CVE-2020-13844 | ARM CPU SLSÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-06-170x00 Îó²î¸ÅÊö
|
CVE ID |
CVE-2020-13844 |
ʱ ¼ä |
2020-06-17 |
|
Àà ÐÍ |
|
µÈ ¼¶ |
ÖÐΣ |
|
Ô¶³ÌʹÓà |
·ñ |
Ó°Ïì¹æÄ£ |
Arm Armv8-A |
0x01 Îó²îÏêÇé
2020Äê6Ô£¬GoogleµÄSafeSideС×éÔÚARM´¦Öóͷ£Æ÷µÄArmv8-A£¨Cortex-A£©CPUϵͳ½á¹¹Öз¢Ã÷ÁËÒ»¸öÃûΪ¡°Straight-Line Speculation £¬SLS¡±µÄÐÂÎó²î£¨CVE-2020-13844£©¡£¸ÃÎó²îµ¼Ö¹¥»÷Õß¶ÔARM¼Ü¹¹´¦Öóͷ£Æ÷¾ÙÐвàÐŵÀ¹¥»÷¡£
SLSÊDzàÐŵÀ¹¥»÷Àï½ÏÁ¿¾µäµÄÒ»ÖÖ£¬¿ÉÒÔÈô¦Öóͷ£Æ÷Ô¤ÏÈ»á¼ûÊý¾ÝÀ´ÌáÉýÐÔÄÜ£¬È»ºóÑïÆúËùÓÐû±»Ê¹ÓùýµÄÅÌËã·ÖÖ§¡£ÖîÔÆÔÆÀàµÄ²àͨµÀ¹¥»÷¿ÉÒÔÈù¥»÷ÕßÄܹ»´Ó´¦Öóͷ£Æ÷ÇÔÈ¡Êý¾Ý¡£
ARMÈ·ÈÏSLSÊÇÔʼSpectreÎó²îµÄÒ»ÖÖ±äÌ壬SpectreÎó²î·¢Ã÷ÓÚ2018Äê1Ô£¬¸ÃÎó²îµ¼Ö¹¥»÷Õß¿ÉÒÔÇÔÈ¡ÅÌËã»úÄÚ´æÖеÄÐÅÏ¢£¬Éæ¼°´æ´¢ÔÚÃÜÂë¹ÜÀíÆ÷»òä¯ÀÀÆ÷ÖеÄÃÜÂ롢СÎÒ˽¼ÒÕÕÆ¬¡¢µç×ÓÓʼþ¡¢¼´Ê±ÐÂÎÅ¡¢ÉõÖÁÊÇÒªº¦ÓªÒµÎĵµ¡£SLSºÍSpectreÎó²îµÄÓ°Ïì¹æÄ£²î±ð£¬SLS½öÓ°ÏìArm Armv-A´¦Öóͷ£Æ÷£¬¶øSpectreÓ°ÏìËùÓÐÖ÷Á÷Ð¾Æ¬ÖÆÔìÉ̵ÄCPU¡£
µ½ÏÖÔÚΪֹ£¬¸ÃÎó²î»¹Ã»ÓÐÔÚҰʹÓᣵ«Ë¼Á¿µ½ARM´¦Öóͷ£Æ÷µÄÓ¦ÓùæÄ£ºÜÊÇÖ®¹ã£¬Éæ¼°ÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄÔÉõÖÁµ¥Æ¬»úµÈ£¬ÒÔÊǸÃÎó²îµÄÓ°Ïì¹æÄ£½ÏÁ¿´ó¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡£¬°üÀ¨FreeBSD£¬OpenBSD£¬Trusted Firmware-AºÍOP-TEE¡£²¹¶¡Á´½Ó£º
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability/latest-updates
ÆäËûÔÝʱ²½·¥£º
ARMÔÚÆä°×ƤÊéÖÐÌṩÁË»º½â²½·¥£¬ÏÂÔØÁ´½Ó£º
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability/downloads/arm-v8-5-a-cpu-updates
0x03 Ïà¹ØÐÂÎÅ
https://cyware.com/news/arm-cpus-face-threats-from-new-variant-of-spectre-vulnerability-44250570/?web_view=true
0x04 ²Î¿¼Á´½Ó
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability/downloads
https://spectreattack.com/#faq-systems-spectre
0x05 ʱ¼äÏß
2020-06-08 ARM¸üÐÂÎó²î²¹¶¡
2020-06-17 VSRCÐû²¼Îó²îͨ¸æ


¾©¹«Íø°²±¸11010802024551ºÅ