MeltdownºÍSpectre´¦Öóͷ£Æ÷Îó²îÍþв´¦Öóͷ£½¨Òé
2018-01-11
Ò». Îó²îÕªÒª
2018Äê1ÔÂ4ÈÕ£¬ÍâÑóÑо¿»ú¹¹Åû¶ÁË”Meltdown”(CVE-2017-5754)ºÍ”Spectre”(CVE-2017-5753& CVE-2017-5715)Á½×éCPUÌØÕ÷Îó²î£¬Îó²î±¬³öºó£¬Ñо¿Ö°Ô±Ò²Â½ÐøÐû²¼ÖÖÖÖ¼ì²âPOC£¬Ïà¹Ø²Ù×÷ϵͳ³§ÉÌÒÔ¼°ä¯ÀÀÆ÷Ö§³Ö³§ÉÌÒ²Â½ÐøÐû²¼ÐÞ¸´²¹¶¡£¬ÏêÇé²ÎÕÕÎó²î²¹¶¡¸üÐÂÕ½Ú
ʹÓÃMeltdownÎó²î£¬µÍȨÏÞÓû§¿ÉÒÔ»á¼ûÄں˵ÄÄÚÈÝ£¬»ñÈ¡ÍâµØ²Ù×÷ϵͳµ×²ãµÄÐÅÏ¢£»µ±Óû§Í¨¹ýä¯ÀÀÆ÷»á¼ûÁ˰üÀ¨Spectre¶ñÒâʹÓóÌÐòµÄÍøÕ¾Ê±£¬Óû§µÄÈçÕʺţ¬ÃÜÂ룬ÓÊÏäµÈСÎÒ˽¼ÒÒþ˽ÐÅÏ¢¿ÉÄܻᱻ×ß©£»ÔÚÔÆ·þÎñ³¡¾°ÖУ¬Ê¹ÓÃSpectre¿ÉÒÔÍ»ÆÆÓû§¼äµÄ¸ôÀ룬ÇÔÈ¡ÆäËûÓû§µÄÊý¾Ý¡£
¶þ. Îó²î²¹¶¡¸üÐÂ
2.1 Windowsϵͳ²¹¶¡¸üÐÂ
1ÔÂ3ÈÕÍí£¬Î¢ÈíÐû²¼ÁËÕë¶ÔMeltdownºÍSpecterµÄϵͳÇå¾²¸üУ¬ÆóÒµ»òСÎÒ˽¼ÒÓû§¿ªÆôϵͳ¸üй¦Ð§ÊµÊ±´òÈ«×îеÄÇå¾²²¹¶¡¡£
ÆóÒµ»òСÎÒ˽¼ÒÓû§¿ÉÒÔÑ¡Ôñ×Ô¶¯¸üлòÊÖ¶¯ÏÂÔØ²¹¶¡¾ÙÐиüУ¬²¹¶¡ÏÂÔØµØµã¼û¸½Â¼A¡£
×Ô¶¯¸üУº
ÔÚÆóÒµÄÚÍøÇéÐÎÖУ¬¿ÉÒÔͨ¹ýWSUS·þÎñÆ÷ÅþÁ¬µ½Microsoft UpdateÀ´»ñÈ¡¸üгÌÐò£¬²¢·Ö·¢¸øÆóÒµÍøÂçÖеĿͻ§¶ËÅÌËã»úʵÏÖÅúÁ¿¸üС£
СÎÒ˽¼ÒÓû§¿ÉÒÔ½øÈë“ÉèÖÔ-“¸üÐÂÓëÇå¾²”£¬Ñ¡Ôñ“¼ì²é¸üД£¬×°Öò¹¶¡¡£²¿·Ö¼æÈÝÐÔÉϱ£´æÎÊÌâµÄÓû§ÔòÐèÒª¼ÌÐøÄÍÐÄÆÚ´ý¼¸Ìì¡£

ÊÖ¶¯¸üУº
ƾ֤ÒÔϰ汾Óë¶ÔÓ¦KBºÅ£¬ÔÚ΢ÈíÇå¾²½¨Òéhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002 £¬²éµ½¶ÔÓ¦¸üÐÂÈí¼þ°ü²¢ÏÂÔØ¸üС£

ÏÖÔÚµÄϵͳ²¹¶¡Éв»¿ÉÍêÕûÐÞ¸´MeltdownºÍSpectre´¦Öóͷ£Æ÷Îó²î£¬ÆóÒµºÍÓû§¿ÉÄÜÐèÒªÌØÁíÍâоƬ×é¹Ì¼þ¸üС£ÈôÊÇÌõ¼Ç±¾µçÄÔ/̨ʽ»ú/·þÎñÆ÷¹©Ó¦ÉÌÌṩÁËÌØÁíÍâоƬ×é¹Ì¼þ¸üУ¬¿ÉÒÔ´Ó¹Ù·½Õ¾µã»ñÈ¡£¬×°Öò¢Íê³ÉÐÞ²¹³ÌÐò¡£
2.2 Linuxϵͳ²¹¶¡¸üÐÂ
Linux Kernel
Linux Ðû²¼ÁËÄں˲¹¶¡£¬°æ±¾°üÀ¨ 4.14.11¡¢4.9.74¡¢4.4.109¡¢3.16.52¡¢3.18.91 ºÍ 3.2.97£¬Óû§¿ÉÒÔ´Ó Kernel.org ÉÏÏÂÔØ¡£
²Î¿¼Á´½Ó£º
https://www.kernel.org/
Red hat:
ºìñ¹«Ë¾ÒѾÐû²¼Í¨¸æ£¬ÆäÖÐÁгöÊܵ½Ó°ÏìµÄ²úÆ·¼°ÆäÄ¿½ñ״̬¡£½¨ÒéÄÚÈÝÅú×¢£º¹ØÓÚÕýÔÚÔËÐÐÊÜÓ°Ïì°æ±¾²úÆ·µÄºìñ¿Í»§£¬Ç¿ÁÒ½¨ÒéÓû§¾¡¿ìƾָ֤µ¼Çåµ¥¾ÙÐиüС£ËùÓÐÊÜÓ°Ïì²úÆ·¶¼Ó¦×°ÖÃÐÞ¸´²¹¶¡¡£
