{"id":700,"date":"2018-08-17T14:20:44","date_gmt":"2018-08-17T11:20:44","guid":{"rendered":"https:\/\/upcloud.com\/global\/us\/2018\/08\/17\/intel-foreshadow-l1tf-vulnerability\/"},"modified":"2018-08-17T14:20:44","modified_gmt":"2018-08-17T11:20:44","slug":"intel-foreshadow-l1tf-vulnerability","status":"publish","type":"post","link":"https:\/\/upcloud.com\/global\/blog\/intel-foreshadow-l1tf-vulnerability\/","title":{"rendered":"Information regarding Foreshadow, the Intel L1 Terminal Fault vulnerability"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Intel recently shared information<\/strong> about a newly identified vulnerability in their&nbsp;processors. It concerns a speculative execution side-channel method that Intel calls L1 Terminal Fault or L1TF for short. The vulnerability was discovered by two independent&nbsp;groups of researchers who have titled it&nbsp;<a href=\"https:\/\/foreshadowattack.eu\/\" target=\"_blank\" rel=\"noopener noreferrer\">Foreshadow<\/a>.<\/p>\n\n\n\n<div style=\"position: relative;padding-bottom: 56.25%;padding-top: 35px;height: 0;overflow: hidden\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">L1TF aka Foreshadow<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Foreshadow vulnerability (CVE-2018-3615) is an exploit on the speculative execution on Intel processors. It can allow attackers to access sensitive information stored in the Level 1 CPU cache and affects most Intel processors. While investigating the cause of the Foreshadow, Intel identified two related attacks (CVE-2018-3620 &amp;&nbsp;CVE-2018-3646) now called Foreshadow Next Generation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>At the moment, no known public exploits exist<\/strong>. However, the Foreshadow-NG could potentially be used to read information from the L1 in a public cloud. This may include data from the operating system, kernel, hypervisor or the neighbouring virtual machine. VMs sharing the same physical CPU core also share the L1 cache which leaves them vulnerable to the attack. Fortunately, there is <strong>no way to make targeted attacks against specific data or virtual machine<\/strong> as guest servers have no way to choose which physical CPU core they use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Due to the nature of the vulnerability, it has been categorised as high severity. Mitigation against the attack vectors will require&nbsp;upgrades to the system microcode. Intel has released some updates to address the issue but the earlier updates made for Meltdown and Spectre are not effective against the L1TF.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Mitigating the vulnerability<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When the issue was first&nbsp;announced, we began immediately testing and validating the updates in preparations for deployment. As the Foreshadow-NG (CVE-2018-3646) is a risk especially to virtualized environments such as cloud service providers, we are auditing and updating all affected infrastructure. We expect to be able to perform the upgrades without any major disruptions to your cloud servers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Likewise to the <a href=\"https:\/\/upcloud.com\/global\/blog\/intel-cpu-vulnerability-meltdown\" target=\"_blank\" rel=\"noreferrer noopener\">Spectre and Meltdown vulnerabilities<\/a>, <strong>users should also upgrade the operating systems<\/strong> on their cloud servers as the fixes become available from their vendors.<br>We are upgrading our public templates to make sure all future deployments are secure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The updates to mitigate the vulnerability are expected&nbsp;to affect performance or resource utilisation in some specific workloads. As Intel is working with their industry partners to provide multiple solutions to address the problem, the final impact on performance is not yet clear. Regardless of the&nbsp;approach to fix the vulnerability, we are focused on minimising performance loss while thoroughly securing the systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Should you have any further questions, please don\u2019t hesitate&nbsp;<a href=\"https:\/\/upcloud.com\/global\/contact\">to contact our support staff<\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/signup.upcloud.com\/\"><img decoding=\"async\" src=\"https:\/\/upcloud.com\/media\/Upcloud-cta-2-300x151.jpg\" alt=\"Call to action regarding signing up for UpCloud's free trial.\" class=\"wp-image-10919\" \/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><\/h2>\n","protected":false},"excerpt":{"rendered":"<p>Intel recently shared information about a newly identified vulnerability in their&nbsp;processors. It concerns a speculative execution side-channel method that Intel calls L1 Terminal Fault or [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":60494,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"250,679,562,451,82,751","_relevanssi_noindex_reason":"Blocked by a filter function","footnotes":""},"categories":[4],"tags":[],"class_list":["post-700","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-announcements"],"acf":[],"_links":{"self":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts\/700","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/comments?post=700"}],"version-history":[{"count":0,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts\/700\/revisions"}],"wp:attachment":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/media?parent=700"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/categories?post=700"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/tags?post=700"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}