Intel CPU vulnerability known as “Downfall” can reduce performance by 50%
Downfall (CVE-2022-40982), a security flaw recently disclosed by Intel, affects several generations of Intel processors. The weakness is related to Intel’s memory optimization feature and takes advantage of the Gather instruction, which speeds up data retrieval from dispersed memory locations. By accident making internal hardware registers visible, it gives malicious software access to information that is stored by other applications. The bug affects server and mainstream Intel processors with the microarchitectures Skylake and Rocket Lake. Here is a list of all the CPUs that are impacted. To address the issue, Intel has released updated software-level microcode. Concerns have been raised about the fix’s potential to negatively impact AVX2 and AVX-512 workloads using the Gather instruction by as much as 50%.
When Phoronix tested the Downfall mitigations, they found that different processors had distinct performance drops. For instance, in some testing, two Xeon Platinum 8380 processors operated about 6% slower, while the Core i7-1165G7 experienced performance deterioration ranging from 11% to 39%. Although these decreases fell short of Intel’s predicted 50% overhead, they are still substantial, particularly for High-Performance Computing (HPC) applications. The effects of Downfall may also apply to more widely used applications like video encoding rather than just highly specialized activities like AI or HPC. Users must choose between performance and security even if Intel has an opt-out mechanism and the microcode upgrade is not required. Executing a Downfall attack may appear difficult, but the ultimate decision over whether to use the mitigation or keep performance will probably depend on the demands and risk assessments of each individual.