Exploiting System Management Mode with a very long interrupt
WhiteDawn
45 points
12 comments
August 10, 2026
Related Discussions
Found 5 related stories in 41.9ms across 4,128 title embeddings via pgvector HNSW
- Systems and Delays vinhnx · 48 pts · July 26, 2026 · 42% similar
- Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles EatonZ · 145 pts · July 27, 2026 · 41% similar
- Systemd Linger edward · 61 pts · July 26, 2026 · 41% similar
- OSS-SEC: 432 Linux kernel CVEs (in less than 32 hours) refp · 14 pts · July 22, 2026 · 37% similar
- Tl;dv: Over 180k meetings left wide open colesantiago · 359 pts · August 10, 2026 · 37% similar
Discussion Highlights (5 comments)
nazgulsenpai
I'm amused at the lengths the readme goes to in order to drive home the fact that this needs to be a LOOOOOOOOOOOOOOOOOOOONG instruction, including the unnecessarily long code block illustration. The topic is interesting anyway, but that makes it way more entertaining.
londons_explore
Unclear why there is a 1 second timeout at all. Presumably the patch for that will be to make it an infinity timeout.
kmeisthax
...huh, I was wondering why serial machine code prankster xoreaxeaxeax was keeping lists of extremely long-running instructions. Hopefully this is at least only possible in kernel mode, right? Right?!
mike_hearn
The designers of the firmware anticipate this attack but punt it to the vendor, apparently: // // Platform implementor should choose a timeout value appropriately: [snip] // - The timeout value must be longer than longest possible IO operation in the system
Liftyee
I don't know much about the specifics of CPU architecture apart from the existence of assembly and different modes. Either way the explanation was still entertaining and interesting. smiiiiiiii