vusec / inspectre-gadget

InSpectre Gadget: in-depth inspection and exploitability analysis of Spectre disclosure gadgets
https://vusec.github.io/inspectre-gadget/
Apache License 2.0
37 stars 3 forks source link

Add controlled part of the base together with independent part #5

Open AlviseDeFaveri opened 8 months ago

AlviseDeFaveri commented 8 months ago

To properly reason about max_secret_too_high, we need to reason about the controlled part of the base, i.e. the part that is both secret-independent and attacker-controlled.

We can add a TransmissionComponent to the Transmission object.

Test case:

__mod_zone_page_state a2336d92-83da-4404-8a1d-2b40ff52c0a9