Technology

A latest security flaw, ‘Collide+Power’ might affect almost every CPU

A new security flaw named “Collide+Power” has been discovered by researchers from Graz University of Technology in Australia in collaboration with the Helmholtz Center. This latest flaw can affect all CPUs and threaten actors by allowing them to observe CPU power consumption, which will reveal sensitive information.

The vulnerability, CVE-2023-20583, involves analyzing power consumption trends while processing both known data from the attacker and unknown data from the victim. As a result, a threat actor can derive the contents of the victim’s CPU cache memory by evaluating the power utilization and disclosing encryption keys and short identifiers.

Furthermore, the ‘Collide+Power’ security issue is available in two flavors: MDS-Power and Meltdown-Power. MDS-Power, if hyperthreading is enabled, can steal data from another security domain co-located on a sibling hardware thread at a rate of 4.82 bits per hour. However, extracting a 4,096-bit RSA key from a cloud vendor would take a month at this rate.

Other than that, Meltdown is pretty harmless, as it leaks data at a rate of 0.136 bits per hour. And observing it on scales of real-world reality, the act becomes even more sluggish in terms of memory prefetching, as it requires a period of 2.86 to extract a single bit from the kernel if fully deployed.

“However, this low-security risk may change dramatically if new architectural or microarchitectural methods of prefetching victim data in co-location with attacker-controlled data are discovered,” the researchers wrote.

Resolving the vulnerability

Although the security flaw may not appear to be feasible for ordinary hackers, it has piqued the curiosity of firms such as AMD, which has previously confirmed that its EPYC server CPUs contain a performance determinism option that can limit the danger of data leakage. Similarly, Intel emphasized the efficacy of current features and guidelines for combating power side-channel attacks exhibited in response to past threats such as PLATYPUS and Hertzbleed.

Recent Posts

Microsoft finally wants to fix Xbox download problems

Fluctuating rates, overloaded servers and frozen updates often plague Xbox users. Microsoft is now intervening…

8 hours ago

ClickFix attack discovered: Hackers spread harmful help on Steam

An attack campaign is currently underway in the Steam discussion forums, in which criminals pose…

8 hours ago

Samsung Galaxy: New cell phone batteries with a step backwards in terms of longevity

Samsung is equipping its new folding smartphones with modern silicon-carbon batteries. This brings more capacity…

8 hours ago

Exchange Online: Stupid email glitch sends too much into quarantine

Many Exchange Online users are struggling with unexpected problems. A bug suddenly moves harmless emails…

8 hours ago

Microsoft solves Azure problem: Updates and Store are running again

After a widespread failure of the Azure infrastructure, central Windows services are working again. Users…

8 hours ago

Ryzen 7 9800HX3D: AMD is probably planning an affordable gaming laptop CPU

AMD is reportedly preparing a new X3D laptop processor for demanding gamers. The upcoming CPU…

8 hours ago