{"id":2606,"date":"2018-08-15T11:46:08","date_gmt":"2018-08-15T16:46:08","guid":{"rendered":"http:\/\/www.serverpronto.com\/spu\/?p=2606"},"modified":"2018-10-08T01:25:20","modified_gmt":"2018-10-08T06:25:20","slug":"red-hat-vulnerability-kernel-side-channel-attack-using-l1-terminal","status":"publish","type":"post","link":"https:\/\/www.serverpronto.com\/spu\/2018\/08\/red-hat-vulnerability-kernel-side-channel-attack-using-l1-terminal\/","title":{"rendered":"Red Hat Vulnerability Kernel Side-Channel Attack using L1 Terminal"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Red Hat has released a statement to acknowledge a vulnerability related to a Kernel Side-Channel attack using L1 Terminal. In this case, is a new computer microprocessor hardware implementation (microarchitecture) issue similar to Spectre and Meltdown which has been reported to affect x86 microprocessors manufactured by Intel. <\/span><\/p>\n<p><!--more--><\/p>\n<h1>Vulnerability Kernel Side-Channel Attack using L1 Terminal<\/h1>\n<p><span style=\"font-weight: 400;\">Hackers can break security by using this flaw. And also, this vulnerability is divided into a couple of ways.<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The first one affects only Intel \u00e2\u20ac\u0153SGX\u00e2\u20ac\u009d secure enclaves and mitigates through updates from the operating system. <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The rest two pieces require software-level mitigations performed by operating systems and hypervisors. <\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">The L1 Terminal Fault vulnerability enables a sidestep memory get to security controls ordinarily imposed and managed by the operating system or hypervisor. It is what a hacker can use to access all physical memory that is available on the <a href=\"https:\/\/lwn.net\/Articles\/252125\/\">L1 data cache<\/a> of the processor. This cache is the first level that contains data that is also on the external memory chips. Is easier to access data on this data cache terminal. Because of its proximity to the central processor, making this vulnerability worth taken advantage of. <\/span><\/p>\n<h2>How is it detected?<\/h2>\n<p><span style=\"font-weight: 400;\">The L1 Terminal fault is detected by the system after it gets through a hardware performance that at first supposed that all entries and permits are valid, before going through to a validity process. But at the end, it detects all terminal faults and throws them away. Still, the hacking attempt usually makes an impact on the cache. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Each access attempt it creates vulnerabilities by shortcutting the two normal stages of translation, which still manifest and read host hypervisor or physical memory. Users need to protect against it.<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Malicious users trying to read system data on a physical system.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Malicious guest trying to access others guests information.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">Everyone should take actions to correct any security measures, including applying updates.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For information related to this matter access: <\/span><a href=\"https:\/\/access.redhat.com\/security\/vulnerabilities\/L1TF?sc_cid=%09701f2000001OBKoAAO&amp;&amp;elqTrackId=0c5cb6cea1704b94ae3482a75b0556fc&amp;elq=2823dec36a6f44bd8119b8b12c647539&amp;elqaid=53086&amp;elqat=1&amp;elqCampaignId=169140\"><span style=\"font-weight: 400;\">L1TF &#8211; L1 Terminal Fault Attack &#8211; CVE-2018-3620 &amp; CVE-2018-3646<\/span><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>ServerPronto offers affordable and secure<a href=\"https:\/\/www.serverpronto.com\/dedicated\"> dedicated servers<\/a> and<a href=\"https:\/\/www.serverpronto.com\/cloud\"> cloud<\/a> hosting service&nbsp;<span style=\"font-size: 14px; letter-spacing: 0px;\">packages.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Red Hat has released a statement to acknowledge a vulnerability related to a Kernel Side-Channel attack using L1 Terminal. In this case, is a new computer microprocessor hardware implementation (microarchitecture) issue similar to Spectre and Meltdown which has been reported to affect x86 microprocessors manufactured by Intel.<\/p>\n","protected":false},"author":10,"featured_media":2884,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[123,85,17,112,13,22,18],"class_list":["post-2606","post","type-post","status-publish","format-standard","has-post-thumbnail","category-dedicated-server-best-practices","tag-cloud","tag-data-center","tag-dedicated-server","tag-hosting","tag-red-hat","tag-server","tag-web-hosting"],"_links":{"self":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/2606","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/comments?post=2606"}],"version-history":[{"count":5,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/2606\/revisions"}],"predecessor-version":[{"id":2883,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/2606\/revisions\/2883"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media\/2884"}],"wp:attachment":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media?parent=2606"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/categories?post=2606"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/tags?post=2606"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}