Ó¢ÌØ¶û¿áî£ CPU·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-06-15

·ì϶±àºÅ


CVE-2018-3665


·ì϶¼¶±ð


¸ß


CVSS·ÖÖµ


³§ÉÌ×ÔÆÀ£º4.3   CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


¸Ã·ì϶ӰÏìËùÓÐÓ¢ÌØ¶û¿áî£Î¢´¦ÖÃÆ÷ £¬Ëü´æÔÚÓÚÏÖʵ CPU ÖÐ £¬Òò¶øÎÞÂÛÓû§Ê¹ÓõÄÊÇÄÄÖÖ²Ù×÷ϵͳÈç Windows¡¢Linux¡¢BSDµÈ £¬Ö»ÓÐÔËÐлùÓÚÓ¢ÌØ¶û¿áĠCPU ÇÒʹÓá°Lazy FPU ¸ßµÍÎÄÇл»¡±Ö°Äܼ´ÊÜÓ°Ïì¡£


·ìϼûèÊö


2018Äê6ÔÂ14ÈÕ £¬Intel ¹Ù·½Åû¶´¦ÖÃÆ÷Öи¡µã¼Ä·ÅÆ÷×´Ì¬ÍÆ³Ù±£ÁôµÄ¸öÐÔ´æÔÚ·ì϶ £¬ÀûÓô˷ì϶ £¬½áºÏ´§Ä¦Ö´ÐкͲàÐÅ·¹¥»÷Äܹ»Ð¹Â¶ÁíÒ»¸ö¹ý³ÌµÄ¸¡µã¼Ä·ÅÆ÷״̬ £¬¿ÉÄÜÔì³ÉÃô¸ÐÐÅϢй¶¡£


ÏÖ´ú´¦ÖÃÆ÷ÔÚ¹ý³ÌÇл»Ê±Äܹ»Ñ¡ÔñÍÆ³Ù±£ÁôºÍ¸´Ô­Ä³Ð©CPU µÄ¸ßµÍÎÄ״̬À´Ìá¸ßϵͳ»úÄÜ¡£


ÆäÖÐFPU Ϊ¸¡µãµ¥Ôª £¬¿ÉÓÃÓڸ߾«¶È¸¡µãÔËËã £¬ÓÉÓÚ²»ÊÇËùÓеÄÀûÓ÷¨Ê½¶¼Ê¹ÓÃFPU £¬ËùÒÔÀûÓÃÍÆ³Ù±£Áô/¸´Ô­µÄ¸öÐÔ £¬ÈôÊÇе÷¶ÈµÄ¹ý³Ì²»Ê¹ÓÃFP Ö¸Áî £¬Ôò²»±ØÒªÇл»FPU ¸ßµÍÎÄ״̬ £¬ÒÔ´ËÀ´Ï÷¼õÖ´ÐÐÖÜÆÚ £¬Ìá¸ß»úÄÜ¡£µ±Ð¹ý³ÌʹÓÃFP Ö¸Áîʱ £¬»á´¥·¢¡°É豸²»³ÉÓã¨DNA£©¡±Òì³£ £¬Í¨¹ýÒì³£´¦ÖÃÀ´Çл»FPU ¸ßµÍÎÄ״̬¡£


ÀûÓøøöÐÔ £¬Äܹ»Í¨¹ý´§Ä¦Ö´ÐкͲàÐÅ·¹¥»÷ÔÚ´¥·¢DNA Ò쳣ǰ¶Áȡ֮ǰ¹ý³ÌµÄ¸¡µã¡£


ͬÑùÓµÓиøöÐԵϹÓÐSSE £¬AVX £¬MMX £¬²¢ÇÒAESµÄ¼ÓÃÜÃÜԿͨ³£»á´æ·ÅÔÚSSE¼Ä·ÅÆ÷ÖÐ £¬Õâ¿ÉÄÜʹ¹¥»÷Õß¿ÉÄÜÇÔÈ¡¸ü¶àÓÐЧÐÅÏ¢¡£


½â¾ö´ëÊ©


Õë¶ÔLinux £¬ÏµÍ³¿ª·¢ÈËÔ±Äܹ»Í¨¹ýeagerfpu=on ²ÎÊýÀ´Æô¶¯ÄÚºË £¬Ê¹ÓÃEager FP¸´Ô­Ä£Ê½À´°ü°ìLazy FP¸´Ô­Ä£Ê½ £¬Eager FP¸´Ô­Ä£Ê½Ï £¬ÎÞÂÛµ±Ç°¹ý³ÌÊÇ·ñʹÓÃFPU £¬³ÇÊб£Áô²¢¸´Ô­FPU ¸ßµÍÎÄ״̬¡£


Õë¶ÔWindows £¬Ä¿Ç°Lazy restore ÔÚWindows ÉÏĬÈÏ¿ªÆô £¬ÇÒÎÞ·¨±»½ûÓà £¬±ØÒªÎ¢Èí¹Ù·½Ìṩ×îв¹¶¡½¨¸´¡£


²Î¿¼×ÊÁÏ


https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00145.html


https://access.redhat.com/solutions/3485131


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180016


https://www.bleepingcomputer.com/news/security/new-lazy-fp-state-restore-vulnerability-affects-all-intel-core-cpus/