• Avid Amoeba@lemmy.ca
    cake
    link
    fedilink
    English
    arrow-up
    135
    ·
    edit-2
    11 months ago

    Requires kernel-level access. Also AMD is “releasing mitigations,” so is it “unfixable?”

    • Bjornir@programming.dev
      link
      fedilink
      English
      arrow-up
      48
      arrow-down
      2
      ·
      11 months ago

      If you have kernel access you can already do almost everything so a vulnerability on top of that isn’t that bad since no one should have kernel access to your computer

      • floofloof@lemmy.ca
        link
        fedilink
        English
        arrow-up
        14
        ·
        11 months ago

        It means that a malicious actor would already need to have hacked your computer quite deeply through some other vulnerability (or social engineering) before they could take advantage of this one. But I don’t agree with another commenter here that this is a “nothingburger”: this vulnerability enables such a hacker to leave undetectable malware that you just can’t remove from the computer even if you replace everything but the motherboard. That’s significant, particularly for anyone who might be a target of cyber-espionage.