{"id":107877,"date":"2023-04-16T12:48:13","date_gmt":"2023-04-16T10:48:13","guid":{"rendered":"https:\/\/prohoster.info\/?p=107877"},"modified":"2023-04-17T17:50:38","modified_gmt":"2023-04-17T15:50:38","slug":"uyazvimost-v-yadre-linux-6-2-pozvolyayushhaya-obojti-zashhitu-ot-atak-spectre-v2","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-yadre-linux-6-2-pozvolyayushhaya-obojti-zashhitu-ot-atak-spectre-v2","title":{"rendered":"Vulnerabilidad en el n\u00facleo de Linux 6.2 que permite eludir la protecci\u00f3n contra ataques Spectre v2","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Se ha identificado una vulnerabilidad en el n\u00facleo de Linux 6.2 (CVE-2023-1998) que desactiva la protecci\u00f3n contra ataques de tipo Spectre v2, lo que permite acceder a la memoria de otros procesos que se ejecutan en hilos SMT o Hyper Threading, pero en un mismo n\u00facleo f\u00edsico del procesador. Entre otras cosas, esta vulnerabilidad puede ser utilizada para filtrar datos entre m\u00e1quinas virtuales en sistemas en la nube. El problema solo afecta al n\u00facleo de Linux 6.2 y es causado por una implementaci\u00f3n incorrecta de optimizaciones destinadas a reducir la sobrecarga significativa al aplicar la protecci\u00f3n contra Spectre v2. La vulnerabilidad ha sido solucionada en la rama experimental del n\u00facleo de Linux 6.3.     <\/p>\n<p>En el espacio de usuario, para protegerse contra ataques de tipo Spectre, los procesos pueden desactivar selectivamente la ejecuci\u00f3n especulativa de instrucciones mediante prctl PR_SET_SPECULATION_CTRL o utilizar la filtraci\u00f3n de llamadas al sistema basada en el mecanismo seccomp. Seg\u00fan los investigadores que identificaron el problema, la optimizaci\u00f3n incorrecta en el n\u00facleo 6.2 dej\u00f3 sin la debida protecci\u00f3n <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/vps\/abuzoustojchivye-vps\/\"   title=\"m\u00e1quinas virtuales\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"4229\">m\u00e1quinas virtuales<\/a> al menos a un importante proveedor de nube, a pesar de que se activ\u00f3 el modo de bloqueo de ataques spectre-BTI a trav\u00e9s de prctl. La vulnerabilidad tambi\u00e9n se manifiesta en <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/server\/dts-gdansk\/\"   title=\"como en entornos de nube p\u00fablicos o privados.\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"4556\">como en entornos de nube p\u00fablicos o privados.<\/a> con n\u00facleo 6.2, al cargar los cuales se utiliza la configuraci\u00f3n &#171;spectre_v2=ibrs.    <\/p>\n<p>La esencia de la vulnerabilidad es que al seleccionar los modos de protecci\u00f3n IBRS o eIBRS, las optimizaciones introducidas desactivaron la aplicaci\u00f3n del mecanismo STIBP (Single Thread Indirect Branch Predictors), necesario para bloquear las filtraciones al utilizar la tecnolog\u00eda de multihilo simult\u00e1neo (SMT o Hyper-Threading). En este caso, solo el modo eIBRS proporciona protecci\u00f3n contra filtraciones entre hilos, pero no el modo IBRS, ya que en este \u00faltimo el bit IBRS, que ofrece protecci\u00f3n contra filtraciones entre n\u00facleos l\u00f3gicos, se limpia por razones de rendimiento al devolver el control al espacio de usuario, lo que deja a los hilos en el espacio de usuario desprotegidos contra ataques de tipo Spectre v2.<br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=58981\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u044f\u0434\u0440\u0435 Linux 6.2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-1998), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044e \u0437\u0430\u0449\u0438\u0442\u044b \u043e\u0442 \u0430\u0442\u0430\u043a \u043a\u043b\u0430\u0441\u0441\u0430 Spectre v2, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043f\u0430\u043c\u044f\u0442\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432, \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0445 \u0432 \u0440\u0430\u0437\u043d\u044b\u0445 \u043f\u043e\u0442\u043e\u043a\u0430\u0445 SMT \u0438\u043b\u0438 Hyper Threading, \u043d\u043e \u043d\u0430 \u043e\u0434\u043d\u043e\u043c \u0444\u0438\u0437\u0438\u0447\u0435\u0441\u043a\u043e\u043c \u044f\u0434\u0440\u0435 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u0430. