Meltdown and Spectre vulnerabilities Intel (and AMD) Chip Bug

Anonymous
2018-01-04T01:54:57+00:00

A lot of noise on the internet, after Intel confirm that chips have a bug:

https://newsroom.intel.com/news/intel-responds-to-security-research-findings/ 

This post is to bring some light on this.

1- Intel says is not only their chips affected

2- PCID (Process-Context Identifiers), a chip feature,  has a bug that allow apps (malware) to read data

3- Process-context identifiers (PCIDs) are a facility by which a logical processor may cache information for multiple linear-address spaces. The processor may retain cached information when software switches to a different linear address space with a different PCID.

4- Macintosh and Linux OS are also affected.

Rumors:

1- If you have Haswell (4th-gen) or newer, PCID (Process-Context Identifiers) is enabled. 

2- After apply the patch, performance is going to be slower on newer CPU. Around 5 to 10%.

2- Still if you have older CPU, performance will be affected worse than newer CPUs.

3- To be affected you must have a OS 64 bits. {Correction: 32bits has vulnerability, MS still working on this)

Just as I'm writing this, Linus Torvalds and his team are working on this too:

https://lkml.org/lkml/2018/1/2/703

https://www.postgresql.org/message-id/20180102222354.qikjmf7dvnjgbkxe%40alap3.anarazel.de

Can we get a word from Microsoft?

For windows, What patch is going to address this? (Update: Patch links and KB are listed on postings)

Is that is going to be on the Montly Rollup and/or Security only patches? (Update: See the links posted)

If performance is going to suffer, can we be able to uninstall such patch? (Update: Microsoft published a document about it, See the links posted)

Please, any info will be appreciated.

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

77 answers

Sort by: Most helpful
  1. Anonymous
    2018-01-06T18:05:54+00:00

    I'm also getting some random BSODs after the patch, even though I've updated the AV clients.  Here is an analysis of the dump file, indicating it's related to the CPU Cache.

    icrosoft (R) Windows Debugger Version 10.0.17061.1000 AMD64
    Copyright (c) Microsoft Corporation. All rights reserved.
    
    Loading Dump File [C:\tools\dumps\MEMORY.DMP]
    Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.
    
    Symbol search path is: srv*
    Executable search path is: 
    Windows 10 Kernel Version 15063 MP (8 procs) Free x64
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 15063.0.amd64fre.rs2_release.170317-1834
    Machine Name:
    Kernel base = 0xfffff802`0d882000 PsLoadedModuleList = 0xfffff802`0dbce660
    Debug session time: Sat Jan  6 11:51:42.373 2018 (UTC - 6:00)
    System Uptime: 1 days 3:23:46.777
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ................................................................
    ..............................
    Loading User Symbols
    
    Loading unloaded module list
    .......................................
    ERROR: FindPlugIns 80070035
    ERROR: Some plugins may not be available [80070035]
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    Use !analyze -v to get detailed debugging information.
    
    BugCheck 124, {0, ffffcd8b7e6dc028, fe000000, 801136}
    
    Probably caused by : GenuineIntel
    
    Followup:     MachineOwner
    ---------
    
    nt!KeBugCheckEx:
    fffff802`0d9ee580 48894c2408      mov     qword ptr [rsp+8],rcx ss:0018:ffffa481`fe5d57c0=0000000000000124
    3: kd> !analyze -v
    ERROR: FindPlugIns 80070035
    ERROR: Some plugins may not be available [80070035]
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    
    WHEA_UNCORRECTABLE_ERROR (124)
    A fatal hardware error has occurred. Parameter 1 identifies the type of error
    source that reported the error. Parameter 2 holds the address of the
    WHEA_ERROR_RECORD structure that describes the error conditon.
    Arguments:
    Arg1: 0000000000000000, Machine Check Exception
    Arg2: ffffcd8b7e6dc028, Address of the WHEA_ERROR_RECORD structure.
    Arg3: 00000000fe000000, High order 32-bits of the MCi_STATUS value.
    Arg4: 0000000000801136, Low order 32-bits of the MCi_STATUS value.
    
    Debugging Details:
    ------------------
    
    KEY_VALUES_STRING: 1
    
    TIMELINE_ANALYSIS: 1
    
    DUMP_CLASS: 1
    
    DUMP_QUALIFIER: 401
    
    BUILD_VERSION_STRING:  15063.0.amd64fre.rs2_release.170317-1834
    
    SYSTEM_MANUFACTURER:  Dell Inc.
    
