AEPIC Leak - ืžืชืงืคื” ื”ืžื“ืœื™ืคืช ืžืคืชื—ื•ืช ืžืžื•ื‘ืœืขื•ืช ืื™ื ื˜ืœ SGX

ื ื—ืฉืฃ ืžื™ื“ืข ืขืœ ืžืชืงืคื” ื—ื“ืฉื” ืขืœ ืžืขื‘ื“ื™ ืื™ื ื˜ืœ - AEPIC Leak (CVE-2022-21233), ืืฉืจ ืžื•ื‘ื™ืœื” ืœื“ืœื™ืคื” ืฉืœ ื ืชื•ื ื™ื ื—ืกื•ื™ื™ื ืžืžื•ื‘ืœืขื•ืช ืžื‘ื•ื“ื“ื•ืช ืฉืœ Intel SGX (Software Guard eXtensions). ื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ืขืœ ื“ื•ืจื•ืช 10, 11 ื•-12 ืฉืœ ืžืขื‘ื“ื™ ืื™ื ื˜ืœ (ื›ื•ืœืœ ืกื“ืจืช Ice Lake ื•-Alder Lake ื”ื—ื“ืฉื”) ื•ื ื’ืจืžืช ืขืœ ื™ื“ื™ ืคื’ื ืืจื›ื™ื˜ืงื˜ื•ื ื™ ื”ืžืืคืฉืจ ื’ื™ืฉื” ืœื ืชื•ื ื™ื ืœื ืžืื•ืชื—ืœื™ื ืฉื ื•ืชืจื• ื‘-APIC (Advanced Programmable Interrupt Controller) ืœืื—ืจ ื”ืขื‘ืจ ืคืขื•ืœื•ืช.

ืฉืœื ื›ืžื• ื”ืชืงืคื•ืช ืžื—ืœืงื•ืช Spectre, ื”ื“ืœื™ืคื” ื‘- AEPIC Leak ืžืชืจื—ืฉืช ืœืœื ืฉื™ืžื•ืฉ ื‘ืฉื™ื˜ื•ืช ืฉื—ื–ื•ืจ ื“ืจืš ืขืจื•ืฆื™ ืฆื“ ืฉืœื™ืฉื™ - ืžื™ื“ืข ืขืœ ื ืชื•ื ื™ื ืกื•ื“ื™ื™ื ืžื•ืขื‘ืจ ื™ืฉื™ืจื•ืช ืขืœ ื™ื“ื™ ื”ืฉื’ืช ืชื•ื›ืŸ ื”ืจืฉืžื™ื ื”ืžืฉืชืงืฃ ื‘ื“ืฃ ื”ื–ื™ื›ืจื•ืŸ ืฉืœ MMIO (memory-mapped I/O) . ื‘ืื•ืคืŸ ื›ืœืœื™, ื”ืžืชืงืคื” ืžืืคืฉืจืช ืœืงื‘ื•ืข ืืช ื”ื ืชื•ื ื™ื ื”ืžื•ืขื‘ืจื™ื ื‘ื™ืŸ ื”ืžื˜ืžื•ืŸ ืฉืœ ื”ืจืžื” ื”ืฉื ื™ื™ื” ื•ื”ืื—ืจื•ื ื”, ื›ื•ืœืœ ืชื•ื›ืŸ ืจื’ื™ืกื˜ืจื™ื ื•ืชื•ืฆืื•ืช ืฉืœ ืคืขื•ืœื•ืช ืงืจื™ืื” ืžื”ื–ื™ื›ืจื•ืŸ, ืฉืขื•ื‘ื“ื• ื‘ืขื‘ืจ ืขืœ ืื•ืชื” ืœื™ื‘ืช ืžืขื‘ื“.

ืžื›ื™ื•ื•ืŸ ืฉื›ื“ื™ ืœื‘ืฆืข ืชืงื™ืคื” ื™ืฉ ืฆื•ืจืš ื‘ื’ื™ืฉื” ืœื“ืคื™ื ื”ืคื™ื–ื™ื™ื ืฉืœ APIC MMIO, ื›ืœื•ืžืจ. ื“ื•ืจืฉ ื”ืจืฉืื•ืช ืžื ื”ืœ, ื”ืฉื™ื˜ื” ืžื•ื’ื‘ืœืช ืœืชืงื™ืคืช ืžื•ื‘ืœืขื•ืช SGX ืฉืœืžื ื”ืœ ืื™ืŸ ื’ื™ืฉื” ื™ืฉื™ืจื” ืืœื™ื”ืŸ. ื—ื•ืงืจื™ื ืคื™ืชื—ื• ื›ืœื™ื ื”ืžืืคืฉืจื™ื, ืชื•ืš ืžืกืคืจ ืฉื ื™ื•ืช, ืœืงื‘ื•ืข ืืช ืžืคืชื—ื•ืช AES-NI ื•-RSA ื”ืžืื•ื—ืกื ื™ื ื‘-SGX, ื›ืžื• ื’ื ืžืคืชื—ื•ืช ื”ืกืžื›ื” ืฉืœ Intel SGX ื•ืคืจืžื˜ืจื™ื ืฉืœ ืžื—ื•ืœืœ ืžืกืคืจื™ื ืคืกืื•ื“ื•-ืืงืจืื™ื™ื. ื”ืงื•ื“ ืœื”ืชืงืคื” ืคื•ืจืกื ื‘-GitHub.

ืื™ื ื˜ืœ ื”ื•ื“ื™ืขื” ืขืœ ืชื™ืงื•ืŸ ื‘ืฆื•ืจื” ืฉืœ ืขื“ื›ื•ืŸ ืžื™ืงืจื•ืงื•ื“ ืฉื™ื˜ืžื™ืข ืชืžื™ื›ื” ื‘ืฉื˜ื™ืคื” ื‘ืžืื’ืจ ื•ื™ื•ืกื™ืฃ ืืžืฆืขื™ื ื ื•ืกืคื™ื ืœื”ื’ื ื” ืขืœ ื ืชื•ื ื™ ื”ืžื•ื‘ืœืขืช. ืžื”ื“ื•ืจืช SDK ื—ื“ืฉื” ืขื‘ื•ืจ Intel SGX ื”ื•ื›ื ื” ื’ื ื”ื™ื ืขื ืฉื™ื ื•ื™ื™ื ื›ื“ื™ ืœืžื ื•ืข ื“ืœื™ืคื•ืช ื ืชื•ื ื™ื. ืœืžืคืชื—ื™ื ืฉืœ ืžืขืจื›ื•ืช ื”ืคืขืœื” ื•ื”ื™ืคืจื•ื•ื™ื–ื•ืจื™ื ืžื•ืžืœืฅ ืœื”ืฉืชืžืฉ ื‘ืžืฆื‘ x2APIC ื‘ืžืงื•ื ื‘ืžืฆื‘ xAPIC ืžื“ื•ืจ ืงื•ื“ื, ื‘ื• ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืื•ื’ืจื™ MSR ื‘ืžืงื•ื ื‘-MMIO ื›ื“ื™ ืœื’ืฉืช ืœืื•ื’ืจื™ APIC.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”