Skip to main content

Digital Trends may earn a commission when you buy through links on our site. Why trust us?

The Spectre flaw is back — and Intel Alder Lake isn’t safe

Intel CPUs have been subjected to several significant security vulnerabilities in recent years, namely Meltdown and Spectre. Now, the latter has made an appearance once again.

As reported by Tom’s Hardware and Phoronix, security research group VUSec and Intel confirmed the existence of a new speculative execution vulnerability labeled branch history injection (BHI).

An Intel Alder Lake pin layout.
Image used with permission by copyright holder

Classified as a by-product of Spectre V2, BHI is a proof-of-concept exploit capable of leaking arbitrary kernel memory on Intel CPUs. As a result, sensitive data such as passwords can be extracted. Intel processors released in the past few years, which includes its latest 12th-generation Alder Lake processors, are said to be affected.

Recommended Videos

Certain ARM silicon have also been found to be vulnerable to the exploit. As for AMD CPUs, security researchers initially found that they remain immune to potential BHI attacks. However, there have been some developments in this area that appear to suggest otherwise.

Please enable Javascript to view this content

“The LFENCE-based mitigation is deemed no longer sufficient for mitigating Spectre V2 attacks. Now the Linux kernel will use return trampolines “retpolines” by default on all AMD processors,” Phoronix explained. “Various AMD CPUs have already defaulted to using Retpolines for Spectre V2 mitigations, while now it will be the default across the board for AMD processors.”

Vusec provided further insight into how the exploit can find its way through mitigations that are already in place. While hardware mitigations prevent an attacker from injecting predictor entries for the kernel, they can still make use of a global history in order to select target entries to speculatively execute. “And the attacker can poison this history from Userland to force the kernel to mispredict to more “interesting” kernel targets (i.e., gadgets) that leak data,” the report added.

Intel has published a list of CPUs affected by the exploit, confirming that several generations of chips ranging back to 2013 (Haswell) can be infiltrated, including Coffee Lake, Tiger Lake, Ice Lake, and Alder Lake. Ice Lake servers were also mentioned on the list.

Chips from ARM, including Neoverse N2, N1, V1, Cortex A15, A57, and A72, have all been found to be impacted as well. Depending on the system on a chip, the chip designer is issuing five different mitigations.

Intel is expected to release a software patch to address the new Spectre-based BHI exploit. In the interim, the chipmaker provided Phoronix with a statement on BHI in regard to its impact on Linux systems:

“The attack, as demonstrated by researchers, was previously mitigated by default in most Linux distributions. The Linux community has implemented Intel’s recommendations starting in Linux kernel version 5.16 and is in the process of backporting the mitigation to earlier versions of the Linux kernel.”

When Spectre and Meltdown were originally discovered as a CPU vulnerability in 2018, lawsuits began to be filed against Intel, alleging the company knew about the flaws but kept silent about them while still selling the silicon in question. As pointed out by Tom’s Hardware, by mid-February 2018, a total of 32 lawsuits were filed against Team Blue.

Intel recently introduced an expansion of its existing Bug Bounty program with Project Circuit Breaker, an initiative directed toward recruiting “elite hackers.” Discovering bugs in firmware, hypervisors, GPUs, chipsets, and other areas could result in a financial windfall for participants, with payouts potentially reaching the six-figure range.

Zak Islam
Former Digital Trends Contributor
Zak Islam was a freelance writer at Digital Trends covering the latest news in the technology world, particularly the…
I’m worried Intel is making a mistake with Arrow Lake
Someone holding the Core i9-12900KS processor.

For the last several years, every new generation from Intel has felt like a make-or-break moment. Now, with Arrow Lake CPUs, the stakes are even higher. Intel is facing unprecedented financial troubles, and although it still makes some of the best processors, the silicon giant that used to loom over the PC industry isn’t as strong as it once was.

Arrow Lake is yet another major shift. The CPUs kill Intel’s long-standing Hyper-Threading feature. They introduce two new core architectures. And they debut the Core Ultra branding on desktop, along with the new LGA 1851 socket. I’m worried that Intel’s strategy won’t work with Arrow Lake, though.

Read more
Sorry, gamers — Intel’s new CPUs won’t deliver any gains
A render for an Intel Arrow Lake CPU.

Intel is setting expectations for its upcoming Arrow Lake-S desktop CPUs. Although the company is holding strong that the new generation will be competitive with the best processors when they release on October 24, the new range of CPUs won't deliver much, if any, performance gains for gamers -- and that's coming from Intel itself.

To kick off the Arrow Lake generation, now called Intel Core Ultra 200S, Intel is releasing five processors. You can see the standard Core Ultra 9, 7, and 5 models in the table below, along with Core Ultra 7 and 5 models that cut the integrated graphics for a slightly lower price. All five of the processors are unlocked for overclocking with the new LGA 1851 socket. Unlike AMD's new Zen 5 CPUs, Core Ultra 200S chips require a new motherboard as Intel retires its LGA 1700 socket.

Read more
Intel did the unthinkable with its new Arrow Lake CPUs
A render of an Intel Core Ultra 200-S chip.

It finally happened. Intel killed Hyper-Threading on its desktop CPUs. The new Arrow Lake range, called Core Ultra 200S, ditches the simultaneous multi-threading (SMT) feature that Intel has held onto for more than a decade. And according to Intel, it doesn't need the extra threads to still deliver a generational performance improvement, even up against the best processors.

Intel says the new range, which we break down in detail in our post focused its gaming potential, can deliver an 8% performance improvement in single-threaded workloads over the previous generation, and a 4% uplift compared to the Ryzen 9 9950X. Those are pretty small margins, but the real impressive stuff comes in multi-threaded performance.

Read more