¹í»êбäÖÖSWAPGS¹¥»÷·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-08-07

? ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1125£¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


SWAPGS¹¥»÷»áÓ°ÏìÔËÐÐIntel Ivy Bridge»ò¸üÐÂCPUµÄÈκÎÉ豸


·ì϶¸ÅÊö


Bitdefender×êÑÐÈËÔ±·¢ÏÖCPU¹í»ê·ì϶µÄбäÖÖ-SWAPGS·ì϶£¬£¬£¬£¬ £¬¸Ã·ì϶¿ÉÔÊÐí¶ñÒⷨʽ½Ó¼ûºÍ¶ÁȡϵͳÄÚºËÄÚ´æÖеÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£SWAPGS·ì϶ÊÇÒ»ÖÖ´§Ä¦ÐÔÖ´ÐеIJâÐÅ··ì϶£¬£¬£¬£¬ £¬¹¥»÷ÕßÄܹ»ÀûÓÃ64λCPUÖеÄSWAPGSÖ¸ÁîÍ»ÆÆÄÚ´æ¸ôÀ룬£¬£¬£¬ £¬ÔÊÐíÎÞÌØÈ¨µÄ¹¥»÷Õß½Ó¼ûÌØÈ¨Äں˵ÄÄÚ´æÃô¸ÐÐÅÏ¢£¬£¬£¬£¬ £¬Ô̺¬Ì¸ÌìÐÂÎÅ¡¢µç×ÓÓʼþ¡¢µÇ¼ʹ´¦¡¢Ö§¸¶ÐÅÏ¢¡¢ÃÜÂë¡¢¼ÓÃÜÃÜÔ¿¡¢ÁîÅÆºÍ½Ó¼ûÍ´´¦µÈ£¬£¬£¬£¬ £¬ÇÒ²»»áÁô϶ÔÓ²¼þµÄ¹¥»÷ºÛ¼£¡£¡£¡£¡£¡£¡£¡£¡£


ΪÁËÌá¸ßCPUµÄ»úÄÜ£¬£¬£¬£¬ £¬Ò»¸ö³ÆÎª´§Ä¦Ö´ÐеÄÖ°Äܽ«ÔÚËü֪·ÊÇ·ñ±ØÒªËüÃÇ֮ǰִÐÐÖ¸Áî¡£¡£¡£¡£¡£¡£¡£¡£Õë¶Ô´ËÖ°Äܵķì϶³ÆÎª²àÐÅ·¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Æù½ñΪֹ£¬£¬£¬£¬ £¬×î×ÅÃûµÄÀý×ÓÊÇMeltdown£¬£¬£¬£¬ £¬Spectre£¬£¬£¬£¬ £¬L1TFºÍMicroarchitectural Data Sampling£¨MDS£©¡£¡£¡£¡£¡£¡£¡£¡£


½â¾öÕâЩ·ì϶¼«¾ßÌôÕ½ÐÔ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚËüÃÇÉî¿Ìµ½ÏÖ´úCPUµÄ½á¹¹ºÍ²Ù×÷ÖУ¬£¬£¬£¬ £¬Òò¶øÆëÈ«½â³ý·ìÏ¶Éæ¼°¸ü»»Ó²¼þ»ò½ûÓÿɴó´óÌá¸ß»úÄܵÄÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£Í¬Ñù£¬£¬£¬£¬ £¬´´½¨»º½â»úÔ켫¶È¸´ÔÓ£¬£¬£¬£¬ £¬²¢ÇÒ¿ÉÄܹÊÕÏͨ¹ý´§Ä¦Ö´ÐÐÖ°ÄÜʵÏֵĻúÄÜÌáÉý¡£¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬ £¬ÆëÈ«½â³ýÕë¶ÔÓ¢ÌØ¶ûCPUµÄ´§Ä¦Ö´ÐÐÖ°ÄܵÄÅÔ·¹¥»÷µÄ¿ÉÄÜÐÔ½«±ØÒªÆëÈ«½ûÓó¬Ị̈߳¬£¬£¬£¬ £¬Õ⽫ÑϳÁ½µµÍ»úÄÜ¡£¡£¡£¡£¡£¡£¡£¡£


