Ó¢ÌØ¶û¿áî£ CPU·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-06-15·ì϶±àºÅ
CVE-2018-3665
·ì϶¼¶±ð
¸ß
CVSS·ÖÖµ
³§ÉÌ×ÔÆÀ£º4.3 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
¸Ã·ì϶ӰÏìËùÓÐÓ¢ÌØ¶û¿áî£Î¢´¦ÖÃÆ÷£¬Ëü´æÔÚÓÚÏÖʵ CPU ÖУ¬Òò¶øÎÞÂÛÓû§Ê¹ÓõÄÊÇÄÄÖÖ²Ù×÷ϵͳÈç Windows¡¢Linux¡¢BSDµÈ£¬Ö»ÓÐÔËÐлùÓÚÓ¢ÌØ¶û¿áî£µÄ CPU ÇÒʹÓá°Lazy FPU ¸ßµÍÎÄÇл»¡±Ö°Äܼ´ÊÜÓ°Ïì¡£
·ìϼûèÊö
2018Äê6ÔÂ14ÈÕ£¬Intel ¹Ù·½Åû¶´¦ÖÃÆ÷Öи¡µã¼Ä·ÅÆ÷×´Ì¬ÍÆ³Ù±£ÁôµÄ¸öÐÔ´æÔÚ·ì϶£¬ÀûÓô˷ì϶£¬½áºÏ´§Ä¦Ö´ÐкͲàÐÅ·¹¥»÷Äܹ»Ð¹Â¶ÁíÒ»¸ö¹ý³ÌµÄ¸¡µã¼Ä·ÅÆ÷״̬£¬¿ÉÄÜÔì³ÉÃô¸ÐÐÅϢй¶¡£
ÏÖ´ú´¦ÖÃÆ÷ÔÚ¹ý³ÌÇл»Ê±Äܹ»Ñ¡ÔñÍÆ³Ù±£ÁôºÍ¸´ÔijЩCPU µÄ¸ßµÍÎÄ״̬À´Ìá¸ßϵͳ»úÄÜ¡£
ÆäÖÐFPU Ϊ¸¡µãµ¥Ôª£¬¿ÉÓÃÓڸ߾«¶È¸¡µãÔËË㣬ÓÉÓÚ²»ÊÇËùÓеÄÀûÓ÷¨Ê½¶¼Ê¹ÓÃFPU£¬ËùÒÔÀûÓÃÍÆ³Ù±£Áô/¸´ÔµÄ¸öÐÔ£¬ÈôÊÇе÷¶ÈµÄ¹ý³Ì²»Ê¹ÓÃFP Ö¸ÁÔò²»±ØÒªÇл»FPU ¸ßµÍÎÄ״̬£¬ÒÔ´ËÀ´Ï÷¼õÖ´ÐÐÖÜÆÚ£¬Ìá¸ß»úÄÜ¡£µ±Ð¹ý³ÌʹÓÃFP Ö¸Áîʱ£¬»á´¥·¢¡°É豸²»³ÉÓã¨DNA£©¡±Òì³££¬Í¨¹ýÒì³£´¦ÖÃÀ´Çл»FPU ¸ßµÍÎÄ״̬¡£
ÀûÓøøöÐÔ£¬Äܹ»Í¨¹ý´§Ä¦Ö´ÐкͲàÐÅ·¹¥»÷ÔÚ´¥·¢DNA Ò쳣ǰ¶Áȡ֮ǰ¹ý³ÌµÄ¸¡µã¡£
ͬÑùÓµÓиøöÐԵϹÓÐSSE£¬AVX£¬MMX£¬²¢ÇÒAESµÄ¼ÓÃÜÃÜԿͨ³£»á´æ·ÅÔÚSSE¼Ä·ÅÆ÷ÖУ¬Õâ¿ÉÄÜʹ¹¥»÷Õß¿ÉÄÜÇÔÈ¡¸ü¶àÓÐЧÐÅÏ¢¡£
½â¾ö´ëÊ©
Õë¶ÔLinux£¬ÏµÍ³¿ª·¢ÈËÔ±Äܹ»Í¨¹ýeagerfpu=on ²ÎÊýÀ´Æô¶¯Äںˣ¬Ê¹ÓÃEager FP¸´ÔģʽÀ´°ü°ìLazy FP¸´Ôģʽ£¬Eager FP¸´ÔģʽÏ£¬ÎÞÂÛµ±Ç°¹ý³ÌÊÇ·ñʹÓÃFPU£¬³ÇÊб£Áô²¢¸´ÔFPU ¸ßµÍÎÄ״̬¡£
Õë¶ÔWindows£¬Ä¿Ç°Lazy restore ÔÚWindows ÉÏĬÈÏ¿ªÆô£¬ÇÒÎÞ·¨±»½ûÓ㬱ØÒªÎ¢Èí¹Ù·½Ìṩ×îв¹¶¡½¨¸´¡£
²Î¿¼×ÊÁÏ
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00145.html
https://access.redhat.com/solutions/3485131
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180016
https://www.bleepingcomputer.com/news/security/new-lazy-fp-state-restore-vulnerability-affects-all-intel-core-cpus/


¾©¹«Íø°²±¸11010802024551ºÅ