Intel won’t patch new Spectre-like chip vulnerabilities for another 12 days

Patches for all operating systems and virtual machines may not be ready until later this year - report

Processor

Intel won't patch a new series of Spectre-related flaws in its chips for another 12 days, it is reported.

Fixes for the flaws, known as 'Spectre Next Generation', were scheduled for 7 May, but the chip manufacturer is allegedly having issues getting the updates ready in time, needing another two weeks to do so. This pushes the release date back to 21 May.

Advertisement - Article continues below

This is according to a report in German IT publication Heise, which suggests the patches could take even longer to arrive.

The flaws were originally reported earlier this month and are caused by the same design issue responsible for the original Spectre vulnerabilities. Around eight flaws have been discovered but technical details about them are yet to be published. Each flaw has a CVE number and each requires a patch to fix the issue.

Spectre Next Generation flaws affect Core i processors and their Xeon derivatives as far back as 2010, Heise reports. These are common Intel processors found in desktops, laptops and servers.

The flaws also reportedly affect Atom-based Pentium, Celeron and Atom processors dating back to 2013 as well as those powering tablets, smartphones and embedded devices.

One of the most troublesome flaws affects Core i and Xeon chips, allowing hackers to attack systems and virtual machines from a compromised VM. These flaws may not be fixed until the middle of August.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

As well as microcode patches from Intel, fixes for the operating system will also be necessary, the publication said.

An Intel spokeswoman said in a statement sent to IT Pro: "Protecting our customers' data and ensuring the security of our products are critical priorities for us. We routinely work closely with customers, partners, other chipmakers and researchers to understand and mitigate any issues that are identified, and part of this process involves reserving blocks of CVE numbers. We believe strongly in the value of coordinated disclosure and will share additional details on any potential issues as we finalise mitigations. As a best practice, we continue to encourage everyone to keep their systems up to date."

Featured Resources

Top 5 challenges of migrating applications to the cloud

Explore how VMware Cloud on AWS helps to address common cloud migration challenges

Download now

3 reasons why now is the time to rethink your network

Changing requirements call for new solutions

Download now

All-flash buyer’s guide

Tips for evaluating Solid-State Arrays

Download now

Enabling enterprise machine and deep learning with intelligent storage

The power of AI can only be realised through efficient and performant delivery of data

Download now
Advertisement

Most Popular

Visit/security/privacy/355155/zoom-kills-facebook-integration-after-data-transfer-backlash
privacy

Zoom kills Facebook integration after data transfer backlash

30 Mar 2020
Visit/infrastructure/server-storage/355118/hpe-warns-of-critical-bug-that-destroys-ssds-after-40000-hours
Server & storage

HPE warns of 'critical' bug that destroys SSDs after 40,000 hours

26 Mar 2020
Visit/software/355113/companies-offering-free-software-to-fight-covid-19
Software

These are the companies offering free software during the coronavirus crisis

25 Mar 2020
Visit/cloud/355098/ibm-dedicates-supercomputing-power-to-coronavirus-researchers
high-performance computing (HPC)

IBM dedicates supercomputing power to coronavirus research

24 Mar 2020