Urgent.News

What's breaking now, across thousands of outlets.

Culture

Hardware backdoors in some x86 CPUs

Article URL: https://github.com/xoreaxeaxeax/rosenbridge Comments URL: https://news.ycombinator.com/item?id=49219508 Points: 208 # Comments: 60

Project Rosenbridge has uncovered a hardware backdoor in certain desktop, laptop, and embedded x86 processors. This backdoor enables user-level code to read and write kernel data, bypassing processor protections. Typically disabled, it is enabled by default on some systems. The backdoor is a small, non-x86 core embedded within the main x86 core in the CPU, controlled by a model-specific-register and toggled with a launch-instruction.

Commands are sent to this hidden core, which executes them, bypassing all memory protections and privilege checks. It appears that only VIA C3 CPUs are affected. The vulnerability is present in certain generations of processors, but not in newer ones. While the backdoor should require kernel-level access to activate, it has been observed to be enabled by default, allowing unprivileged code to modify the kernel.

The research project provides tools to check if a processor is affected, close the backdoor, and analyze the backdoor. The tools were developed to identify and fix the perceived security vulnerability.

Written by urgent.news from Hacker News Best's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at github.com →

More in Culture

More from Saturday 8 August →