ÕâÀà·ì϶µÄ»º½â´ëÊ©ÄÑÒÔÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£ËüÃÇͨ³£·ÖΪÈýÀࣺӲ¼þ½¨¸´£¬£¬£¬£¬ £¬Èí¼þ»º½â»ò΢´úÂ뻺½â¡£¡£¡£¡£¡£¡£¡£¡£ËùÓÐÏÈǰ¶³öµÄ²àͨ·¹¥»÷¶¼Í¨¹ýÈýÖÖ²½ÖèÖеÄÖÁÉÙÒ»ÖÖÀ´¼õÇá¡£¡£¡£¡£¡£¡£¡£¡£


Bitdefender×êÑÐÈËÔ±ÃèÊöÁËSWAPGS¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ÕâÖÖ¹¥»÷ÊÇÒ»ÖÖ´ÓÄÚºËй©Ãô¸ÐÐÅÏ¢µÄв½Ö裬£¬£¬£¬ £¬ÓÉÓÚËüÈÆ¹ýÁËËùÓÐÒÑÖªµÄ²àÐÅ·¹¥»÷»º½â¼¼Êõ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊÇͨ¹ýÀÄÓÃSWAPGSÖ¸ÁîÄܹ»´§Ä¦ÐÔµØÖ´ÐеÄÊÂÊ·´ÊµÏֵġ£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Ç¿ÔìÄÚºËÖеÄËÁÒâÄÚ´æ½â³ýÒýÓ㬣¬£¬£¬ £¬Õâ»áÔÚÊý¾Ý»º´æÖÐÁôϺۼ£¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Ê°È¡ÕâЩÐźţ¬£¬£¬£¬ £¬ÒÔ´§¶ÈλÓÚ¸ø¶¨Äں˵ØÖ·µÄÖµ¡£¡£¡£¡£¡£¡£¡£¡£


BitdefenderÒѾ­ÑÝʾÁËHypervisor IntrospectionÈôºÎͨ¹ýɾ³ýÔÚ佨²¹µÄWindowsϵͳÉϳɹ¦ËùÐèµÄǰÌáÀ´×èÖ¹¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ÕâÖÖ»º½â´ëʩûÓÐÒýÆðÏÔÖøµÄ»úÄܽµÂä¡£¡£¡£¡£¡£¡£¡£¡£¹ÌȻǿÁÒ½¨Òé´ÓMicrosoft²¿Êð²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬ £¬µ«Hypervisor IntrospectionÄܹ»ÌṩÓÐЧµÄÅâ³¥½ÚÔ죬£¬£¬£¬ £¬Ö±µ½Äܹ»½¨²¹ÏµÍ³¡£¡£¡£¡£¡£¡£¡£¡£DEMOÑÝʾ£ºhttp://www.bitdefender.com/SWAPGSAttack¡£¡£¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


΢Èí¡¢ºìñÒÔ¼°Ó¢ÌضûºÍ¹È¸èµÈ¹©¸øÉÌÒѾ­°ä²¼ÁËÓйؽ¨¸´²¹¶¡ºÍ½¨Ò飬£¬£¬£¬ £¬AMDÔò³ÆËûÃǵIJúÆ·²»ÊÜÓ°Ï죺


΢Èí£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1125


Redhat£ºhttps://access.redhat.com/articles/4329821


Ó¢ÌØ¶û£ºhttps://software.intel.com/security-software-guidance/insights/more-information-swapgs-and-speculative-only-segment-loads


¹È¸è£º


https://chromium.googlesource.com/chromiumos/third_party/kernel/+/cc4c818b2219c58af5f0ca59f3e9f02c48bc0b65/Documentation/admin-guide/hw-vuln/spectre.rst


https://android-review.googlesource.com/c/kernel/common/+/1097435


Linux kernel£ºhttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?

id=18ec54fdd6d18d92025af097cd042a75cf0ea24c


²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/swapgs-vulnerability-in-modern-cpus-fixed-in-windows-linux-chromeos/