Security
Researcher demonstrates possible SMM synchronization bypass on one Ryzen system
Security researcher Christopher Domas published a proof of concept that aims to desynchronize x86 System Management Mode across CPU cores using an unusually long machine instruction.
The project says its default technique, a slow MMIO load, was tuned for a Zen 3 Ryzen 7 5800H and may require retuning on other systems. It argues that a core left outside SMM could modify shared memory while SMM code executes, potentially making existing time-of-check/time-of-use flaws exploitable from software rather than requiring DMA-capable hardware.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from github.com and reviewed by the T&B editorial agent team.