新的幽靈漏洞昨天被發佈 - 3C

Enid avatar
By Enid
at 2022-03-09T12:58

Table of Contents

新聞來源:
https://www.tomshardware.com/news/intel-alder-lake-arm-cpus-affected-by-new-spec
tre-vulnerability

縮網址:https://bit.ly/3hOskDS

新的幽靈漏洞昨天被發佈,
這個屬於Specture-V2的漏洞,主要影響Intel跟Arm CPU系統,
Intel從Haswell開始到Alderlake都有影響,
會出一個新的軟體更新去修正這問題,

Arms則是影響Cortex A15, A57, A72 及 Neoverse V1, N1, and N2

可由Intel之 CVE-2022-0001、CVE-2022-0002
及 Arm 之 CVE-2022-23960 了解漏洞及修正

漏洞演示:
https://twitter.com/vu5ec/status/1501256481097883648

https://youtu.be/537HUwV36ME


底下為原文:
VUSec security research group and Intel on Tuesday disclosed a yet another Spect
re-class speculative execution vulnerability called branch history injection (BH
I). The new exploit affects all of Intel processors released in the recent years
, including the latest Alder Lake CPUs, and select Arm cores. By contrast, AMD's
chips are believed to be unaffected.

BHI is a proof-of-concept attack that affects CPUs already vulnerable to Spectre
V2 exploits, but with all kinds of mitigations already in place. The new exploi
t bypasses Intel's eIBRS and Arm's CSV2 mitigations, reports Phoronix. BHI re-en
ables cross-privilege Spectre-v2 exploits, allows kernel-to-kernel (so-called in
tra-mode BTI) exploits, and allows perpetrators to inject predictor entries into
the global branch prediction history to make kernel leak data, reports VUSec. A
s a result, arbitrary kernel memory on select CPUs can be leaked and potentially
reveal confidential information, including passwords. An example of how such a
leak can happen was published here.

VUSec
圖片我就不附上,因為有影片
(Image credit: VUSec)
All of Intel's processors beginning with Haswell (launched in 2013) and extendin
g to the latest Ice Lake-SP and Alder Lake are affected by the vulnerability, bu
t Intel is about to release a software patch that will mitigate the issue.

Numerous cores from Arm, including Cortex A15, A57, A72 as well as Neoverse V1,
N1, and N2 are also affected. Arm is expected to release software mitigations f
or its cores. What is unclear is whether custom versions of these cores (e.g., s
elect cores from Qualcomm) are also affected and when the potential security hol
es will be covered.

Since this is a proof-of-concept vulnerability and it is being mitigated by Inte
l and Arm, it should not be able to be used to attack a client or server machine
— as long as all the latest patches are installed. There's no indication how m
uch the mitigations will impact performance.

