PortSmash vulnerability hits Intel CPUs

Some of Intel's most popular chips have been hit by a major security flaw, researchers have claimed.

This vulnerability, named PortSmash, has been discovered by a team of academics from Tampere University of Technology in Finland and Technical University of Havana Cuba.

PortSmash is impacting some of Intel's most well-known processors, including the Kaby Lake and Skylake units found in many laptops on the market today, and could potentially allow attackers to leak encrypted data from the CPU’s internal processes.

Intel CPU threat

Specifically, PortSmash targets a flaw in Intel's hyperthreading technology, which cuts down on the time needed for a device to carry out high-end computing tasks.

The researchers where able to exploit a leak in the hyperthreading system to access secure private keys from servers running Skylake and Kaby Lake processors by tracking specific computing processes in order to deduce the key.

The flaw affects both servers and PCs, the researchers said, although the former is more at risk, which could prove dangerous for cloud providers who offer infrastructure-as-a-service (IaaS) platforms, as servers, storage and networking hardware could be targeted in a single shot.

Intel has responded to the report, noting that it expects that the threat it "is not unique" to its platforms alone. 

"Protecting our customers’ data and ensuring the security of our products is a top priority for Intel and we will continue to work with customers, partners and researchers to understand and mitigate any vulnerabilities that are identified," the company added.

Via: ArsTechnica

TOPICS
Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Pro
Racks of servers inside a data center.
Modernizing data centers: an efficient path forward
Dr. Peter Zhou, President of Huawei Data Storage Product Line
Why AI commonization is so important for business intelligent transformation and what Huawei’s data storage has to offer
Wix automation
The world's leading website builder aims to save businesses time with new tool
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Hands typing on a keyboard surrounded by security icons
The psychology of scams: how cybercriminals are exploiting the human brain
Latest in News
Brad Pitt looks over his right shoulder with 'F1' written behind him
Apple Original Films will take you behind-the-scenes of a racing cockpit in this new thrilling F1 movie trailer
AI writer
Coding AI tells developer to write it himself
Reacher looking down at another character from the Prime Video TV series Reacher
Reacher season 3 becomes Prime Video’s biggest returning show thanks to Hollywood’s biggest heavyweight
Image showing detail of the Leica D-Lux 8
Still can't get a Fujifilm X100VI? This premium Leica compact costs less, and it's in stock
Man using iMessage on an iPhone
Apple will finally enable encrypted RCS messages between iOS and Android, and it's about time
Google Messages update
Google Messages could soon follow WhatsApp with an upgrade that makes it much easier to join group chats