CVE-2019-11157 | Intel CPU Plundervolt¹¥»÷

Ðû²¼Ê±¼ä 2019-12-12


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


1.Åä¾°ÐÎò


¿ËÈÕ£¬£¬£¬£¬ £¬£¬£¬Å·ÖÞÈýËù´óѧµÄѧÕßÅû¶ÁËÒ»¸öÓ°ÏìIntel SGX´æ´¢Êý¾ÝÍêÕûÐÔµÄPlundervoltÎó²î£¨CVE-2019-11157£©£¬£¬£¬£¬ £¬£¬£¬¸ÃÎó²î¿ÉÓÃÓÚ»Ö¸´¼ÓÃÜÃÜÔ¿»òÔÚÒÔǰÇå¾²µÄÈí¼þÖÐÒýÈë¹ýʧ¡£¡£ ¡£¡£¡£¡£¡£Intel̨ʽ»ú¡¢Ð§ÀÍÆ÷ºÍÒÆ¶¯CPU¾ùÊÜÓ°Ïì¡£¡£ ¡£¡£¡£¡£¡£


2.Îó²îÁбí


CVE    ID£º    CVE-2019-11157

Îó²îÆ·¼¶£º    ¸ßΣ

CVSSÆÀ·Ö£º    7.9

CVSSVector:  CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Îó²î·ÖÀࣺ    ÌØÈ¨Éý¼¶¡¢ÐÅϢй¶

Ó°Ïì¹æÄ££º    Intel?µÚ6¡¢7¡¢8¡¢9ºÍ10´úCoreTM´¦Öóͷ£Æ÷

                    Intel?ÖÁÇ¿?´¦Öóͷ£Æ÷E3 v5ºÍv6

                    Intel?ÖÁÇ¿?´¦Öóͷ£Æ÷E-2100ºÍE-2200¼Ò×å


3.Îó²îÏêÇé


ijЩIntel£¨R£©´¦Öóͷ£Æ÷ÖеĵçѹÉèÖñ£´æ²»×¼È·µÄÌõ¼þ¼ìÅÌÎÊÌ⣬£¬£¬£¬ £¬£¬£¬¿ÉÄÜ»áÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§Í¨¹ýÍâµØ»á¼û¾ÙÐÐÌØÈ¨Éý¼¶»òÐÅϢй¶¡£¡£ ¡£¡£¡£¡£¡£

Plundervolt¹¥»÷רÃÅÕë¶ÔIntel SGXÓ²¼þÇå¾²¹¦Ð§£¬£¬£¬£¬ £¬£¬£¬SGXΪӦÓóÌÐòÌṩһ¸ö¿ÉÐŵÄÖ´ÐÐÇéÐΡ£¡£ ¡£¡£¡£¡£¡£SGX¸ôÀëÇøÔÚÖ÷Intel CPUÄÚ´æµÄһС²¿·ÖÉÏÔËÐУ¬£¬£¬£¬ £¬£¬£¬ÔÚÓ²¼þ¼¶±ð£¨SGXÄÚ´æÓëÆäÓàCPUÄÚ´æÍÑÀ룩ºÍÈí¼þ¼¶±ð£¨SGXÊý¾ÝÒѼÓÃÜ£©¾ù¾ÙÐиôÀë¡£¡£ ¡£¡£¡£¡£¡£


Plundervolt¹¥»÷Á¬ÏµÁËÁ½ÖÖ¹¥»÷ÊÖÒÕ£¬£¬£¬£¬ £¬£¬£¬°üÀ¨Rowhammer¹¥»÷ºÍCLKSCREW¹¥»÷¡£¡£ ¡£¡£¡£¡£¡£PlundervoltʹÓÃCPUµÄµçÔ´ÖÎÀí½Ó¿ÚÀ´¸ü¸ÄSGX´æ´¢µ¥Î»ÄÚ²¿µÄµçѹºÍƵÂÊ£¬£¬£¬£¬ £¬£¬£¬´Ó¶øµ¼ÖÂSGXÊý¾ÝµÄ²»ÐëÒª¸ü¸Ä¡£¡£ ¡£¡£¡£¡£¡£ÕâЩ¸ü¸Ä²»»áÆÆËðSGXµÄ±£ÃÜÐÔ£¬£¬£¬£¬ £¬£¬£¬µ«»áÔÚSGX²Ù×÷¼°Æä´¦Öóͷ£µÄÊý¾ÝÖÐÒýÈë¹ýʧ£¬£¬£¬£¬ £¬£¬£¬¼´Plundervolt²»»áÆÆËðSGX£¬£¬£¬£¬ £¬£¬£¬¶øÖ»»áÆÆËðÆäÊä³ö¡£¡£ ¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬ £¬£¬£¬Plundervolt¿ÉÓÃÓÚÔÚSGXÄÚ²¿Ö´ÐеļÓÃÜËã·¨/²Ù×÷ÖÐÒý·¢¹ýʧ£¬£¬£¬£¬ £¬£¬£¬´Ó¶øÊ¹¼ÓÃÜÄÚÈÝÒ»µ©ÍÑÀëSGX¾ÍºÜÈÝÒ×±»ÆÆ½â£¬£¬£¬£¬ £¬£¬£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÒÔ»Ö¸´ÓÃÓÚ¼ÓÃÜÆäÖÐÊý¾ÝµÄ¼ÓÃÜÃÜÔ¿¡£¡£ ¡£¡£¡£¡£¡£


Plundervolt²»¿É±»Ô¶³ÌʹÓ㬣¬£¬£¬ £¬£¬£¬²¢ÇÒÐèÒªroot»òadminÌØÈ¨´ÓÄ¿µÄÖ÷»úÉÏÔËÐгÌÐò¡£¡£ ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬£¬PlundervoltÎÞ·¨ÔÚÐéÄ⻯ÇéÐΣ¨ÀýÈçÐéÄâ»úºÍÔÆÅÌËãЧÀÍ£©ÖÐÔËÐС£¡£ ¡£¡£¡£¡£¡£


4.ÐÞ¸´½¨Òé


IntelÔÚÇ徲ת´ïINTEL-SA-00289ÖÐÐû²¼ÁËÏà¹ØÎ¢´úÂëºÍBIOS¸üС£¡£ ¡£¡£¡£¡£¡£ÕâЩ¸üÐÂΪÖÎÀíÔ±ÌṩÁËÒ»¸öеÄBIOSÑ¡Ï£¬£¬£¬ £¬£¬£¬¿ÉÒÔÔÚËûÃDz»Ê¹ÓÃϵͳ»òÒÔΪPlundervolt£¨CVE-2019-11157£©×é³ÉÕæÕýΣº¦µÄÇéÐÎϽûÓÃϵͳÉϵĵçѹºÍƵÂÊ¿ØÖƽçÃæ¡£¡£ ¡£¡£¡£¡£¡£


5.²Î¿¼Á´½Ó


https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00289.html

https://plundervolt.com/

https://github.com/KitMurdock/plundervolt

https://www.zdnet.com/article/new-plundervolt-attack-impacts-intel-cpus/