Apr 6, 2018 11:50 am EDT
Categorized: High Severity
Share this post:
Three security vulnerabilities that allow unauthorized users to bypass the hardware barrier between applications and kernel memory have been made public. These vulnerabilities all make use of speculative execution to perform side-channel information disclosure attacks. The first two vulnerabilities, CVE-2017-5753 and CVE-2017- 5715, are collectively known as Spectre, and allow user-level code to infer data from unauthorized memory; the third vulnerability, CVE-2017-5754, is known as Meltdown, and allows user-level code to infer the contents of kernel memory. The vulnerabilities are all variants of the same class of attacks and differ in the way that speculative execution is exploited.
Product Impact
To exploit these vulnerabilities, an attacker must be able to run malicious code on an affected system. IBM hardware security modules (HSMs), specifically the IBM 4768 (Crypto Express6S or CEX6S), the IBM 4767 (Crypto Express5S or CEX5S) and the IBM 4765 (Crypto Express 4S or CEX4S), are not exposed to these vulnerabilities because they are closed systems and are designed to prevent unauthorized users from loading and executing code other than code provided by or authorized by IBM. In the case of IBM HSM Toolkit customers, execution of non-IBM code is supported, but proper security credentials are required to install said code on the HSMs – that is, the code must be signed with a key registered with IBM by the customer.
For all IBM HSM products, we recommend implementing any firmware and OS updates in accordance with your normal procedures.
from IBM Product Security Incident Response Team https://ift.tt/2EpQD52
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.