[mps-discussion] The x86 ENTER instruction leaks read/write page-fault counts into userspace

David Jones drj at pobox.com
Mon Aug 19 15:42:56 UTC 2024


because it's not restartable (!)

https://infosec.exchange/@jann/112983458910799814

I didn't work through all the details but the basics seem to be that
if ENTER is used copy an overlapping region downwards on the stack
(not its normal use), then restarting it is not idempotent, and the
subsequent data can be inspected to count how many faults occurred.

Cheers,
 drj




More information about the MPS-discussion mailing list