    SYSTEM_PRODUCT_NAME:  Precision 5520
    
    SYSTEM_SKU:  07BF
    
    BIOS_VENDOR:  Dell Inc.
    
    BIOS_VERSION:  1.3.3
    
    BIOS_DATE:  05/08/2017
    
    BASEBOARD_MANUFACTURER:  Dell Inc.
    
    BASEBOARD_PRODUCT:  0R6JFH
    
    BASEBOARD_VERSION:  A00
    
    DUMP_TYPE:  1
    
    BUGCHECK_P1: 0
    
    BUGCHECK_P2: ffffcd8b7e6dc028
    
    BUGCHECK_P3: fe000000
    
    BUGCHECK_P4: 801136
    
    BUGCHECK_STR:  0x124_GenuineIntel
    
    CPU_COUNT: 8
    
    CPU_MHZ: b58
    
    CPU_VENDOR:  GenuineIntel
    
    CPU_FAMILY: 6
    
    CPU_MODEL: 9e
    
    CPU_STEPPING: 9
    
    CPU_MICROCODE: 6,9e,9,0 (F,M,S,R)  SIG: 48'00000000 (cache) 48'00000000 (init)
    
    BLACKBOXBSD: 1 (!blackboxbsd)
    
    DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT
    
    PROCESS_NAME:  System
    
    CURRENT_IRQL:  f
    
    ANALYSIS_SESSION_HOST:  NONEYA
    
    ANALYSIS_SESSION_TIME:  01-06-2018 11:58:53.0326
    
    ANALYSIS_VERSION: 10.0.17061.1000 amd64fre
    
    STACK_TEXT:  
    ffffa481`fe5d57b8 fffff802`0d83f5cf : 00000000`00000124 00000000`00000000 ffffcd8b`7e6dc028 00000000`fe000000 : nt!KeBugCheckEx
    ffffa481`fe5d57c0 fffff802`0dade32d : ffffcd8b`7e6dc028 ffffcd8b`7dce70d0 ffffcd8b`7dce70d0 ffffcd8b`7dce70d0 : hal!HalBugCheckSystem+0xcf
    ffffa481`fe5d5800 fffff802`0d83faf8 : 00000000`00000728 00000000`00000003 00000000`00000000 00000000`00000000 : nt!WheaReportHwError+0x25d
    ffffa481`fe5d5860 fffff802`0d83fe58 : 00000000`00000010 00000000`00000003 ffffa481`fe5d5a08 00000000`00000003 : hal!HalpMcaReportError+0x50
    ffffa481`fe5d59b0 fffff802`0d83fd46 : ffffcd8b`7dce6d00 00000000`00000001 00000000`00000000 00000000`00000000 : hal!HalpMceHandlerCore+0xe0
    ffffa481`fe5d5a00 fffff802`0d83ff8a : 00000000`00000008 00000000`00000001 00000000`00000000 00000000`00000000 : hal!HalpMceHandler+0xda
    ffffa481`fe5d5a40 fffff802`0d840120 : ffffcd8b`7dce6d00 ffffa481`fe5d5c70 00000000`00000000 00000000`00000000 : hal!HalpMceHandlerWithRendezvous+0xce
    ffffa481`fe5d5a70 fffff802`0d9f86bb : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : hal!HalHandleMcheck+0x40
    ffffa481`fe5d5aa0 fffff802`0d9f842c : 00000000`00000000 fffff802`0d9f83ab 00000000`00000000 00000000`00000000 : nt!KxMcheckAbort+0x7b
    ffffa481`fe5d5be0 fffff80d`ea901388 : fffff80d`ea901360 00000000`00000000 00000000`00000000 ffffcd8b`899da000 : nt!KiMcheckAbort+0x1ac
    ffffa481`fe5f97d8 fffff80d`ea901360 : 00000000`00000000 00000000`00000000 ffffcd8b`899da000 ffffa481`fe5cb180 : intelppm!MWaitIdle+0x18
    ffffa481`fe5f97e0 fffff802`0d8f8ac9 : 00000000`00000000 00000000`0000007b 00000000`00000000 00000000`00000052 : intelppm!AcpiCStateIdleExecute+0x20
    ffffa481`fe5f9810 fffff802`0d8f8323 : 00000000`00000003 00000000`00000002 ffffcd8b`899da0f0 00000000`00000000 : nt!PpmIdleExecuteTransition+0x619
    ffffa481`fe5f9a80 fffff802`0d9f15fc : ffffffff`00000000 ffffa481`fe5cb180 ffffa481`fe5d7d80 ffffcd8b`965e4080 : nt!PoIdle+0x343
    ffffa481`fe5f9be0 00000000`00000000 : ffffa481`fe5fa000 ffffa481`fe5f3000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x2c
    
