Multiple kernel AMD K7/K8 CPUs floating-point unit information disclosure
| amd-fpu-information-disclosure (25871) |
Description:
Linux and BSD kernels running on systems with AMD K7 or K8 CPUs could allow a local attacker to obtain sensitive information, caused by an error where FOP, FIP and FDP x87 registers are only saved or restored by FXSAVE or FXRSTOR if the exception summary bit is set to 1. This error could result in processes that use floating-point unit (FPU) operations to leak sensitive information, which could be used by an attacker to launch further attacks against the affected system.
Platforms Affected:
- Canonical, Ubuntu 5.04
- Canonical, Ubuntu 5.10
- Canonical, Ubuntu 6.06 LTS
- Debian, Debian Linux 3.1
- FreeBSD, FreeBSD
- Linux, Kernel 2.6.0 test7
- Linux, Kernel 2.6.0 test8
- Linux, Kernel 2.6.0 test9
- Linux, Kernel 2.6.0 test6
- Linux, Kernel 2.6.0 test5
- Linux, Kernel 2.6.0
- Linux, Kernel 2.6.0 test3
- Linux, Kernel 2.6.0 test2
- Linux, Kernel 2.6.0 test11
- Linux, Kernel 2.6.0 test10
- Linux, Kernel 2.6.0 test1
- Linux, Kernel 2.6.0 test4
- Linux, Kernel 2.6.1 rc1
- Linux, Kernel 2.6.1 rc2
- Linux, Kernel 2.6.1 rc3
- Linux, Kernel 2.6.1
- Linux, Kernel 2.6.10 rc2
- Linux, Kernel 2.6.10 rc3
- Linux, Kernel 2.6.10
- Linux, Kernel 2.6.10 rc1
- Linux, Kernel 2.6.11 rc2
- Linux, Kernel 2.6.11 rc3
- Linux, Kernel 2.6.11 rc4
- Linux, Kernel 2.6.11
- Linux, Kernel 2.6.11 rc5
- Linux, Kernel 2.6.11 rc1
- Linux, Kernel 2.6.11.1
- Linux, Kernel 2.6.11.10
- Linux, Kernel 2.6.11.11
- Linux, Kernel 2.6.11.12
- Linux, Kernel 2.6.11.2
- Linux, Kernel 2.6.11.3
- Linux, Kernel 2.6.11.4
- Linux, Kernel 2.6.11.5
- Linux, Kernel 2.6.11.6
- Linux, Kernel 2.6.11.7
- Linux, Kernel 2.6.11.8
- Linux, Kernel 2.6.11.9
- Linux, Kernel 2.6.12 rc6
- Linux, Kernel 2.6.12 rc5
- Linux, Kernel 2.6.12
- Linux, Kernel 2.6.12 rc4
- Linux, Kernel 2.6.12 rc3
- Linux, Kernel 2.6.12 rc2
- Linux, Kernel 2.6.12 rc1
- Linux, Kernel 2.6.12.1
- Linux, Kernel 2.6.12.12
- Linux, Kernel 2.6.12.2
- Linux, Kernel 2.6.12.22
- Linux, Kernel 2.6.12.3
- Linux, Kernel 2.6.12.4
- Linux, Kernel 2.6.12.5
- Linux, Kernel 2.6.12.6
- Linux, Kernel 2.6.13 rc6
- Linux, Kernel 2.6.13 rc7
- Linux, Kernel 2.6.13 rc5
- Linux, Kernel 2.6.13
- Linux, Kernel 2.6.13 rc4
- Linux, Kernel 2.6.13 rc3
- Linux, Kernel 2.6.13 rc2
- Linux, Kernel 2.6.13 rc1
- Linux, Kernel 2.6.13.1
- Linux, Kernel 2.6.13.2
- Linux, Kernel 2.6.13.3
- Linux, Kernel 2.6.13.4
- Linux, Kernel 2.6.13.5
- Linux, Kernel 2.6.14 rc4
- Linux, Kernel 2.6.14 rc5
- Linux, Kernel 2.6.14 rc2
- Linux, Kernel 2.6.14
- Linux, Kernel 2.6.14 rc1
- Linux, Kernel 2.6.14 rc3
- Linux, Kernel 2.6.14.1
- Linux, Kernel 2.6.14.2
- Linux, Kernel 2.6.14.3
- Linux, Kernel 2.6.14.4
- Linux, Kernel 2.6.14.5
- Linux, Kernel 2.6.14.6
- Linux, Kernel 2.6.14.7
- Linux, Kernel 2.6.15 rc7
- Linux, Kernel 2.6.15 rc1
- Linux, Kernel 2.6.15
- Linux, Kernel 2.6.15 rc2
- Linux, Kernel 2.6.15 rc6
- Linux, Kernel 2.6.15 rc3
- Linux, Kernel 2.6.15 rc4
- Linux, Kernel 2.6.15 rc5
- Linux, Kernel 2.6.15.1
- Linux, Kernel 2.6.15.11
- Linux, Kernel 2.6.15.2
- Linux, Kernel 2.6.15.3