Ret HatÇ徲ͨ¸æµØµã£ºhttps://access.redhat.com/security/vulnerabilities/speculativeexecution
Êܵ½MeltdownÓ°ÏìµÄ²úÆ·Ãû³Æ
|
Red Hat Enterprise Linux 7(ÒѸüÐÂ) Red Hat Enterprise Linux 6(²¿·Ö¸üÐÂ) Red Hat Enterprise Linux 5(´ý¸üÐÂ) RHEL Atomic Host(´ý¸üÐÂ) Red Hat Enterprise MRG 2 (ÒѸüÐÂ) |
Êܵ½SpectreÓ°ÏìµÄ²úÆ·Ãû³Æ
|
Red Hat Enterprise Linux 7 (ÒѸüÐÂ) Red Hat Enterprise Linux 6 (²¿·Ö¸üÐÂ) Red Hat Enterprise Linux 5 (´ý¸üÐÂ) RHEL Atomic Host (´ý¸üÐÂ) Red Hat Enterprise MRG 2(ÒѸüÐÂ) Red Hat Virtualization 3ELS¡¢4(RHEV-H/RHV-H)(ÒѸüÐÂ) Red Hat OpenStack v6 (´ý¸üÐÂ) Red Hat OpenStack v7 (´ý¸üÐÂ) Red Hat OpenStack v8 (´ý¸üÐÂ) Red Hat OpenStack v9(´ý¸üÐÂ) Red Hat OpenStack v10 (´ý¸üÐÂ) Red Hat OpenStack v11 (´ý¸üÐÂ) Red Hat OpenStack v12 (´ý¸üÐÂ) |
CentOS:
CentOSÍŶӿËÈÕÃæÏò64루x86_64£©CentOS 7ÔÚÄڵĶà¸ö°æ±¾Ðû²¼ÄÚºËÇå¾²²¹¶¡£¬ÖصãÐÞ¸´ÁËÈÕǰ±¬·¢µÄMeltdown£¨ÈÛ¶Ï£©ºÍSpectre£¨ÓÄÁ飩Á½¸öÎó²î¡£CentOS 7»ùÓÚRed Hat Enterprise Linux 7£¬±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÊÇÔÚRed Hat½üÆÚÐû²¼µÄÐÞ¸´²¹¶¡ÉϾÙÐж¨ÖÆÓÅ»¯µÄ¡£
ÏÖÔÚ±£´æÎÊÌâµÄÈí¼þ°üÀ¨kernel-3.10.0-693.11.6.el7.x86_64.rpm kernel-abi-whitelists-3.10.0-693.11.6.el7.noarch.rpm kernel-debug-3.10.0-693.11.6.el7.x86_64.rpm kernel-debug-devel-3.10.0-693.11.6.el7.x86_64.rpm kernel-devel-3.10.0-693.11.6.el7.x86_64.rpmÒÔ¼°kernel-doc-3.10.0-693.11.6.el7.noarch.rpm¡£
±ðµÄkernel-headers-3.10.0-693.11.6.el7.x86_64.rpm kernel-tools-3.10.0-693.11.6.el7.x86_64.rpm kernel-tools-libs-3.10.0-693.11.6.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-693.11.6.el7.x86_64.rpm perf-3.10.0-693.11.6.el7.x86_64.rpmºÍ python-perf-3.10.0-693.11.6.el7.x86_64.rpmÒ²ÐèÒª¸üС£
