ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืžืขื‘ื“ื™ AMD ื•ืื™ื ื˜ืœ

AMD ื”ื•ื“ื™ืขื” ืขืœ ื‘ื™ื˜ื•ืœ 22 ืคื’ื™ืขื•ื™ื•ืช ื‘ื“ื•ืจ ื”ืจืืฉื•ืŸ, ื”ืฉื ื™ ื•ื”ืฉืœื™ืฉื™ ืฉืœ ืžืขื‘ื“ื™ ื”ืฉืจืชื™ื ืžืกื“ืจืช AMD EPYC, ืžื” ืฉืžืืคืฉืจ ืœืกื›ืŸ ืืช ืคืขื•ืœืชืŸ ืฉืœ ื˜ื›ื ื•ืœื•ื’ื™ื•ืช PSP (Platform Security Processor), SMU (System Management Unit) ื•- SEV (Secure Encrypted Virtualization) . 6 ื‘ืขื™ื•ืช ื–ื•ื”ื• ื‘-2020 ื•-16 ื‘-2021. ื‘ืžื”ืœืš ืžื—ืงืจ ืื‘ื˜ื—ื” ืคื ื™ืžื™ ื–ื•ื”ื• 11 ืคืจืฆื•ืช ืขืœ ื™ื“ื™ ืขื•ื‘ื“ื™ ื’ื•ื’ืœ, 6 ืขืœ ื™ื“ื™ ืื•ืจืงืœ ื•-5 ืขืœ ื™ื“ื™ ืžื™ืงืจื•ืกื•ืคื˜.

ืขืจื›ื•ืช ืžืขื•ื“ื›ื ื•ืช ืฉืœ ืงื•ืฉื—ื” ืฉืœ AGESA (AMD Generic Encapsulated Software Architecture) ืฉื•ื—ืจืจื• ืขื‘ื•ืจ ื™ืฆืจื ื™ ืฆื™ื•ื“ OEM, ื”ื—ื•ืกืžื•ืช ืืช ื”ืชืจื—ืฉื•ืชืŸ ืฉืœ ื‘ืขื™ื•ืช ื‘ืื•ืคืŸ ืขื•ืงืฃ. ื—ื‘ืจื•ืช ื›ืžื• HP, Dell, Supermicro ื•ืœื ื•ื‘ื• ื›ื‘ืจ ืคืจืกืžื• ืขื“ื›ื•ื ื™ BIOS ื•-UEFI ืขื‘ื•ืจ ืžืขืจื›ื•ืช ื”ืฉืจืช ืฉืœื”ืŸ.

4 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืžืกื•ื•ื’ื•ืช ื›ืžืกื•ื›ื ื•ืช (ืคืจื˜ื™ื ื˜ืจื ื ื—ืฉืคื•):

  • CVE-2020-12954 - ื”ื™ื›ื•ืœืช ืœืขืงื•ืฃ ืžื ื’ื ื•ื ื™ ื”ื’ื ืช SPI ROM ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ื”ื’ื“ืจื•ืช ืžืกื•ื™ืžื•ืช ืฉืœ ืขืจื›ืช ืฉื‘ื‘ื™ื ืคื ื™ืžื™ืช. ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืชื•ืงืฃ ืœื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื‘-SPI Flash ื›ื“ื™ ืœื”ืฆื™ื’ ืงื•ื“ ื–ื“ื•ื ื™ ืื• rootkits ืฉืื™ื ื ื ืจืื™ื ืœืžืขืจื›ืช.
  • CVE-2020-12961 - ืคื’ื™ืขื•ืช ื‘ืžืขื‘ื“ ื”-PSP (ืžืขื‘ื“ ืื‘ื˜ื—ื” AMD), ื”ืžืฉืžืฉืช ืœื”ืคืขืœืช ืกื‘ื™ื‘ื” ืžื‘ื•ื“ื“ืช ืžื•ื’ื ืช ืฉืื™ื ื” ื ื’ื™ืฉื” ืžืžืขืจื›ืช ื”ื”ืคืขืœื” ื”ืจืืฉื™ืช, ืžืืคืฉืจืช ืœืชื•ืงืฃ ืœืืคืก ื›ืœ ืจื™ืฉื•ื ืžืขื‘ื“ ืžื™ื•ื—ืก ื‘-SMN (ืžืขืจื›ืช ื ื™ื”ื•ืœ ืจืฉืช) ื•ืœืขืงื•ืฃ ื”ื’ื ืช SPI ROM.
  • CVE-2021-26331 - ืฉื’ื™ืื” ื‘ืชืช-ืžืขืจื›ืช SMU (System Management Unit) ื”ืžืฉื•ืœื‘ืช ื‘ืžืขื‘ื“, ื”ืžืฉืžืฉืช ืœื ื™ื”ื•ืœ ืฆืจื™ื›ืช ื—ืฉืžืœ, ืžืชื— ื•ื˜ืžืคืจื˜ื•ืจื”, ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ื—ืกืจ ื”ืจืฉืื•ืช ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืงื•ื“ ืขื ื”ืจืฉืื•ืช ื’ื‘ื•ื”ื•ืช.
  • CVE-2021-26335 - ืื™ืžื•ืช ื ืชื•ื ื™ ืงืœื˜ ืฉื’ื•ื™ ื‘ืžื˜ืขืŸ ื”ืงื•ื“ ืขื‘ื•ืจ ืžืขื‘ื“ ื”-PSP ืžืืคืฉืจ ืœื”ืฉืชืžืฉ ื‘ืขืจื›ื™ื ื ืฉืœื˜ื™ ืชื•ืงืฃ ื‘ืฉืœื‘ ืฉืœืคื ื™ ื‘ื“ื™ืงืช ื”ื—ืชื™ืžื” ื”ื“ื™ื’ื™ื˜ืœื™ืช ื•ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืฉืœ ื”ืงื•ื“ ืฉืœื”ื ื‘-PSP.