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u0441\u0440\u0435\u0434\u0438 \u043f\u0440\u043e\u0447\u0435\u0433\u043e, \u043c\u043e\u0436\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0443\u0442\u0435\u0447\u043a\u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u043c\u0435\u0436\u0434\u0443 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u043c\u0438 \u043c\u0430\u0448\u0438\u043d\u0430\u043c\u0438 \u0432 \u043e\u0431\u043b\u0430\u0447\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u0442\u043e\u043b\u044c\u043a\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-107877","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux 6.2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-1998), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044e \u0437\u0430\u0449\u0438\u0442\u044b \u043e\u0442 \u0430\u0442\u0430\u043a \u043a\u043b\u0430\u0441\u0441\u0430 Spectre v2, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043f\u0430\u043c\u044f\u0442\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432, \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0445 \u0432 \u0440\u0430\u0437\u043d\u044b\u0445 \u043f\u043e\u0442\u043e\u043a\u0430\u0445 SMT \u0438\u043b\u0438 Hyper.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-yadre-linux-6-2-pozvolyayushhaya-obojti-zashhitu-ot-atak-spectre-v2\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u044f\u0434\u0440\u0435 Linux 6.2, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 \u0437\u0430\u0449\u0438\u0442\u0443 \u043e\u0442 \u0430\u0442\u0430\u043a Spectre v2 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux 6.2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-1998), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044e \u0437\u0430\u0449\u0438\u0442\u044b \u043e\u0442 \u0430\u0442\u0430\u043a \u043a\u043b\u0430\u0441\u0441\u0430 Spectre v2, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043f\u0430\u043c\u044f\u0442\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432, \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0445 \u0432 \u0440\u0430\u0437\u043d\u044b\u0445 \u043f\u043e\u0442\u043e\u043a\u0430\u0445 SMT \u0438\u043b\u0438 Hyper.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-yadre-linux-6-2-pozvolyayushhaya-obojti-zashhitu-ot-atak-spectre-v2\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-04-16T10:48:13+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-04-17T15:50:38+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilidad en el n\u00facleo de Linux 6.2 que permite eludir la protecci\u00f3n contra ataques Spectre v2 | ProHoster","description":"Se ha identificado una vulnerabilidad en el n\u00facleo de Linux 6.2 (CVE-2023-1998) que desactiva la protecci\u00f3n contra ataques de tipo Spectre v2, permitiendo el acceso a la memoria de otros procesos ejecutados en diferentes hilos SMT o Hyper.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-yadre-linux-6-2-pozvolyayushhaya-obojti-zashhitu-ot-atak-spectre-v2","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u044f\u0434\u0440\u0435 Linux 6.2, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 \u0437\u0430\u0449\u0438\u0442\u0443 \u043e\u0442 \u0430\u0442\u0430\u043a Spectre v2 | ProHoster","og:description":"\u0412 \u044f\u0434\u0440\u0435 Linux 6.2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-1998), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044e \u0437\u0430\u0449\u0438\u0442\u044b \u043e\u0442 \u0430\u0442\u0430\u043a \u043a\u043b\u0430\u0441\u0441\u0430 Spectre v2, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043f\u0430\u043c\u044f\u0442\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432, \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0445 \u0432 \u0440\u0430\u0437\u043d\u044b\u0445 \u043f\u043e\u0442\u043e\u043a\u0430\u0445 SMT \u0438\u043b\u0438 Hyper.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-yadre-linux-6-2-pozvolyayushhaya-obojti-zashhitu-ot-atak-spectre-v2","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-04-16T10:48:13+00:00","article:modified_time":"2023-04-17T15:50:38+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/107877","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=107877"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/107877\/revisions"}],"predecessor-version":[{"id":164434,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/107877\/revisions\/164434"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=107877"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=107877"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=107877"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}