Intel CPU΢¼Ü¹¹Êý¾Ý²ÉÑù(MDS)·ì϶
°ä²¼¹¦·ò 2019-05-15
²¼¾°ÃèÊö
·ì϶Áбí
·ì϶µÈ¼¶£º ÖÐΣ
·ìϼûû³Æ£º ΢¼Ü¹¹´æ´¢»º³åÇøÊý¾Ý²ÉÑù£¨MSBDS£©£¬Ò²±»³ÆÎªFallout¹¥»÷
CVSSÆÀ·Ö£º 6.5
CVE ID £º CVE-2018-12127
·ì϶µÈ¼¶£º ÖÐΣ
·ìϼûû³Æ£º ΢¼Ü¹¹¸ºÔض˿ÚÊý¾Ý²ÉÑù£¨MLPDS£©£¬Ò²±»³ÆÎªZombieload»òRIDL¹¥»÷
CVSSÆÀ·Ö£º 6.5
CVE ID £º CVE-2018-12130
·ì϶µÈ¼¶£º ÖÐΣ
·ìϼûû³Æ£º ΢¼Ü¹¹Ìî³ä»º³åÇøÊý¾Ý²ÉÑù£¨MFBDS£©£¬RIDLÀ๥»÷
CVSSÆÀ·Ö£º 6.5
CVE ID £º CVE-2019-11091
·ì϶µÈ¼¶£º µÍΣ
·ìϼûû³Æ£º ΢¼Ü¹¹²»³É»º´æÄÚ´æÊý¾Ý²ÉÑù£¨MDSUM£©£¬RIDLÀ๥»÷
CVSSÆÀ·Ö£º 3.8
·ì϶ÏêÇé
ͨ¹ýÀûÓÃIntel CPU΢¼Ü¹¹ÖеĴ§Ä¦Ö´ÐвÙ×÷£¬MDS¹¥»÷¿ÉÔÊÐí¹¥»÷Õß½Ó¼ûÆäËü·¨Ê½ÔÚCPUÖд¦ÖõÄÊý¾Ý¡£×Ô2011ÄêÒÔÀ´µÄIntel CPUÏÕЩ¶¼ÊÜÓ°Ï죬Ô̺¬Ì¨Ê½»ú¡¢±Ê¼Ç±¾¼°·þÎñÆ÷µÄ´¦ÖÃÆ÷¡£Intel°µÊ¾Æä×îвúÆ·¿É´ÓÓ²¼þ²ãÃæ½â¾öÕâЩÎÊÌ⣬Ô̺¬µÚ8´úºÍµÚ9´úCore´¦ÖÃÆ÷¼°µÚ¶þ´úXeon Scalable´¦ÖÃÆ÷¡£¶ÔÓÚÆäËûÊÜÓ°ÏìµÄ²úÆ·£¬¿Éͨ¹ý΢´úÂë¸üлñµÃ»º½â¡£
Ó¢ÌØ¶û»¹°µÊ¾¶Ô´óÎÞÊýPC¶øÑÔ£¬»º½â´ëÊ©¶Ô»úÄÜÓ°Ïì²»´ó£¬µ«¶ÔÊý¾ÝÖÐÐĸºÔضøÑÔ£¬»úÄÜ¿ÉÄÜ´æ±ÉÈ˽µ¡£
ARMºÍAMD´¦ÖÃÆ÷ËÆºõûÓÐÊܵ½Ó°Ïì¡£
ÊÜÓ°Ïì²úÆ·µÄÆëÈ«Áбí¿É²Î¿¼ÒÔÏÂÎļþ£º
https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf
½¨¸´½¨Òé
MicrosoftÒѰ䲼²Ù×÷ϵͳ¼¶¸üУ¬ÒÔ½â¾öËĸöMDS·ì϶¡£Æ¾¾ÝMicrosoftµÄMDS°²È«½¨Ò飬²Ù×÷ϵͳ¸üпÉÓÃÓÚWindowsºÍWindows Server£¬Ò²¿ÉÓÃÓÚSQL ServerÊý¾Ý¿â¡£Azure¿Í»§¶ËÒÑÊܵ½±£»¤£¬ÓÉÓÚMicrosoftÒѲÉÈ¡´ëÊ©½¨²¹ÆäÔÆ»ù´¡¼Ü¹¹²¢¼õÇáÍþв¡£
Apple
Æ»¹û½ñÌì°ä²¼µÄmacOS Mojave 10.14.5ÒѾ²¿ÊðÁ˶ÔMDS¹¥»÷µÄ»º½â´ëÊ©¡£iOSÉ豸²»Ò×Êܵ½MDS¹¥»÷£¬Òò¶øÄ¿Ç°²»±ØÒªÌØÊâµÄ»º½â´ëÊ©¡£
Linux
Ë鯬»¯µÄLINUXÉú̬ϵͳ°ä²¼²¹¶¡µÄ¿ìÂÊ»ºÂý¡£ÔÚ׫д±¾ÎÄʱ£¬Ö»ÓÐRed HatºÍUbuntu°ä²¼Á˽¨¸´²¹¶¡¡£
¹È¸è½ñÌì°ä²¼ÁËÒ»¸öÔ®ÊÖÒ³Ãæ£¬ÁгöÁËÿÖÖ²úÆ·µÄ״̬ÒÔ¼°ËüÈôºÎÊܵ½DS¹¥»÷µÄÓ°Ï졣ƾ¾Ý´ËÒ³Ãæ£¬¹È¸èµÄÔÆ»ù´¡¼Ü¹¹ÒѾ»ñµÃÁËÊʵ±µÄ±£»¤¡£Ä³Ð©Google Cloud Platform¿Í»§¿ÉÄܱØÒª²é¿´Ä³Ð©ÉèÖ㬵«G SuiteºÍGoogle Apps¿Í»§ÎÞÐèÖ´ÐÐÈκβÙ×÷¡£Chrome²Ù×÷ϵͳÒÑÍ£ÓÃChrome OS 74¼°ºóÐø°æ±¾µÄ³¬Ïß³ÌÖ°ÄÜ¡£¹È¸è°µÊ¾£¬ÕâÄܹ»Ô¤·ÀMDS¹¥»÷¡£AndroidÓû§²»ÊÜÓ°Ïì¡£¹È¸è°µÊ¾£¬²Ù×÷ϵͳ¼¶´ËÍ⻺½â´ëʩӦÄܱ£»¤Chromeä¯ÀÀÆ÷Óû§¡£
Amazon
ÀàËÆÓڹȸèºÍ΢Èí£¬ÑÇÂíÑ·°µÊ¾ÒѾÔÚÔÆ·þÎñÆ÷ÉϽ¨²¹²¢ÀûÓûº½â´ëÊ©¡£
²Î¿¼Á´½Ó
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00233.html
https://www.zdnet.com/article/intel-cpus-impacted-by-new-zombieload-side-channel-attack/


¾©¹«Íø°²±¸11010802024551ºÅ