CVE-2019-11157 | Intel CPU Plundervolt¹¥»÷

°ä²¼¹¦·ò 2019-12-12


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


1.²¼¾°ÃèÊö


½üÈÕ £¬Å·ÖÞÈýËù´óѧµÄѧÕßÅû¶ÁËÒ»¸öÓ°ÏìIntel SGX´æ´¢Êý¾ÝÆëÈ«ÐÔµÄPlundervolt·ì϶£¨CVE-2019-11157£© £¬¸Ã·ì϶¿ÉÓÃÓÚ¸´Ô­¼ÓÃÜÃÜÔ¿»òÔÚÒÔǰ°²È«µÄÈí¼þÖÐÒýÈëÃýÎó¡£Intel̨ʽ»ú¡¢·þÎñÆ÷ºÍÒÆ¶¯CPU¾ùÊÜÓ°Ïì¡£


2.·ì϶Áбí


CVE    ID£º    CVE-2019-11157

·ì϶µÈ¼¶£º    ¸ßΣ

CVSSÆÀ·Ö£º    7.9

CVSSVector:  CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

·ì϶·ÖÀࣺ    ÌØÈ¨Éý¼¶¡¢ÐÅϢй¶

Ó°ÏìÁìÓò£º    Intel?µÚ6¡¢7¡¢8¡¢9ºÍ10´úCoreTM´¦ÖÃÆ÷

                    Intel?ÖÁÇ¿?´¦ÖÃÆ÷E3 v5ºÍv6

                    Intel?ÖÁÇ¿?´¦ÖÃÆ÷E-2100ºÍE-2200¼Ò×å


3.·ì϶ÏêÇé


ijЩIntel£¨R£©´¦ÖÃÆ÷ÖеĵçѹÉèÖôæÔÚ²»ÕýÈ·µÄǰÌá²é³­ÎÊÌâ £¬¿ÉÄÜ»áÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÓû§Í¨¹ý±¾µØ½Ó¼û½øÐÐÌØÈ¨Éý¼¶»òÐÅϢй¶¡£

Plundervolt¹¥»÷רÃÅÕë¶ÔIntel SGXÓ²¼þ°²È«Ö°ÄÜ £¬SGXΪÀûÓ÷¨Ê½Ìṩһ¸ö¿ÉÐŵÄÖ´Ðл·¾³¡£SGX¸ôÀëÇøÔÚÖ÷Intel CPUÄÚ´æµÄÒ»Óײ¿ÃÅÉÏÔËÐÐ £¬ÔÚÓ²¼þ¼¶±ð£¨SGXÄÚ´æÓëÆäÓàCPUÄÚ´æ·Ö¸ô£©ºÍÈí¼þ¼¶±ð£¨SGXÊý¾ÝÒѼÓÃÜ£©¾ù½øÐиôÀë¡£


Plundervolt¹¥»÷½áºÏÁËÁ½ÖÖ¹¥»÷¼¼Êõ £¬Ô̺¬Rowhammer¹¥»÷ºÍCLKSCREW¹¥»÷¡£PlundervoltÀûÓÃCPUµÄµçÔ´ÖÎÀí½Ó¿ÚÀ´¸ü¸ÄSGX´æ´¢µ¥ÔªÄÚ²¿µÄµçѹºÍƵÂÊ £¬´Ó¶øµ¼ÖÂSGXÊý¾ÝµÄ²»ÓÃÒª¸ü¸Ä¡£ÕâЩ¸ü¸Ä²»»á·ÛËéSGXµÄ±£ÃÜÐÔ £¬µ«»áÔÚSGX²Ù×÷¼°Æä´¦ÖõÄÊý¾ÝÖÐÒýÈëÃýÎó £¬¼´Plundervolt²»»á·ÛËéSGX £¬¶øÖ»»á·ÛËéÆäÊä³ö¡£ÀýÈç £¬Plundervolt¿ÉÓÃÓÚÔÚSGXÄÚ²¿Ö´ÐеļÓÃÜËã·¨/²Ù×÷ÖÐÒý·¢ÃýÎó £¬´Ó¶øÊ¹¼ÓÃÜÄÚÈÝÒ»µ©ÍÑÀëSGX¾ÍºÜÈÝÒ×±»ÆÆ½â £¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»¸´Ô­ÓÃÓÚ¼ÓÃÜÆäÖÐÊý¾ÝµÄ¼ÓÃÜÃÜÔ¿¡£


Plundervolt²»Äܱ»Ô¶³ÌÀûÓà £¬²¢ÇÒ±ØÒªroot»òadminÌØÈ¨´ÓÖ¸±êÖ÷»úÉÏÔËÐз¨Ê½¡£´Ë±í £¬PlundervoltÎÞ·¨ÔÚÐé¹¹»¯»·¾³£¨ÀýÈçÐé¹¹»úºÍÔÆÍÆËã·þÎñ£©ÖÐÔËÐС£


4.½¨¸´½¨Òé


IntelÔÚ°²È«´«µÝINTEL-SA-00289Öа䲼ÁËÓйØÎ¢´úÂëºÍBIOS¸üС£ÕâЩ¸üÐÂΪÖÎÀíÔ±ÌṩÁËÒ»¸öеÄBIOSÑ¡Ïî £¬Äܹ»ÔÚËûÃDz»Ê¹ÓÃϵͳ»òÒÔΪPlundervolt£¨CVE-2019-11157£©×é³ÉÕæÕý·çÏÕµÄÇé¿öϽûÓÃϵͳÉϵĵçѹºÍƵÂʽÚÔì½çÃæ¡£


5.²Î¿¼Á´½Ó


https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00289.html

https://plundervolt.com/

https://github.com/KitMurdock/plundervolt

https://www.zdnet.com/article/new-plundervolt-attack-impacts-intel-cpus/