Ó¢ÌØ¶û¿áî£ CPU·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-06-15

·ì϶±àºÅ


CVE-2018-3665


·ì϶¼¶±ð


¸ß


CVSS·ÖÖµ


³§ÉÌ×ÔÆÀ£º4.3   CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


¸Ã·ì϶ӰÏìËùÓÐÓ¢ÌØ¶û¿áî£Î¢´¦ÖÃÆ÷£¬Ëü´æÔÚÓÚÏÖʵ CPU ÖУ¬Òò¶øÎÞÂÛÓû§Ê¹ÓõÄÊÇÄÄÖÖ²Ù×÷ϵͳÈç Windows¡¢Linux¡¢BSDµÈ£¬Ö»ÓÐÔËÐлùÓÚÓ¢ÌØ¶û¿áĠCPU ÇÒʹÓá°Lazy FPU ¸ßµÍÎÄÇл»¡±Ö°Äܼ´ÊÜÓ°Ïì¡£


·ìϼûèÊö


2018Äê6ÔÂ14ÈÕ£¬Intel ¹Ù·½Åû¶´¦ÖÃÆ÷Öи¡µã¼Ä·ÅÆ÷×´Ì¬ÍÆ³Ù±£ÁôµÄ¸öÐÔ´æÔÚ·ì϶£¬ÀûÓô˷ì϶£¬½áºÏ´§Ä¦Ö´ÐкͲàÐÅ·¹¥»÷Äܹ»Ð¹Â¶ÁíÒ»¸ö¹ý³ÌµÄ¸¡µã¼Ä·ÅÆ÷״̬£¬¿ÉÄÜÔì³ÉÃô¸ÐÐÅϢй¶¡£


ÏÖ´ú´¦ÖÃÆ÷ÔÚ¹ý³ÌÇл»Ê±Äܹ»Ñ¡ÔñÍÆ³Ù±£ÁôºÍ¸´Ô­Ä³Ð©CPU µÄ¸ßµÍÎÄ״̬À´Ìá¸ßϵͳ»úÄÜ¡£


ÆäÖÐFPU Ϊ¸¡µãµ¥Ôª£¬¿ÉÓÃÓڸ߾«¶È¸¡µãÔËË㣬ÓÉÓÚ²»ÊÇËùÓеÄÀûÓ÷¨Ê½¶¼Ê¹ÓÃFPU£¬ËùÒÔÀûÓÃÍÆ³Ù±£Áô/¸´Ô­µÄ¸öÐÔ£¬ÈôÊÇе÷¶ÈµÄ¹ý³Ì²»Ê¹ÓÃFP Ö¸ÁÔò²»±ØÒªÇл»FPU ¸ßµÍÎÄ״̬£¬ÒÔ´ËÀ´Ï÷¼õÖ´ÐÐÖÜÆÚ£¬Ìá¸ß»úÄÜ¡£µ±Ð¹ý³ÌʹÓÃFP Ö¸Áîʱ£¬»á´¥·¢¡°É豸²»³ÉÓã¨DNA£©¡±Òì³££¬Í¨¹ýÒì³£´¦ÖÃÀ´Çл»FPU ¸ßµÍÎÄ״̬¡£


ÀûÓøøöÐÔ£¬Äܹ»Í¨¹ý´§Ä¦Ö´ÐкͲàÐÅ·¹¥»÷ÔÚ´¥·¢DNA Ò쳣ǰ¶Áȡ֮ǰ¹ý³ÌµÄ¸¡µã¡£


ͬÑùÓµÓиøöÐԵϹÓÐSSE£¬AVX£¬MMX£¬²¢ÇÒAESµÄ¼ÓÃÜÃÜԿͨ³£»á´æ·ÅÔÚSSE¼Ä·ÅÆ÷ÖУ¬Õâ¿ÉÄÜʹ¹¥»÷Õß¿ÉÄÜÇÔÈ¡¸ü¶àÓÐЧÐÅÏ¢¡£


½â¾ö´ëÊ©


Õë¶ÔLinux£¬ÏµÍ³¿ª·¢ÈËÔ±Äܹ»Í¨¹ýeagerfpu=on ²ÎÊýÀ´Æô¶¯Äںˣ¬Ê¹ÓÃEager FP¸´Ô­Ä£Ê½À´°ü°ìLazy FP¸´Ô­Ä£Ê½£¬Eager FP¸´Ô­Ä£Ê½Ï£¬ÎÞÂÛµ±Ç°¹ý³ÌÊÇ·ñʹÓÃFPU£¬³ÇÊб£Áô²¢¸´Ô­FPU ¸ßµÍÎÄ״̬¡£


Õë¶ÔWindows£¬Ä¿Ç°Lazy restore ÔÚWindows ÉÏĬÈÏ¿ªÆô£¬ÇÒÎÞ·¨±»½ûÓ㬱ØÒªÎ¢Èí¹Ù·½Ìṩ×îв¹¶¡½¨¸´¡£


²Î¿¼×ÊÁÏ


https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00145.html


https://access.redhat.com/solutions/3485131


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180016


https://www.bleepingcomputer.com/news/security/new-lazy-fp-state-restore-vulnerability-affects-all-intel-core-cpus/