transientfail icon indicating copy to clipboard operation
transientfail copied to clipboard

Add Snoop Assisted L1D Sampling attack?

Open jovanbulck opened this issue 5 years ago • 0 comments

Described here and here; "Snoopy" seems to be a special type of Foreshadow/L1TF; not sure how this would fit into the classification tree? It doesn't seem that snoops are a new type of faults or assists, but maybe we can mention the technique under the various -L1 leaves? Would probably require more experimentation as well..

On certain processors and under certain conditions, data in a modified cache line that is being returned in response to a snoop may also be forwarded to a faulting, microarchitectural assist, or Intel® Transactional Synchronization Extensions (Intel® TSX) asynchronous aborting load operation to a different address that occurs simultaneously.

jovanbulck avatar Mar 11 '20 10:03 jovanbulck