²Î¿¼Á´½Ó£º
CentOS 6 kernel Security Update
https://lists.centos.org/pipermail/centos-announce/2018-January/022701.html
CentOS 7 kernel Security Update
https://lists.centos.org/pipermail/centos-announce/2018-January/022696.html
Debian:
ÒÑÕë¶ÔMeltdownÎó²îÌṩ¸üС£
²Î¿¼Á´½Ó£ºhttps://security-tracker.debian.org/tracker/CVE-2017-5754
Ubuntu:
UbuntuÇå¾²ÍŶӵÄDustin KirklandÌåÏÖп¶¡ÒѾÓÉÁËÁ½¸ö¶àÔµIJâÊÔ£¬°üÀ¨Ubuntu 12.04 ESM (Extended Security Maintenance) Ubuntu 14.04 LTS Ubuntu 16.04 LTSºÍUbuntu 17.10ÔÚÄÚËùÓÐÉд¦ÓÚÖ§³Ö״̬µÄUbuntu¿¯Ðа汾¶¼»áÔÚ½üÆÚ»ñµÃ¸üС£
²Î¿¼Á´½Ó£ºhttps://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAndMeltdown
Suse:
½«ÎªËùÓÐÆóÒµ°æSUSE Linux£¨SLE£©ÌṩMeltdownÓëSpectre²¹¶¡¸üУ¬Æ¾Ö¤¹Ù·½ÐÎò£¬SuseÒ²½«ÌṩAMD Óë Intel´¦Öóͷ£Æ÷΢³ÌÐò°üµÄ¹Ì¼þÓëQEMU / KVM¸üиüС£
ÏÖÔÚÒÑÌṩ¸üеÄSLE°æ±¾ÈçÏ£º
|
SLES 12 SP3 SLES 12 SP2 SLES 12 SP1-LTSS SLES 12-LTSS SLES 11 SP4 SLES 11 SP3-LTSS SUSE CaaS Platform |
²Î¿¼Á´½Ó£ºhttps://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/
Fedora:
ÒÑÕë¶ÔFedora Linux²Ù×÷ϵͳ£¨º¬Fedora26¡¢Fedora27°æ±¾£©ÓëRawhide (ÄÚºË 4.15×îÖÕ²âÊÔ°æ±¾)Ìṩ¸üв¹¶¡°ü £¬ÒÔ½µµÍÔâµ½Meltdown¹¥»÷µÄΣº¦¡£
²Î¿¼Á´½Ó£ºhttps://fedoramagazine.org/protect-fedora-system-meltdown/
2.3 оƬ×é¹Ì¼þ¸üÐÂ
Intel ·½ÃæÔÚ1ÔÂ4ºÅÐû²¼ÁËÐÂͨ¸æÌåÏÖ£¬½«°ü¹Ü 90%µÄ CPU£¨½ü5ÄêµÄ£©¹Ì¼þ¸üлáÔÚÏÂÖÜ¿¢ÊÂǰËùÓзųö¡£ÏÖÔÚËûÃÇÒѾÔÚºÍÆäËûÏàÖúͬ°é¾ÙÐÐÕâЩ CPU ¸üС£³õʼװ±¸ÖÆÔìÉÌºÍÆäËûÓ²¼þ¹©Ó¦ÉÌÐèÒª½«ÕâЩ¹Ì¼þ¸üаüÀ¨ÔÚ×Ô¼ºµÄ²úÆ·¸üÐÂÖС£³ý´ËÖ®Í⣬¸Ã¹«Ë¾ÖØÉ꣬¹Ì¼þ¸üв»»áÔì³ÉÏÔÖøµÄÐÔÄÜϽµ£¬²¢ÔÊÐí»áËæ×Åʱ¼äµÄÍÆÒÆ¶ÔÕâЩ²¹¶¡¾ÙÐвâÊÔºÍÓÅ»¯£¬ÒÔ½øÒ»²½¼õÇá¶ÔÐÔÄܵÄÓ°Ïì¡£
ÏêϸÄÚÈÝÇëÏÂÔØ±¨¸æ

AG¹«Ë¾ÔÆ





