![]() |
|
Message-ID: <6f9ffc49-ad46-45eb-9d6f-7d58769c3671@gmail.com> Date: Wed, 5 Mar 2025 23:03:49 -0600 From: Jacob Bachmeyer <jcb62281@...il.com> To: oss-security@...ts.openwall.com, Solar Designer <solar@...nwall.com> Cc: Tavis Ormandy <taviso@...il.com> Subject: Re: AMD Microcode Signature Verification Vulnerability On 3/5/25 21:30, Solar Designer wrote: > [...] I'll focus on what the vulnerability and its fix are: > >> [...] >> >> Forging On >> We noticed that the key from an old Zen 1 CPU was the example key of the >> NIST SP 800-38B publication (Appendix D.1 2b7e1516 28aed2a6 abf71588 >> 09cf4f3c) and was reused until at least Zen 4 CPUs. [...] They... used... the... example... key... in... a... real... production... system... [I have no words.] -- Jacob
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.