiple people have access to other people's stuff floating around on the same CPU. Intel's got a microcode update to patch against it and according to Red Hat, software that "realistic applications" using AVX2/AVX512 (not benchmarks) "only low single-digit percentage slowdowns".


If you liked this tiny snippet of content from The Sizzle - Australia's favourite daily email containing the latest tech news & bargains - then sign up for a 30-day free trial below. No credit card required! Learn more about The Sizzle at https://thesizzle.com.au