• Sources: primary, discussion
  • Summary: Christopher Domas published a proof of concept in which one long-running instruction keeps a core outside System Management Mode for about one second, breaking the rendezvous that SMM handlers rely on. The README states the demonstration is tuned for a Zen 3 Ryzen 7 5800H and uses a wide xmm load from MMIO at 0xfcc68860, and that on any other part one should expect no divergence until the long instruction is retuned. He states that SMM time-of-check-to-time-of-use bugs were written off as needing a DMA-capable peripheral and physical access, counts over 100 CVEs in that class, and states there is probably no workable mitigation.
  • Why it matters: The technique brings a bug class the author counts at over 100 CVEs, previously written off as needing a DMA-capable peripheral and physical access, into reach from software. The affected hardware range is not established beyond the single AMD Zen 3 part tested, and no affected microarchitecture list, firmware version range, or fix is stated, so the reach of the technique is open.
  • Follow-up: Whether the technique reproduces on other microarchitectures, and any vendor or firmware response.

send feedback on this story