- Linux, Kernel 2.6.15.4
- Linux, Kernel 2.6.15.5
- Linux, Kernel 2.6.15.6
- Linux, Kernel 2.6.15.7
- Linux, Kernel 2.6.16 rc6
- Linux, Kernel 2.6.16 rc7
- Linux, Kernel 2.6.16
- Linux, Kernel 2.6.16 rc5
- Linux, Kernel 2.6.16 rc4
- Linux, Kernel 2.6.16 rc3
- Linux, Kernel 2.6.16.1
- Linux, Kernel 2.6.16.2
- Linux, Kernel 2.6.16.3
- Linux, Kernel 2.6.16.4
- Linux, Kernel 2.6.16.5
- Linux, Kernel 2.6.16.6
- Linux, Kernel 2.6.16.7
- Linux, Kernel 2.6.16.8
- Linux, Kernel 2.6.2 rc1
- Linux, Kernel 2.6.2
- Linux, Kernel 2.6.2 rc3
- Linux, Kernel 2.6.2 rc2
- Linux, Kernel 2.6.3 rc1
- Linux, Kernel 2.6.3 rc3
- Linux, Kernel 2.6.3 rc2
- Linux, Kernel 2.6.3
- Linux, Kernel 2.6.3 rc4
- Linux, Kernel 2.6.4 rc3
- Linux, Kernel 2.6.4 rc2
- Linux, Kernel 2.6.4 rc1
- Linux, Kernel 2.6.4
- Linux, Kernel 2.6.5 rc3
- Linux, Kernel 2.6.5 rc2
- Linux, Kernel 2.6.5
- Linux, Kernel 2.6.5 rc1
- Linux, Kernel 2.6.6 rc3
- Linux, Kernel 2.6.6 rc1
- Linux, Kernel 2.6.6
- Linux, Kernel 2.6.6 rc2
- Linux, Kernel 2.6.7
- Linux, Kernel 2.6.7 rc1
- Linux, Kernel 2.6.7 rc2
- Linux, Kernel 2.6.7 rc3
- Linux, Kernel 2.6.8 rc3
- Linux, Kernel 2.6.8 rc2
- Linux, Kernel 2.6.8 rc4
- Linux, Kernel 2.6.8 rc1
- Linux, Kernel 2.6.8
- Linux, Kernel 2.6.8.1
- Linux, Kernel 2.6.9
- Linux, Kernel 2.6.9 rc2
- Linux, Kernel 2.6.9 rc1
- Linux, Kernel 2.6.9 rc3
- Linux, Kernel 2.6.9 rc4
- Novell, UnitedLinux 1.0
- RedHat, Enterprise Linux 2.1 WS
- RedHat, Enterprise Linux 2.1 AS
- RedHat, Enterprise Linux 2.1 ES
- RedHat, Enterprise Linux 3 WS
- RedHat, Enterprise Linux 3 ES
- RedHat, Enterprise Linux 3 AS
- RedHat, Enterprise Linux 3 Desktop
- RedHat, Enterprise Linux 4 AS
- RedHat, Enterprise Linux 4 ES
- RedHat, Enterprise Linux 4 WS
- RedHat, Enterprise Linux 4 Desktop
- SuSE, Linux Enterprise Server 8
- SuSE, Linux Enterprise Server 9
- SuSE, SuSE Linux 10.0
- SuSE, SuSE Linux 9.1
- SuSE, SuSE Linux 9.2
- SuSE, SuSE Linux 9.3
- SuSE, SuSE Linux Desktop 1.0
- SuSE, SuSE SLES 9
- VMware, ESX Server 2.1.3
- VMware, ESX Server 2.5.3
- VMware, ESX Server 2.5.4
- VMware, ESX Server 3.0.0
Remedy:
For Linux kernel:
Upgrade to the latest stable version of Linux kernel (2.6.16.9 or later), available from The Linux Kernel Archives. See References.
For VMware 2.5.3:
Apply the patch for this vulnerability, as listed in the VMware Advisory esx-253-200610-patch. See References.
Refer to FreeBSD Security Advisory FreeBSD-SA-06:14.fpu for patch, upgrade, or suggested workaround information. See References.
For Debian GNU/Linux:
Refer to DSA-1097-1 and DSA-1103-1 for patch, upgrade, or suggested workaround information. See References.
For Red Hat Linux 2.1:
Refer to RHSA-2006:0579-12 for patch, upgrade, or suggested workaround information. See References.
For Red Hat Linux 3:
Refer to RHSA-2006:0437-22 for patch, upgrade, or suggested workaround information. See References.
For Red Hat Linux 4:
Refer to RHSA-2006:0575-22 for patch, upgrade, or suggested workaround information. See References.
For ESX Server 3.0.0:
Apply the patch for this vulnerability, as listed in VMware Advisory Doc ID: 2533126. See References.
