“Negative Result: Reading Kernel Memory from User Mode” (Intel CPU Bug)
cyber.wtf
cyber.wtf
> So at this point my experiment is failed and thus the negative result.
> While I did set out to read kernel mode without privileges and that produced a negative result, I do feel like I opened a Pandora’s box. The thing is there was two positive results in my tests. The first is that Intel’s implementation of Tomasulo’s algorithm is not side channel safe. Consequently we have access to results of speculative execution despite the results never being committed. Secondly, my results demonstrate that speculative execution does indeed continue despite violations of the isolation between kernel mode and user mode.