    THREAD_SHA1_HASH_MOD_FUNC:  7cd3ee35f3ce339c67306f8de8bf43774bb073ed
    
    THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  156e2c098a41a59803870b90ea738ec33c1f740e
    
    THREAD_SHA1_HASH_MOD:  20fd580bf9b01c1a6ca450e04acef799c7715c5a
    
    FOLLOWUP_NAME:  MachineOwner
    
    MODULE_NAME: GenuineIntel
    
    IMAGE_NAME:  GenuineIntel
    
    DEBUG_FLR_IMAGE_TIMESTAMP:  0
    
    STACK_COMMAND:  .thread ; .cxr ; kb
    
    FAILURE_BUCKET_ID:  0x124_GenuineIntel_PROCESSOR_CACHE
    
    BUCKET_ID:  0x124_GenuineIntel_PROCESSOR_CACHE
    
    PRIMARY_PROBLEM_CLASS:  0x124_GenuineIntel_PROCESSOR_CACHE
    
    TARGET_TIME:  2018-01-06T17:51:42.000Z
    
    OSBUILD:  15063
    
    OSSERVICEPACK:  0
    
    SERVICEPACK_NUMBER: 0
    
    OS_REVISION: 0
    
    SUITE_MASK:  272
    
    PRODUCT_TYPE:  1
    
    OSPLATFORM_TYPE:  x64
    
    OSNAME:  Windows 10
    
    OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS
    
    OS_LOCALE:  
    
    USER_LCID:  0
    
    OSBUILD_TIMESTAMP:  2017-11-29 20:34:10
    
    BUILDDATESTAMP_STR:  170317-1834
    
    BUILDLAB_STR:  rs2_release
    
    BUILDOSVER_STR:  10.0.15063.0.amd64fre.rs2_release.170317-1834
    
    ANALYSIS_SESSION_ELAPSED_TIME:  42b
    
    ANALYSIS_SOURCE:  KM
    
    FAILURE_ID_HASH_STRING:  km:0x124_genuineintel_processor_cache
    
    FAILURE_ID_HASH:  {4c8f3f5e-1af5-ed8b-df14-d42663b1dfa7}
    
    Followup:     MachineOwner
    ---------
    

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-01-06T01:16:31+00:00

    Finally Dell put the new firmware updates.

    For Servers go here:

    http://www.dell.com/support/article/us/en/04/sln308588/microprocessor-side-channel-attacks--cve-2017-5715--cve-2017-5753--cve-2017-5754---impact-on-dell-emc-products--dell-enterprise-servers--storage-and-networking-?lang=en

    For Clients go here:

    http://www.dell.com/support/article/us/en/04/sln308587/microprocessor-side-channel-attacks--cve-2017-5715--cve-2017-5753--cve-2017-5754---impact-on-dell-products?lang=en

    But because Symantec still is working on this, we are officially on hold until further notice:

    "we are recommending that SEP 12.1/14.0 customers please hold off on applying the Windows Security Updates released on January 3rd, 2018 until our investigation has concluded. "

    https://www.symantec.com/connect/forums/latest-win10-update-corrupts-sep14#

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-01-05T22:32:05+00:00

    Here is the intel vulnerability tool to check your system. Then you need to check with your computer manufacturer to see if they have offered a patch yet.

    https://downloadcenter.intel.com/download/26755/INTEL-SA-00075-Detection-and-Mitigation-Tool

    That is for another privilege vulnerability:

    Intel® Active Management Technology (AMT) dated back on Date: 9/12/2017

    https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr

    Not related to this one:

    Speculative Execution and Indirect Branch Prediction Side Channel Analysis Method  01/3/2018 

    https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00088&languageid=en-fr

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-01-05T22:26:24+00:00

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-01-05T19:35:21+00:00

    Oh well... What to say...

    In my personal opinion it would be wise to wait and see what damage those MS patches make... There are quite a few reports of weird happenings out there...

    BUT: That is only my personal opinion.

    I'm just a normal user....

    Was this answer helpful?

    0 comments No comments