CVE-2019-11157 | Intel CPU Plundervolt¹¥»÷

Ðû²¼Ê±¼ä 2019-12-12


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


1.Åä¾°ÐÎò


¿ËÈÕ£¬£¬ £¬£¬£¬£¬Å·ÖÞÈýËù´óѧµÄѧÕßÅû¶ÁËÒ»¸öÓ°ÏìIntel SGX´æ´¢Êý¾ÝÍêÕûÐÔµÄPlundervoltÎó²î£¨CVE-2019-11157£©£¬£¬ £¬£¬£¬£¬¸ÃÎó²î¿ÉÓÃÓÚ»Ö¸´¼ÓÃÜÃÜÔ¿»òÔÚÒÔǰÇå¾²µÄÈí¼þÖÐÒýÈë¹ýʧ ¡£¡£Intel̨ʽ»ú¡¢Ð§ÀÍÆ÷ºÍÒÆ¶¯CPU¾ùÊÜÓ°Ïì ¡£¡£


2.Îó²îÁбí


CVE    ID£º    CVE-2019-11157

Îó²îÆ·¼¶£º    ¸ßΣ

CVSSÆÀ·Ö£º    7.9

CVSSVector:  CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Îó²î·ÖÀࣺ    ÌØÈ¨Éý¼¶¡¢ÐÅϢй¶

Ó°Ïì¹æÄ££º    Intel?µÚ6¡¢7¡¢8¡¢9ºÍ10´úCoreTM´¦Öóͷ£Æ÷

                    Intel?ÖÁÇ¿?´¦Öóͷ£Æ÷E3 v5ºÍv6

                    Intel?ÖÁÇ¿?´¦Öóͷ£Æ÷E-2100ºÍE-2200¼Ò×å


3.Îó²îÏêÇé


ijЩIntel£¨R£©´¦Öóͷ£Æ÷ÖеĵçѹÉèÖñ£´æ²»×¼È·µÄÌõ¼þ¼ìÅÌÎÊÌ⣬£¬ £¬£¬£¬£¬¿ÉÄÜ»áÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§Í¨¹ýÍâµØ»á¼û¾ÙÐÐÌØÈ¨Éý¼¶»òÐÅϢй¶ ¡£¡£

Plundervolt¹¥»÷רÃÅÕë¶ÔIntel SGXÓ²¼þÇå¾²¹¦Ð§£¬£¬ £¬£¬£¬£¬SGXΪӦÓóÌÐòÌṩһ¸ö¿ÉÐŵÄÖ´ÐÐÇéÐÎ ¡£¡£SGX¸ôÀëÇøÔÚÖ÷Intel CPUÄÚ´æµÄһС²¿·ÖÉÏÔËÐУ¬£¬ £¬£¬£¬£¬ÔÚÓ²¼þ¼¶±ð£¨SGXÄÚ´æÓëÆäÓàCPUÄÚ´æÍÑÀ룩ºÍÈí¼þ¼¶±ð£¨SGXÊý¾ÝÒѼÓÃÜ£©¾ù¾ÙÐиôÀë ¡£¡£


Plundervolt¹¥»÷Á¬ÏµÁËÁ½ÖÖ¹¥»÷ÊÖÒÕ£¬£¬ £¬£¬£¬£¬°üÀ¨Rowhammer¹¥»÷ºÍCLKSCREW¹¥»÷ ¡£¡£PlundervoltʹÓÃCPUµÄµçÔ´ÖÎÀí½Ó¿ÚÀ´¸ü¸ÄSGX´æ´¢µ¥Î»ÄÚ²¿µÄµçѹºÍƵÂÊ£¬£¬ £¬£¬£¬£¬´Ó¶øµ¼ÖÂSGXÊý¾ÝµÄ²»ÐëÒª¸ü¸Ä ¡£¡£ÕâЩ¸ü¸Ä²»»áÆÆËðSGXµÄ±£ÃÜÐÔ£¬£¬ £¬£¬£¬£¬µ«»áÔÚSGX²Ù×÷¼°Æä´¦Öóͷ£µÄÊý¾ÝÖÐÒýÈë¹ýʧ£¬£¬ £¬£¬£¬£¬¼´Plundervolt²»»áÆÆËðSGX£¬£¬ £¬£¬£¬£¬¶øÖ»»áÆÆËðÆäÊä³ö ¡£¡£ÀýÈ磬£¬ £¬£¬£¬£¬Plundervolt¿ÉÓÃÓÚÔÚSGXÄÚ²¿Ö´ÐеļÓÃÜËã·¨/²Ù×÷ÖÐÒý·¢¹ýʧ£¬£¬ £¬£¬£¬£¬´Ó¶øÊ¹¼ÓÃÜÄÚÈÝÒ»µ©ÍÑÀëSGX¾ÍºÜÈÝÒ×±»ÆÆ½â£¬£¬ £¬£¬£¬£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÒÔ»Ö¸´ÓÃÓÚ¼ÓÃÜÆäÖÐÊý¾ÝµÄ¼ÓÃÜÃÜÔ¿ ¡£¡£


Plundervolt²»¿É±»Ô¶³ÌʹÓ㬣¬ £¬£¬£¬£¬²¢ÇÒÐèÒªroot»òadminÌØÈ¨´ÓÄ¿µÄÖ÷»úÉÏÔËÐгÌÐò ¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬PlundervoltÎÞ·¨ÔÚÐéÄ⻯ÇéÐΣ¨ÀýÈçÐéÄâ»úºÍÔÆÅÌËãЧÀÍ£©ÖÐÔËÐÐ ¡£¡£


4.ÐÞ¸´½¨Òé


IntelÔÚÇ徲ת´ïINTEL-SA-00289ÖÐÐû²¼ÁËÏà¹ØÎ¢´úÂëºÍBIOS¸üР¡£¡£ÕâЩ¸üÐÂΪÖÎÀíÔ±ÌṩÁËÒ»¸öеÄBIOSÑ¡Ï£¬ £¬£¬£¬£¬¿ÉÒÔÔÚËûÃDz»Ê¹ÓÃϵͳ»òÒÔΪPlundervolt£¨CVE-2019-11157£©×é³ÉÕæÕýΣº¦µÄÇéÐÎϽûÓÃϵͳÉϵĵçѹºÍƵÂÊ¿ØÖƽçÃæ ¡£¡£


5.²Î¿¼Á´½Ó


https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00289.html

https://plundervolt.com/

https://github.com/KitMurdock/plundervolt

https://www.zdnet.com/article/new-plundervolt-attack-impacts-intel-cpus/