CVE-2019-11157 | Intel CPU Plundervolt¹¥»÷

Ðû²¼Ê±¼ä 2019-12-12


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


1.Åä¾°ÐÎò


¿ËÈÕ £¬Å·ÖÞÈýËù´óѧµÄѧÕßÅû¶ÁËÒ»¸öÓ°ÏìIntel SGX´æ´¢Êý¾ÝÍêÕûÐÔµÄPlundervoltÎó²î£¨CVE-2019-11157£© £¬¸ÃÎó²î¿ÉÓÃÓÚ»Ö¸´¼ÓÃÜÃÜÔ¿»òÔÚÒÔǰÇå¾²µÄÈí¼þÖÐÒýÈë¹ýʧ¡£Intel̨ʽ»ú¡¢·þÎñÆ÷ºÍÒÆ¶¯CPU¾ùÊÜÓ°Ïì¡£


2.Îó²îÁбí


CVE    ID£º    CVE-2019-11157

Îó²îÆ·¼¶£º    ¸ßΣ

CVSSÆÀ·Ö£º    7.9

CVSSVector:  CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Îó²î·ÖÀࣺ    ÌØÈ¨Éý¼¶¡¢ÐÅϢй¶

Ó°Ïì¹æÄ££º    Intel?µÚ6¡¢7¡¢8¡¢9ºÍ10´úCoreTM´¦Öóͷ£Æ÷

                    Intel?ÖÁÇ¿?´¦Öóͷ£Æ÷E3 v5ºÍv6

                    Intel?ÖÁÇ¿?´¦Öóͷ£Æ÷E-2100ºÍE-2200¼Ò×å


3.Îó²îÏêÇé


ijЩIntel£¨R£©´¦Öóͷ£Æ÷ÖеĵçѹÉèÖñ£´æ²»×¼È·µÄÌõ¼þ¼ìÅÌÎÊÌâ £¬¿ÉÄÜ»áÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§Í¨¹ýÍâµØ»á¼û¾ÙÐÐÌØÈ¨Éý¼¶»òÐÅϢй¶¡£

Plundervolt¹¥»÷רÃÅÕë¶ÔIntel SGXÓ²¼þÇå¾²¹¦Ð§ £¬SGXΪӦÓóÌÐòÌṩһ¸ö¿ÉÐŵÄÖ´ÐÐÇéÐΡ£SGX¸ôÀëÇøÔÚÖ÷Intel CPUÄÚ´æµÄһС²¿·ÖÉÏÔËÐÐ £¬ÔÚÓ²¼þ¼¶±ð£¨SGXÄÚ´æÓëÆäÓàCPUÄÚ´æÍÑÀ룩ºÍÈí¼þ¼¶±ð£¨SGXÊý¾ÝÒѼÓÃÜ£©¾ù¾ÙÐиôÀë¡£


Plundervolt¹¥»÷ÍŽáÁËÁ½ÖÖ¹¥»÷ÊÖÒÕ £¬°üÀ¨Rowhammer¹¥»÷ºÍCLKSCREW¹¥»÷¡£PlundervoltʹÓÃCPUµÄµçÔ´ÖÎÀí½Ó¿ÚÀ´¸ü¸ÄSGX´æ´¢µ¥Î»ÄÚ²¿µÄµçѹºÍƵÂÊ £¬´Ó¶øµ¼ÖÂSGXÊý¾ÝµÄ²»ÐëÒª¸ü¸Ä¡£ÕâЩ¸ü¸Ä²»»áÆÆËðSGXµÄ±£ÃÜÐÔ £¬µ«»áÔÚSGX²Ù×÷¼°Æä´¦Öóͷ£µÄÊý¾ÝÖÐÒýÈë¹ýʧ £¬¼´Plundervolt²»»áÆÆËðSGX £¬¶øÖ»»áÆÆËðÆäÊä³ö¡£ÀýÈç £¬Plundervolt¿ÉÓÃÓÚÔÚSGXÄÚ²¿Ö´ÐеļÓÃÜËã·¨/²Ù×÷ÖÐÒý·¢¹ýʧ £¬´Ó¶øÊ¹¼ÓÃÜÄÚÈÝÒ»µ©ÍÑÀëSGX¾ÍºÜÈÝÒ×±»ÆÆ½â £¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÒÔ»Ö¸´ÓÃÓÚ¼ÓÃÜÆäÖÐÊý¾ÝµÄ¼ÓÃÜÃÜÔ¿¡£


Plundervolt²»¿É±»Ô¶³ÌʹÓà £¬²¢ÇÒÐèÒªroot»òadminÌØÈ¨´ÓÄ¿µÄÖ÷»úÉÏÔËÐгÌÐò¡£±ðµÄ £¬PlundervoltÎÞ·¨ÔÚÐéÄ⻯ÇéÐΣ¨ÀýÈçÐéÄâ»úºÍÔÆÅÌËã·þÎñ£©ÖÐÔËÐС£


4.ÐÞ¸´½¨Òé


IntelÔÚÇ徲ת´ïINTEL-SA-00289ÖÐÐû²¼ÁËÏà¹ØÎ¢´úÂëºÍBIOS¸üС£ÕâЩ¸üÐÂΪÖÎÀíÔ±ÌṩÁËÒ»¸öеÄBIOSÑ¡Ïî £¬¿ÉÒÔÔÚËûÃDz»Ê¹ÓÃϵͳ»òÒÔΪPlundervolt£¨CVE-2019-11157£©×é³ÉÕæÕýΣº¦µÄÇéÐÎϽûÓÃϵͳÉϵĵçѹºÍƵÂÊ¿ØÖƽçÃæ¡£


5.²Î¿¼Á´½Ó


https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00289.html

https://plundervolt.com/

https://github.com/KitMurdock/plundervolt

https://www.zdnet.com/article/new-plundervolt-attack-impacts-intel-cpus/