ื™ืฉ ืœืฆื™ื™ืŸ ื‘ื ืคืจื“ ื‘ื™ื˜ื•ืœ ืคื’ื™ืขื•ืช (CVE-2021-26334) ื‘ืขืจื›ืช ื”ื›ืœื™ื AMD ฮผProf, ืžืกื•ืคืงืช ื›ื•ืœืœ ืขื‘ื•ืจ Linux ื•-FreeBSD, ื•ืžืฉืžืฉืช ืœื ื™ืชื•ื— ื‘ื™ืฆื•ืขื™ื ื•ืฆืจื™ื›ืช ื—ืฉืžืœ. ื”ื‘ืขื™ื” ืงื™ื™ืžืช ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ ืฉืœ AMDPowerProfiler ื•ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ื—ืกืจ ื”ืจืฉืื•ืช ื›ื“ื™ ืœืงื‘ืœ ื’ื™ืฉื” ืœืจื™ืฉื•ืžื™ MSR (ืกืคืฆื™ืคื™ ื“ื’ื) Register) ื›ื“ื™ ืœืืจื’ืŸ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœืš ื‘ืจืžื” ืฉืœ ื˜ื‘ืขืช ื”ื”ื’ื ื” ื”ืืคืกื™ืช (ring-0). ื”ืคื’ื™ืขื•ืช ืชื•ืงื ื” ื‘-amduprof-3.4-502 ืขื‘ื•ืจ Linux ื•-AMDuProf-3.4.494 ืขื‘ื•ืจ Windows.

ื‘ื™ื ืชื™ื™ื, ืื™ื ื˜ืœ ืคืจืกืžื” ื“ื•ื—ื•ืช ืจื‘ืขื•ื ื™ื™ื ืขืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืžื•ืฆืจื™ื ืฉืœื”, ืžื”ืŸ ื‘ื•ืœื˜ื•ืช ื”ื‘ืขื™ื•ืช ื”ื‘ืื•ืช:

  • CVE-2021-0146 ื”ื™ื ืคื’ื™ืขื•ืช ื‘ืžืขื‘ื“ื™ Intel Pentium, Celeron ื•-Atom ืขื‘ื•ืจ ืžืขืจื›ื•ืช ื ื™ื™ื“ื•ืช ื•ืฉื•ืœื—ื ื•ืช ืขื‘ื•ื“ื” ื”ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืขื ื’ื™ืฉื” ืคื™ื–ื™ืช ืœืฆื™ื•ื“ ืœื”ืฉื™ื’ ื”ืกืœืžื” ืฉืœ ื”ืจืฉืื•ืช ืขืœ ื™ื“ื™ ื”ืคืขืœืช ืžืฆื‘ื™ ื ื™ืคื•ื™ ื‘ืื’ื™ื.
  • CVE-2021-0157, CVE-2021-0158 ื”ืŸ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืงื•ื“ ื”ื™ื™ื—ื•ืก ืฉืœ ื”-BIOS ืฉืกื•ืคืง ืœืืชื—ื•ืœ ืฉืœ ืžืขื‘ื“ื™ Intel Xeon (E/W/Scalable), Core (7/10/11gen), Celeron (N) ื•-Pentium Silver. ื”ื‘ืขื™ื•ืช ื ื’ืจืžื•ืช ืขืœ ื™ื“ื™ ืื™ืžื•ืช ืงืœื˜ ืฉื’ื•ื™ ืื• ื‘ืงืจืช ื–ืจื™ืžื” ืฉื’ื•ื™ื” ื‘ืงื•ืฉื—ืช ื”-BIOS ื•ืžืืคืฉืจื•ืช ื”ืกืœืžื” ืฉืœ ื”ืจืฉืื•ืช ื›ืืฉืจ ื’ื™ืฉื” ืžืงื•ืžื™ืช ื–ืžื™ื ื”.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”