ืื™ื ื˜ืœ ืคืจืกืžื” ืžื™ื“ืข ืขืœ ืกื•ื’ ื—ื“ืฉ ืฉืœ ืคื’ื™ืขื•ื™ื•ืช

ืื™ื ื˜ืœ ืคืจืกืžื” ืžื™ื“ืข ืขืœ ืกื•ื’ ื—ื“ืฉ ืฉืœ ืคื’ื™ืขื•ื™ื•ืช ื‘ืžืขื‘ื“ื™ื ืฉืœื” - MDS (Microarchitectural Data Sampling). ื›ืžื• ื”ืชืงืคื•ืช ืงื•ื“ืžื•ืช ืฉืœ Spectre, ื”ื‘ืขื™ื•ืช ื”ื—ื“ืฉื•ืช ืขืœื•ืœื•ืช ืœื”ื•ื‘ื™ืœ ืœื“ืœื™ืคื” ืฉืœ ื ืชื•ื ื™ื ืงื ื™ื™ื ื™ื™ื ืžืžืขืจื›ืช ื”ื”ืคืขืœื”, ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ื•ืชื”ืœื™ื›ื™ื ื–ืจื™ื. ื ื˜ืขืŸ ื›ื™ ื”ื‘ืขื™ื•ืช ื–ื•ื”ื• ืœืจืืฉื•ื ื” ืขืœ ื™ื“ื™ ืขื•ื‘ื“ื™ ืื™ื ื˜ืœ ื•ืฉื•ืชืคื™ื ื‘ืžื”ืœืš ื‘ื™ืงื•ืจืช ืคื ื™ืžื™ืช. ื‘ื—ื•ื“ืฉื™ื ื™ื•ื ื™ ื•ืื•ื’ื•ืกื˜ 2018, ืžื™ื“ืข ืขืœ ื‘ืขื™ื•ืช ื ืžืกืจ ืœืื™ื ื˜ืœ ื’ื ืขืœ ื™ื“ื™ ื—ื•ืงืจื™ื ืขืฆืžืื™ื™ื, ื•ืœืื—ืจ ืžื›ืŸ ื‘ื•ืฆืขื” ื›ืžืขื˜ ืฉื ื” ืฉืœ ืขื‘ื•ื“ื” ืžืฉื•ืชืคืช ืขื ื™ืฆืจื ื™ื ื•ืžืคืชื—ื™ ืžืขืจื›ื•ืช ื”ืคืขืœื” ื›ื“ื™ ืœื–ื”ื•ืช ื•ืงื˜ื•ืจื™ ืชืงื™ืคื” ืืคืฉืจื™ื™ื ื•ืœืกืคืง ืชื™ืงื•ื ื™ื. ืžืขื‘ื“ื™ AMD ื•-ARM ืื™ื ื ืžื•ืฉืคืขื™ื ืžื”ื‘ืขื™ื”.

ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉื–ื•ื”ื•:

CVE-2018-12126 - MSBDS (Microarchitectural Store Buffer Data Sampling), ืฉื—ื–ื•ืจ ื”ืชื•ื›ืŸ ืฉืœ ืžืื’ืจื™ ืื—ืกื•ืŸ. ืžืฉืžืฉ ื‘ื”ืชืงืคืช Fallout. ื“ืจื’ืช ื”ืกื›ื ื” ื ืงื‘ืขืช ืœ-6.5 ื ืงื•ื“ื•ืช (CVSS);

CVE-2018-12127 - MLPDS (ื“ื’ื™ืžืช ื ืชื•ื ื™ ื˜ืขื™ื ื” ืžื™ืงืจื•-ืืจื›ื™ื˜ืงื˜ื•ื ื™ืช), ืฉื—ื–ื•ืจ ืชื•ื›ืŸ ื™ืฆื™ืืช ื”ื˜ืขื™ื ื”. ืžืฉืžืฉ ื‘ื”ืชืงืคืช RIDL. CVSS 6.5;

CVE-2018-12130 - MFBDS (ื“ื’ื™ืžืช ื ืชื•ื ื™ื ืฉืœ ืžื™ืœื•ื™ ืžืื’ืจ ืžื™ืงืจื•-ืืจื›ื™ื˜ืงื˜ื•ื ื™), ืฉื—ื–ื•ืจ ืชื•ื›ืŸ ืžืื’ืจ ืžื™ืœื•ื™. ืžืฉืžืฉ ื‘ื”ืชืงืคื•ืช ZombieLoad ื•-RIDL. CVSS 6.5;

CVE-2019-11091 - MDSUM (ืžื™ืงืจื•-ืืจื›ื™ื˜ืงื˜ื•ื ื™ ื ืชื•ื ื™ื ื“ื’ื™ืžืช ื–ื™ื›ืจื•ืŸ ืœื ื ื™ืชืŸ ืœืžื˜ืžื•ืŸ), ืฉื—ื–ื•ืจ ืฉืœ ืชื•ื›ืŸ ื–ื™ื›ืจื•ืŸ ื‘ืœืชื™ ื ื™ืชืŸ ืœืื—ืกื•ืŸ. ืžืฉืžืฉ ื‘ื”ืชืงืคืช RIDL. CVSS 3.8.

ืžืงื•ืจ: linux.org.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”