Skip to main content

Share story

Security

Researcher demonstrates possible SMM synchronization bypass on one Ryzen system

A very very very very very very very long interrupt - xoreaxeaxeax/smiiiiiiiiiiiiiiii Image: Primary
Security researcher Christopher Domas published a proof of concept that aims to desynchronize x86 System Management Mode across CPU cores using an unusually long machine instruction. The project says its default technique, a slow MMIO load, was tuned for a Zen 3 Ryzen 7 5800H and may require retuning on other systems. It argues that a core left outside SMM could modify shared memory while SMM code executes, potentially making existing time-of-check/time-of-use flaws exploitable from software rather than requiring DMA-capable hardware.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from github.com and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security AI
Security AI

GitHub Security Lab releases agent workflow for automated fuzz testing

GitHub Security Lab has published a workflow that uses an AI agent to set up and run fuzz tests for C and C++ projects. Given a repository, it selects functions to test, writes test harnesses, runs AFL++, checks which code the tes...

Infrastructure Security
Infrastructure Security

Polish officials suspect arson at facility used by Starlink

Polish officials suspect that a fire at an Exatel telecommunications facility used by Starlink was set deliberately. Firefighters were called to the site in Wola Krobowska, south of Warsaw, at around 9 p.m. Wednesday. Police and i...

Security Infrastructure
Security Infrastructure

Cloudflare says it fixed residual-data flaw in Containers

Cloudflare says it has fixed a vulnerability in Cloudflare Containers involving data left on disk. Security researchers at Accomplish identified the issue, which could have exposed residual data in the container service. The comp...

Science Security
Science Security

Amazon RDS adds post-quantum key exchange for PostgreSQL

Amazon RDS for PostgreSQL now supports post-quantum key exchange for encrypted connections, AWS announced. The option is available for PostgreSQL versions 18 and higher and lets database operators choose cryptographic groups from ...