[mps-discussion] The x86 ENTER instruction leaks read/write page-fault counts into userspace
David Jones
drj at pobox.com
Mon Aug 19 15:42:56 UTC 2024
because it's not restartable (!)
https://infosec.exchange/@jann/112983458910799814
I didn't work through all the details but the basics seem to be that
if ENTER is used copy an overlapping region downwards on the stack
(not its normal use), then restarting it is not idempotent, and the
subsequent data can be inspected to count how many faults occurred.
Cheers,
drj
More information about the MPS-discussion
mailing list