Spectre NG – New security holes in Intel CPUs

Since the beginning of 2018 the security holes Spectre and Meltdown, that were found in Intel CPUs are on everyone’s lips. Just now that there are some helpful updates, researchers found new – even more – security holes in these processors.

Spectre Next Generation

According to current information researcher groups have found eight new security holes in Intel CPUs. Each of them are essentially caused by the same design problem and that’s why they are called “Spectre Next Generation”. At the moment the flaws are being kept secret but c’t has some exclusive information.

High risk for clouds

Four of the eight vulnerabilities are classified as “high risk” by Intel itself – the remaining are rated as “medium”. According to c’t one of the Spectre Next Generation flaws simplifies attacks across system boundaries to such an extent that they estimate the threat potential to be significantly higher than with Spectre. Especially for cloud hoster this is a high risk regarding the security because passwords and keys for data transfer are at risk. In addition to this Intel’s Software Guard Extension that protects sensitive data is not protected against Spectre.

CPU patches in progress

c’t has exclusive information from Intel and their plans for the patches. Each of the eight Next Generation flaws needs its own patches on which Intel is already working – on some together with operating system manufacturers. Intel plans two patch surges: One of them in May and the second one in August. It is highly recommended to make these updates asap.

Intel’s statement

"Protecting our customers’ data and ensuring the security of our products are critical priorities for us. We routinely work closely with customers, partners, other chipmakers and researchers to understand and mitigate any issues that are identified, and part of this process involves reserving blocks of CVE numbers. We believe strongly in the value of coordinated disclosure and will share additional details on any potential issues as we finalize mitigations. As a best practice, we continue to encourage everyone to keep their systems up-to-date."

[UPDATE]: First patches delayed by Intel

As we mentioned already in the text above, the first patches for the Spectre Next Generation flaws were planned to be released this May – more precisely on 7 May. This day is over and there are still no patches because Intel asked for more time.
It’s obvious that Intel has problems with providing the updates in time and now they moved the release date to the 21 May. By then there are supposed to be microcode updates and they even want to publish some information about two of the Spectre NG flaws. According to heise – who have exclusive information – this date is far away from being a fixed appointment: Intel allegedly applied for another extension of time until the 10 July. [UPDATE/]

Source: heise ; c’t

##Read our last blog post about Intel’s Spectre and Meltdown

More on this topic

7 Feb 2018 know-how

Spectre and Meltdown – News about the recent CPU problems

As we mentioned in our last ‘What’s New’ article the security breaches Spectre and Meltdown are often discussed in recent days and weeks. What happened, what it’s all about and how the spo-comm Mini-PCs are affected you can find here.
29 Mar 2018 know-how

Update to Intel’s Spectre and Meltdown

After the occurrence of Spectre and Meltdown at the beginning of this year it got fairly quiet about these processor security holes. Intel’s CEO, Brian Krzanich published a post regarding the security problems Spectre and Meltdown and explains that Intel is going to continue mitigating their effects and what was already done against those exploits.
27 Apr 2018 know-how

Update to Intel’s Spectre and Meltdown – Part 2

Owners of older PCs with Windows 10 are waiting desperately for BIOS updates. The affected CPUs need these updates to protect Windows 10 against Spectre (variant 2) – but Microsoft doesn’t provide them. As an alternative there is now an optional Windows update.