----------
https://i.imgur.com/RVYbywG.jpg

----
Sent from BePTT on my SHARP FS8002

--
Tags: 3C

All Comments

Regina avatar
By Regina
at 2022-03-09T15:29
是AMD運氣好嗎?常常都沒他的事
Lucy avatar
By Lucy
at 2022-03-09T18:01
架構不同,分支預測做法不同
Ida avatar
By Ida
at 2022-03-09T20:32
不會說都沒有,但是會比較少
Joe avatar
By Joe
at 2022-03-09T23:04
https://bit.ly/3hOWZRF
其實沒有比較少,只是沒人無聊一直
Joseph avatar
By Joseph
at 2022-03-10T01:35
貼。這一個還算蠻有趣的
Mia avatar
By Mia
at 2022-03-10T04:07
AMD自己bug就夠搞了
Ursula avatar
By Ursula
at 2022-03-10T06:38
Designer: 又要多浪費電晶體了
Connor avatar
By Connor
at 2022-03-10T09:10
一直都有,看大不大條和好不好修而
已,以前的漏洞是修完-50%效能才被
Ida avatar
By Ida
at 2022-03-10T11:41
AMD被炮是因為效能原本就沒有intel
Hazel avatar
By Hazel
at 2022-03-10T14:13
好 修完BUG例如當年TLB BUG效能
又更少
Puput avatar
By Puput
at 2022-03-10T16:44
安全漏洞無感吧 用AMD的很少
的人
Rachel avatar
By Rachel
at 2022-03-10T14:58
i皇「跟上!! AMD快跟上!!」
Iris avatar
By Iris
at 2022-03-10T17:30
I皇就靠漏洞偷效能
Agatha avatar
By Agatha
at 2022-03-10T14:58
當年分支預測漏洞號稱修補後最多會
降20%效能,但是實測之後影響很小
不過這個一系列漏洞的確打亂了i社
Bennie avatar
By Bennie
at 2022-03-10T17:30
的處理器布局,黑暗的九代U大部分都
拿掉了HT,整個市場定位亂掉
Olivia avatar
By Olivia
at 2022-03-10T14:58
九代可以說是最亂的一代
Zora avatar
By Zora
at 2022-03-10T17:30
打了補丁又要降幾%效能
Hardy avatar
By Hardy
at 2022-03-10T14:58
原來是宣稱喔?我還以為是真的 XD
Zora avatar
By Zora
at 2022-03-10T17:30
那時很多團隊都測試過了,是有影響
但是對於一般user的影響很小。分支
Harry avatar
By Harry
at 2022-03-10T14:58
預測的漏洞影響最大的是server用戶
當時比較擔心的是ssh key會被這種小
Megan avatar
By Megan
at 2022-03-10T17:30
刀掘牆滴水穿石的方式偷走。但以結
果而言,駭客寧願去選更有效率的方
Freda avatar
By Freda
at 2022-03-10T14:58
Ingrid avatar
By Ingrid
at 2022-03-10T17:30
e3 1231 v3被吃很多校能幹
Joe avatar
By Joe
at 2022-03-10T14:58
#1TD5NRWH (PC_Shopping)
之前九代 還更新了步進從硬體層面修
Candice avatar
By Candice
at 2022-03-10T17:30
Xeon E5 那時候I/O影響比較大
Frederica avatar
By Frederica
at 2022-03-10T14:58
12代分支預測已經改良過了
Suhail Hany avatar
By Suhail Hany
at 2022-03-10T17:30
又有漏洞了喔...

某屋TUF 跟ROG 3070ti開放單買

Michael avatar
By Michael
at 2022-03-09T12:57
藉這篇文問個問題 3070ti因為切壞又很臭所以乏人問津 那麼 3080ti算不算切壞或臭? 因為之前在搜尋降壓超頻 我看很多人都說買3080 但幾乎沒看到買3080ti的 ? - ...

CST130 Basic 便宜的小型mATX機殼

Madame avatar
By Madame
at 2022-03-09T12:48
電蝦板各位12900KS、3090Ti好 阿肥我前陣子看到這咖CST130 Basic 27.3L的體積在可以裝mATX板子+ATX PSU的機殼裡算小的 加上我不太喜歡玻璃側板,CST130用的壓克力側板正得我心 於是阿肥我就不小心手滑買下去惹 https://imgur.com/8o55KNF 我在P ...

fuhbbjj

Quanna avatar
By Quanna
at 2022-03-09T11:19
Gubhbjj ----- Sent from JPTT on my iPhone - ...

美亞 RM750x $83 10y/全模

Audriana avatar
By Audriana
at 2022-03-09T11:11
這網址應該沒含紅利連結之類的吧 https://www.amazon.com/CORSAIR-RM750x-Certified-Modular-Supply/dp/B079HGN5QS 我看現在寄臺灣免運,不知道有沒有人要肉測xD 預計出貨日 3/28 要想清楚 我記得賊船應該有全球保吧 -80金 -全 ...

某屋TUF 跟ROG 3070ti開放單買

Kama avatar
By Kama
at 2022-03-09T10:08
沒跟到大哥的3070Ti,這兩張開放單買選TUF會不會太盤了?還是再等等? - ...