New CPU Bug Found

53 views
Skip to first unread message

jonbrown...@gmail.com

unread,
Aug 13, 2018, 7:44:18 PM8/13/18
to qubes-users
New CPU backdoor has been found with code available here: https://github.com/xoreaxeaxeax/rosenbridge

Anyone mind checking if Thinkpad 230 is affected?

Sphere

unread,
Aug 13, 2018, 10:02:47 PM8/13/18
to qubes-users
On Tuesday, August 14, 2018 at 7:44:18 AM UTC+8, jonbrown...@gmail.com wrote:
> New CPU backdoor has been found with code available here: https://github.com/xoreaxeaxeax/rosenbridge
>
> Anyone mind checking if Thinkpad 230 is affected?

Wow... things sure are going rough in the firmware/hardware/low-level instruction side of things

tier...@gmail.com

unread,
Aug 14, 2018, 3:21:04 AM8/14/18
to qubes-users
On Tuesday, August 14, 2018 at 12:44:18 AM UTC+1, jonbrown...@gmail.com wrote:
> New CPU backdoor has been found with code available here: https://github.com/xoreaxeaxeax/rosenbridge
>
> Anyone mind checking if Thinkpad 230 is affected?

It is thought that only VIA C3 CPUs are affected by this issue. The C-series processors are marketed towards industrial automation, point-of-sale, ATM, and healthcare hardware, as well as a variety of consumer desktop and laptop computers.

Thinkpads are Intel. But don't think for a second a 0-day for Intel/AMD doesn't exist, and isn't actively being exploited. Security is broken.

brenda...@gmail.com

unread,
Aug 14, 2018, 6:39:42 AM8/14/18
to qubes-users
On Monday, August 13, 2018 at 7:44:18 PM UTC-4, jonbrown...@gmail.com wrote:
> New CPU backdoor has been found with code available here: https://github.com/xoreaxeaxeax/rosenbridge
>
> Anyone mind checking if Thinkpad 230 is affected?

As per earlier in the thread, this only applies to some older VIA C3 CPUs. Also: the "bug" is a documented feature of those CPUs and can only be initially enabled via a privileged instruction...so...

Reply all
Reply to author
Forward
0 new messages