Intel ´¦Öóͷ£Æ÷Ó²¼þ¡°VoltJockey¡±£¨ÆïÊ¿£©Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2019-12-11

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-11157£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.9£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Intel Core µÚ6¡¢7¡¢8¡¢9ºÍµÚ10´ú´¦Öóͷ£Æ÷

Intel Xeon ´¦Öóͷ£Æ÷E3 v5ºÍv6

Intel Xeon ´¦Öóͷ£Æ÷E-2100 ºÍ E-2200


Îó²î¸ÅÊö


2019Äê12ÔÂ10ÈÕ£¬£¬£¬£¬Intel¹ÙÆÓֱʽȷÈϲ¢Ðû²¼ÁË¡°VoltJockey¡±£¨ÆïÊ¿£©Îó²îͨ¸æ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚÏÖ´úÖ÷Á÷´¦Öóͷ£Æ÷΢ϵͳ¼Ü¹¹Éè¼ÆÊ±½ÓÄɵĶ¯Ì¬µçÔ´ÖÎÀíÄ£¿£¿£¿ £¿ £¿£¿£¿£¿éDVFS£¨Dynamic Voltage and Frequency Scaling£©±£´æÇå¾²Òþ»¼Ôì³ÉµÄ£¬£¬£¬£¬±£´æÌáȨºÍÐÅϢй¶µÄΣº¦¡£¡£¡£¡£¡£¡£¡£¡£


VoltJockeyÎó²î»ùÓÚµçѹ¹ÊÕÏ×¢Èë¶ÔCPU¾ÙÐй¥»÷£¬£¬£¬£¬Ê¹ÓÃÓ²¼þ¹ÊÕ϶ÔCPUµÄÓ²¼þ¸ôÀëÉèÊ©£¨ÈçTrustZone£©¾ÙÐй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£²î±ðÓڹŰå½ÓÄɱà³Ì½Ó¿ÚÎó²îµÄ¹¥»÷·½·¨£¬£¬£¬£¬¸ÃÒªÁìÍêÈ«½ÓÄÉCPUµÄÓ²¼þÎó²î£¬£¬£¬£¬·ÀÓùÆðÀ´Ïà¶ÔÄÑÌ⣬£¬£¬£¬ÇÒ¹ØÓÚÀàËÆTrustZoneµÄÆäËüCPUµÄÓ²¼þÇå¾²À©Õ¹Ò²ÓÐÀàËÆÐ§¹û¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚVoltJockeyÎó²îÆÕ±é±£´æÓÚÖ÷Á÷´¦Öóͷ£Æ÷оƬÖУ¬£¬£¬£¬¿ÉÄÜÉæ¼°Ä¿½ñ´ó×ÚʹÓõÄÊÖ»úÖ§¸¶¡¢ÈËÁ³/Ö¸ÎÆÊ¶±ð¡¢Çå¾²ÔÆÅÌËãµÈ¸ß¼ÛÖµÃܶÈÓ¦ÓõÄÇå¾²£¬£¬£¬£¬Ó°ÏìÃæ¹ã¡£¡£¡£¡£¡£¡£¡£¡£


ÁíÍâ¸ÃÇå¾²Îó²î½öµ±ÔÚIntel SGX£¨Software Guard Extensions£©¿ªÆôʱ²Å±£´æ¡£¡£¡£¡£¡£¡£¡£¡£IntelÒѾ­ÏòÏµÍ³ÖÆÔìÉÌÐû²¼Á˹̼þ¸üУ¬£¬£¬£¬ÒÔ»º½âÕâһDZÔÚµÄÎó²î¡£¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


Intel½¨ÒéÊÜÓ°ÏìµÄÓû§ÓëÏµÍ³ÖÆÔìÉÌÁªÏµ£¬£¬£¬£¬ÒÔ»ñÈ¡¿É»º½â´ËÎÊÌâµÄ×îÐÂBIOS¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00289.html