Intel's 10th generation and above CPUs are confirmed to be affected by the new "Reptar" vulnerability, but the company has quickly rolled out mitigations for its latest chips. The Reptar vulnerability, labeled CVE-2023-23583, is considered a "critical risk" primarily due to its ability to "allow escalation and/or information disclosure and/or denial of service via local access."

Reptar, which has a CVSS score of 8.8, is capable of tampering with executing software instructions, causing harmful effects, one of which is the "redundant prefix problem." Simply put, interference from the "REX prefix" when executing specific instructions may lead to unpredictable system behavior and cause system crashes/stucks.

However, the important fact to note is that Google's security research team discovered this vulnerability months ago. According to Tavis Ormandy, "Reptar" can cause the CPU to malfunction and may cause "unexpected behavior" in terms of operation. The vulnerability had a huge impact on virtual machines, putting the security of cloud hosts and devices at risk and potentially compromising the data of thousands of people.

Google security researcher Tavis Ormandy said:

During testing we observed some very strange behavior. For example, branches are taken to unexpected locations, unconditional branches are ignored, and the processor no longer accurately records the instruction pointer in xsave or call instructions. Oddly, when we try to understand what's going on, we see the debugger reporting invalid status. This seemed to indicate a serious problem, but in a few days of experimentation we found that when multiple cores triggered the same error, the processor would start reporting machine check exceptions and stop running.

Security researchers have verified this even in an unprivileged guest virtual machine, so this already has serious security implications for cloud providers. Once this was confirmed to be a security issue, the situation was immediately reported to Intel.

As far as security report responses go, it took a long time, but fortunately Intel responded. Since the vulnerability has affected 10th generation and newer CPUs, Intel has currently launched mitigation measures for 12th, 13th and 4th generation Intel Xeon processors. There haven't been any reports of active attacks via Reptar, which is why Intel may choose to get ahead of relatively new generations of processors.

If you are concerned that you may be affected by Reptar, you can see a list of affected CPUs in the image below to apply mitigations:

https://www.intel.com/content/www/us/en/developer/topic-technology/software-security-guidance/processors-affected-consolidated-product-cpu-model.html

While this is uncertain, applying mitigations may result in performance degradation, so you should keep this in mind before proceeding.

Products updated with new microcode:

The following products have been mitigated: