Multiple OS Vendors Release Security Patches After Misinterpreting Intel Docs (bleepingcomputer.com)
Almost all major OS vendors released security patches yesterday after a researcher discovered that some OS makers have misinterpreted an Intel CPU debug feature and left their systems open to attacks. From a report: The vulnerability is in how the OS vendors implemented a hardware debug mechanism for Intel x86-64 architectures -- and more specifically the MOV SS and POP SS instructions. "In certain circumstances after the use of certain Intel x86-64 architecture instructions, a debug exception pointing to data in a lower ring (for most operating systems, the kernel Ring 0 level) is made available to operating system components running in Ring 3," the CERT/CC team explained in an advisory published yesterday. Explained in layman's terms, "this may allow an attacker to utilize operating system APIs to gain access to sensitive memory information or control low-level operating system functions." Operating systems that mishandle this debug exception and had their systems open to attacks include Apple, Microsoft, FreeBSD, Red Hat, Ubuntu, SUSE Linux, and other Linux distros based on the Linux Kernel -- which is also affected.
yes there used to be one based on a BSD kernel, but now-a-days ???
That must have been some seriously badly written documentation if that many things made the same mistake.
That inspires confidence.
If several unrelated Companies made the exact same error it is more likely poorly written documentation.
AMD is affected too...
So, my question is:
Why a developer, developing for AMD-64 on top of AMD Hardware (think Athlon, Buldozer, Ryzen/Epyc et al) would be using an "INTEL's" Docs?
Shouldn't said developer be using AMD's documentation? If so, then, how said developer was also afected?
*** Suerte a todos y Feliz dia!
You keep using that instruction. I do not think it means what you think it means.
"Apple" and "Microsoft" are not Operating systems. But point still understood. In short, a very highly represented subset of all workstation users.
Intel probably just had the same guy that drafted the spectre/meltdown response press release write the document and he was kind of on a roll with the whole misdirection thing.
Operating systems that mishandle this debug exception and had their systems open to attacks include Apple, Microsoft, FreeBSD, Red Hat, Ubuntu, SUSE Linux, and other Linux distros based on the Linux Kernel -- which is also affected.
Apple, Microsoft, and Red Hat are not operation systems ;-)
Also, I think most Linux distros are based on the Linux Kernel.
Good work, BSD teams!
Any sufficiently unpopular but cohesive argument is indistinguishable from trolling.
It's good to see these NSA backdoors being closed, one by one.
If the custodians of every major OS misinterpreted the same document in the same way, shouldn't we consider that the document itself is suspect / at fault instead?
Given that Windows - by far and away the most-used operating system - isn't on the list, are we supposed to assume it's safe?
A confirmation either way would be nice, given the seriousness of the problem.
systemd is Roko's Basilisk.
I guess I am not affected since I am still on XP with no updates.
Face in palm.
See subject: I've started porting APK Hosts File Engine to Linux via FreePascal & Lazarus, so soon I'll be "honoring" requests put to me here on /. from "penguins" to do so!
* So far I like what I see in KUbuntu 18.04 & FreePascal & Lazarus IDE (just like Delphi 2.0 & enough to get this done) - so far, so good!
So I don't have the TIME to bother w/ your bs as unlike YOU? I am doing constructive things in my program (& domestically in 'spring cleaning' + yardwork)...
APK
P.S.=> ... Lastly - I've been "steering clear" of posting JUST to see if you'd keep up your bs (you have) & I've seen others knowing you're "fake apk" as they called you & them telling you to "F"-off as you "impersonate" me etc. - so your bs is backfiring on you... apk
That is why you always leave a note, with clear and concise documentation.
@msmash: I, for one, laud your biddable rectitude anent proffering pleonasm-eschewing elucidationary paraphrasing. Kudos!
See subject SOYBoy (rotflmao) in your UNIDENTIFIABLE anonymous "courageous" trolling you "not man" - LMAO!
(You know - I understand your SOYMilk & Bisphenol A "notman" SOYBoy formulas have addled your brains but that takes the cake for "illogic logic" from "your kind", lol!)
* The other poster's not I but they are making you get all "triggered" when you see your addled thinking fools nobody but your sick in the head chemically NEUTERED (lol) selves, lmao!
APK
P.S.=> Classic - one for my bookmarks... apk
add the tags "grammar" and "incoherent rambling". You can go back and reflect on these posts. Please use them to learn to speak like a human being.
I'm guessing APK is on something much stronger than soymilk to have "addled" his brain.