For VMware ESX Server 2.1.3:
Apply the patch for this vulnerability, as listed in the VMware Advisory esx-213-200610-patch. See References.
For VMware ESX Server 2.5.4:
Apply the patch for this vulnerability, as listed in the VMware Advisory esx-254-200610-patch. See References.
For SUSE Linux:
Refer to SUSE-SA:2006:028 for patch, upgrade, or suggested workaround information. See References.
For other distributions:
Contact your vendor for upgrade or patch information.
Consequences:
Obtain Information
References:
- FreeBSD Security Advisory FreeBSD-SA-06:14.fpu , FPU information disclosure at ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:14.fpu.asc.
- Full-Disclosure Mailing List, Mon Nov 13 2006 - 17:22:20 CST, VMSA-2006-0005 - VMware ESX Server 2.5.4 Upgrade Patch 1 at http://archives.neohapsis.com/archives/fulldisclosure/2006-11/0223.html.
- Full-Disclosure Mailing List, Mon Nov 13 2006 - 17:22:38 CST, VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4 at http://archives.neohapsis.com/archives/fulldisclosure/2006-11/0226.html.
- Full-Disclosure Mailing List, Mon Nov 13 2006 - 17:22:54 CST, VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2 at http://archives.neohapsis.com/archives/fulldisclosure/2006-11/0224.html.
- Full-Disclosure Mailing List, Mon Nov 13 2006 - 17:23:11 CST, VMSA-2006-0009 - VMware ESX Server 3.0.0 AMD fxsave/restore issue at http://archives.neohapsis.com/archives/fulldisclosure/2006-11/0227.html.
- The Linux Kernel Archives, ChangeLog-2.6.16.9 at http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.9.
- The The Linux Kernel Archives Web site, The Linux Kernel Archives at http://www.kernel.org/.
- VMware Advisory esx-253-200610-patch, VMware ESX Server 2.5.3 Upgrade Patch 4 (for 2.5.3 Systems Only) at http://www.vmware.com/download/esx/esx-253-200610-patch.html.
- VMware KB Doc ID: 2533126 , ESX Server 3.0.0 Patch ESX-2533126: AMD fxsave/fxrstor Security Vulnerability at http://kb.vmware.com/vmtnkb/search.do?cmd=displayKC&docType=kc&externalId=2533126&sliceId=SAL_Public.
- VMware Web site, VMware ESX Server 2.5.4 Upgrade Patch 1 (for 2.5.4 Systems Only) at http://www.vmware.com/download/esx/esx-254-200610-patch.html.
- VMware Web site, VMware ESX Server 2.1.3 Upgrade Patch 2 (for 2.1.3 Systems Only) at http://www.vmware.com/download/esx/esx-213-200610-patch.html.
- ASA-2006-180: Updated kernel packages for Red Hat Enterprise Linux 3 Update 8 (RHSA-2006-0437)
- ASA-2006-200: Updated kernel packages available for Red Hat Enterprise Linux 4 Update 4 (RHSA-2006-0575)
- BID-17600: Multiple Vendor AMD CPU Local FPU Information Disclosure Vulnerability
- CVE-2006-1056: The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processers in a security-relevant fashion that was not addressed by the kernels.
- DSA-1097: kernel-source-2.4.27 -- several vulnerabilities
- DSA-1103: kernel-source-2.6.8 -- several vulnerabilities
- OSVDB ID: 24746: FreeBSD FPU x87 Register Information Disclosure
- OSVDB ID: 24807: Linux Kernel x87 Register Information Disclosure
- RHSA-2006-0437: Updated kernel packages for Red Hat Enterprise Linux 3 Update 8
- RHSA-2006-0575: Updated kernel packages available for Red Hat Enterprise Linux 4 Update 4
- RHSA-2006-0579: kernel security update
- SA19715: FreeBSD FPU x87 Register Information Leak
- SA19724: Linux Kernel x87 Register Information Leak
- SA21983: Avaya Products Linux Kernel Multiple Vulnerabilities
- SA22417: Avaya Products Linux Kernel Multiple Vulnerabilities
- SA22875: VMware ESX Server Multiple Vulnerabilities
- SA22876: VMware ESX Server x87 Register Information Leak
- SECTRACK ID: 1015966: FreeBSD Floating Point Unit Kernel Implementation Error May Let Local Users Obtain Sensitive Information
- SUSE-SA:2006:028: various kernel security problems
- USN-302-1: Linux kernel vulnerabilities
- VUPEN/ADV-2006-1426: Linux Kernel AMD K7/K8 CPU x87 Register Local Information Leak Vulnerability
- VUPEN/ADV-2006-4353: VMware AMD K7/K8 CPU x87 Register Local Information Disclosure Vulnerability
- VUPEN/ADV-2006-4502: VMware ESX Server Security Update Fixes Multiple Buffer Overflow Vulnerabilities
Reported:
Apr 18, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
