By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Training Solo: New Set Of Serious Security Vulnerabilities Exposed For Intel & Arm CPUs
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Training Solo: New Set Of Serious Security Vulnerabilities Exposed For Intel & Arm CPUs
Computing

Training Solo: New Set Of Serious Security Vulnerabilities Exposed For Intel & Arm CPUs

News Room
Last updated: 2025/05/12 at 1:13 PM
News Room Published 12 May 2025
Share
SHARE

The VUSec security researchers are at it again… The embargo is now lifted on another set of of security vulnerabilities affecting Intel processors as well as Arm core designs. This new vulnerability is dubbed Training Solo.

Security researchers discovered that domain isolation used for commonly mitigating Spectre Variant Two vulnerabilities have multiple shortcomings across different CPU architectures. Making matters worse, Training Solo exposes three separate variants with multiple mitigations needed.

Training Solo vulnerability

The ITS variant of Training Solo requires an Intel CPU microcode update as well as software mitigations to the Linux kernel and KVM. There’s also a Training Solo variant affecting Intel Lion Cove cores requiring a separate mitigation approach. Lastly, the third variant also requires an Intel microcode update as well as Intel and Arm software patches to the Linux kernel.

Training Solo mitigations

The VUSec security paper going live today explains: “In this paper, we challenge this assumption and show that even perfect domain isolation is insufficient to deter practical attacks. To this end, we systematically analyze self-training Spectre-v2 attacks, where both training and speculative control-flow hijacking occur in the same (victim) domain. While self-training attacks are believed to be limited to the in-domain scenario—where attackers can run arbitrary code and inject their own disclosure gadgets in a (default-off) sandbox such as eBPF—our analysis shows cross-domain variants are possible in practice. Specifically, we describe three new classes of attacks against the Linux kernel and present two end-to-end exploits that leak kernel memory on recent Intel CPUs at up to 17 KB/sec. During our investigation, we also stumbled upon two Intel issues which completely break (user, guest, and hypervisor) isolation and re-enable classic Spectre-v2 attacks.”

Training Solo vulnerability

I was only notified a short time in advance of today’s embargo lift on Training Solo, so I am still digging through the details myself. The Training Solo website for this vulnerability should be live now at VUSec.net. As Linux kernel patches and new Intel CPU microcode becomes available, I will be conducting some benchmarks on them to measure any new associated overhead to these additional security mitigations.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Java News Roundup: OpenJDK JEPs, Hibernate Reactive, Infinispan, JHipster, Gatherers4j
Next Article The upgraded VMU Pro turns the Dreamcast’s memory card into a handheld emulator
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Kenyan MP seeks ban on cashless-only payments under $775
Computing
The Peloton treadmill just hit its lowest price this year at Amazon
News
How to Watch Google’s ‘The Android Show: I/O Edition’ Event Live
Software
Pioneer HDJ-CUE1BT Review
Gadget

You Might also Like

Computing

Kenyan MP seeks ban on cashless-only payments under $775

3 Min Read
Computing

China and US tie for top spot in gold medal count at Paris Olympics 2024 · TechNode

1 Min Read
Computing

Chinese YouTube star Li Ziqi returns to social media after 3-year hiatus · TechNode

2 Min Read
Computing

Baidu unveils its first AI glasses Xiaodu AI Glasses · TechNode

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?