Intel Spectre Vulnerabilities Now Have a Release Schedule

Published by

HardOCP published Intel Spectre Vulnerabilities Now Have a Release Schedule A quote from the article:
Intel has adopted a release schedule for new Spectre vulnerability disclosures. According to The Register, starting today new patches will be released quarterly to patch the latest exploits. This is akin to the Windows Patch Tuesday. I never thought that hardware would have a patch release schedule, but on the bright side, organizations can now plan in advance. I would manually set a restore point after reading this.....

The new Spectre-class side-channel vulnerability to be disclosed today in Intel's processors can be exploited through bounds-check bypass store attacks. This means malicious code already running on an Intel-powered computer can leverage speculative execution to potentially alter function pointers and return addresses in other threads to hijack applications. At that point, the malware can extract secrets from the system, and cause other merry mischief. The good news is that software mitigations available today for Spectre variant 1 will thwart bounds-check bypass store attacks. Thus, web browsers and other applications employing anti-Spectre mechanisms should be safe.
 Intel Spectre Vulnerabilities Now Have a Release Schedule