CVE-2019-11157 | Intel CPU Plundervolt¹¥»÷

Ðû²¼Ê±¼ä 2019-12-12


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


1.Åä¾°ÐÎò


¿ËÈÕ £¬ £¬£¬ £¬£¬£¬Å·ÖÞÈýËù´óѧµÄѧÕßÅû¶ÁËÒ»¸öÓ°ÏìIntel SGX´æ´¢Êý¾ÝÍêÕûÐÔµÄPlundervoltÎó²î£¨CVE-2019-11157£© £¬ £¬£¬ £¬£¬£¬¸ÃÎó²î¿ÉÓÃÓÚ»Ö¸´¼ÓÃÜÃÜÔ¿»òÔÚÒÔǰÇå¾²µÄÈí¼þÖÐÒýÈë¹ýʧ¡£¡£Intel̨ʽ»ú¡¢Ð§ÀÍÆ÷ºÍÒÆ¶¯CPU¾ùÊÜÓ°Ïì¡£¡£


2.Îó²îÁбí


CVE    ID£º    CVE-2019-11157

Îó²îÆ·¼¶£º    ¸ßΣ

CVSSÆÀ·Ö£º    7.9

CVSSVector:  CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Îó²î·ÖÀࣺ    ÌØÈ¨Éý¼¶¡¢ÐÅϢй¶

Ó°Ïì¹æÄ££º    Intel?µÚ6¡¢7¡¢8¡¢9ºÍ10´úCoreTM´¦Öóͷ£Æ÷

                    Intel?ÖÁÇ¿?´¦Öóͷ£Æ÷E3 v5ºÍv6

                    Intel?ÖÁÇ¿?´¦Öóͷ£Æ÷E-2100ºÍE-2200¼Ò×å


3.Îó²îÏêÇé


ijЩIntel£¨R£©´¦Öóͷ£Æ÷ÖеĵçѹÉèÖñ£´æ²»×¼È·µÄÌõ¼þ¼ìÅÌÎÊÌâ £¬ £¬£¬ £¬£¬£¬¿ÉÄÜ»áÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§Í¨¹ýÍâµØ»á¼û¾ÙÐÐÌØÈ¨Éý¼¶»òÐÅϢй¶¡£¡£

Plundervolt¹¥»÷רÃÅÕë¶ÔIntel SGXÓ²¼þÇå¾²¹¦Ð§ £¬ £¬£¬ £¬£¬£¬SGXΪӦÓóÌÐòÌṩһ¸ö¿ÉÐŵÄÖ´ÐÐÇéÐΡ£¡£SGX¸ôÀëÇøÔÚÖ÷Intel CPUÄÚ´æµÄһС²¿·ÖÉÏÔËÐÐ £¬ £¬£¬ £¬£¬£¬ÔÚÓ²¼þ¼¶±ð£¨SGXÄÚ´æÓëÆäÓàCPUÄÚ´æÍÑÀ룩ºÍÈí¼þ¼¶±ð£¨SGXÊý¾ÝÒѼÓÃÜ£©¾ù¾ÙÐиôÀë¡£¡£


Plundervolt¹¥»÷Á¬ÏµÁËÁ½ÖÖ¹¥»÷ÊÖÒÕ £¬ £¬£¬ £¬£¬£¬°üÀ¨Rowhammer¹¥»÷ºÍCLKSCREW¹¥»÷¡£¡£PlundervoltʹÓÃCPUµÄµçÔ´ÖÎÀí½Ó¿ÚÀ´¸ü¸ÄSGX´æ´¢µ¥Î»ÄÚ²¿µÄµçѹºÍƵÂÊ £¬ £¬£¬ £¬£¬£¬´Ó¶øµ¼ÖÂSGXÊý¾ÝµÄ²»ÐëÒª¸ü¸Ä¡£¡£ÕâЩ¸ü¸Ä²»»áÆÆËðSGXµÄ±£ÃÜÐÔ £¬ £¬£¬ £¬£¬£¬µ«»áÔÚSGX²Ù×÷¼°Æä´¦Öóͷ£µÄÊý¾ÝÖÐÒýÈë¹ýʧ £¬ £¬£¬ £¬£¬£¬¼´Plundervolt²»»áÆÆËðSGX £¬ £¬£¬ £¬£¬£¬¶øÖ»»áÆÆËðÆäÊä³ö¡£¡£ÀýÈç £¬ £¬£¬ £¬£¬£¬Plundervolt¿ÉÓÃÓÚÔÚSGXÄÚ²¿Ö´ÐеļÓÃÜËã·¨/²Ù×÷ÖÐÒý·¢¹ýʧ £¬ £¬£¬ £¬£¬£¬´Ó¶øÊ¹¼ÓÃÜÄÚÈÝÒ»µ©ÍÑÀëSGX¾ÍºÜÈÝÒ×±»ÆÆ½â £¬ £¬£¬ £¬£¬£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÒÔ»Ö¸´ÓÃÓÚ¼ÓÃÜÆäÖÐÊý¾ÝµÄ¼ÓÃÜÃÜÔ¿¡£¡£


Plundervolt²»¿É±»Ô¶³ÌʹÓà £¬ £¬£¬ £¬£¬£¬²¢ÇÒÐèÒªroot»òadminÌØÈ¨´ÓÄ¿µÄÖ÷»úÉÏÔËÐгÌÐò¡£¡£±ðµÄ £¬ £¬£¬ £¬£¬£¬PlundervoltÎÞ·¨ÔÚÐéÄ⻯ÇéÐΣ¨ÀýÈçÐéÄâ»úºÍÔÆÅÌËãЧÀÍ£©ÖÐÔËÐС£¡£


4.ÐÞ¸´½¨Òé


IntelÔÚÇ徲ת´ïINTEL-SA-00289ÖÐÐû²¼ÁËÏà¹ØÎ¢´úÂëºÍBIOS¸üС£¡£ÕâЩ¸üÐÂΪÖÎÀíÔ±ÌṩÁËÒ»¸öеÄBIOSÑ¡Ïî £¬ £¬£¬ £¬£¬£¬¿ÉÒÔÔÚËûÃDz»Ê¹ÓÃϵͳ»òÒÔΪPlundervolt£¨CVE-2019-11157£©×é³ÉÕæÕýΣº¦µÄÇéÐÎϽûÓÃϵͳÉϵĵçѹºÍƵÂÊ¿ØÖƽçÃæ¡£¡£


5.²Î¿¼Á´½Ó


https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00289.html

https://plundervolt.com/

https://github.com/KitMurdock/plundervolt

https://www.zdnet.com/article/new-plundervolt-attack-impacts-intel-cpus/