ืคื’ื™ืขื•ื™ื•ืช ื‘ื™ื™ืฉื•ื ื˜ื›ื ื•ืœื•ื’ื™ื™ืช AMD SEV ื”ืžืฉืคื™ืขื•ืช ืขืœ ืžืขื‘ื“ื™ AMD EPYC

AMD ื”ื–ื”ื™ืจื” ื›ื™ ื–ื•ื”ื• ืฉืชื™ ืฉื™ื˜ื•ืช ืชืงื™ืคื” ืฉื™ื›ื•ืœื•ืช ืœืขืงื•ืฃ ืืช ืžื ื’ื ื•ืŸ ื”ืื‘ื˜ื—ื” AMD SEV (Secure Encrypted Virtualization). ื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ืขืœ ื”ื“ื•ืจ ื”ืจืืฉื•ืŸ, ื”ืฉื ื™ ื•ื”ืฉืœื™ืฉื™ ืฉืœ ืžืขื‘ื“ื™ AMD EPYC (ื”ืžื‘ื•ืกืกื™ื ืขืœ ื”ืžื™ืงืจื•-ืืจื›ื™ื˜ืงื˜ื•ืจื” Zen1 - Zen3), ื•ื›ืŸ ืขืœ ืžืขื‘ื“ื™ AMD EPYC ืžืฉื•ื‘ืฆื™ื.

AMD SEV ื‘ืจืžืช ื”ื—ื•ืžืจื” ืžืกืคืงืช ื”ืฆืคื ื” ืฉืงื•ืคื” ืฉืœ ื–ื™ื›ืจื•ืŸ ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช, ืฉื‘ื” ืจืง ืœืžืขืจื›ืช ื”ืื•ืจื—ืช ื”ื ื•ื›ื—ื™ืช ื™ืฉ ื’ื™ืฉื” ืœื ืชื•ื ื™ื ืžืคื•ืขื ื—ื™ื, ื•ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ืื—ืจื•ืช ื•ื”-Hypervisor ืžืงื‘ืœื™ื ืกื˜ ืžื•ืฆืคืŸ ืฉืœ ื ืชื•ื ื™ื ื›ืืฉืจ ืžื ืกื™ื ืœื’ืฉืช ืœื–ื™ื›ืจื•ืŸ ื–ื”. ื”ื‘ืขื™ื•ืช ืฉื–ื•ื”ื• ืžืืคืฉืจื•ืช ืœืชื•ืงืฃ ืขื ื–ื›ื•ื™ื•ืช ื ื™ื”ื•ืœ ื‘ืฉืจืช ื•ืฉืœื™ื˜ื” ื‘-hypervisor ืœืขืงื•ืฃ ืžื’ื‘ืœื•ืช AMD SEV ื•ืœื”ืคืขื™ืœ ืืช ื”ืงื•ื“ ืฉืœื”ื ื‘ื”ืงืฉืจ ืฉืœ ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ืžื•ื’ื ื•ืช.

ื‘ืขื™ื•ืช ืฉื–ื•ื”ื•:

  • CVE-2021-26311 (ืžืชืงืคื” ืœื ืžื•ื’ืฉืช) - ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ืฉื™ื ื•ื™ ืกื“ืจ ื‘ืœื•ืงื™ ื”ื–ื™ื›ืจื•ืŸ ื‘ืžืจื—ื‘ ื”ื›ืชื•ื‘ื•ืช ืฉืœ ื”ืžืขืจื›ืช ื”ืื•ืจื—ืช, ืื ื™ืฉ ืœืš ืฉืœื™ื˜ื” ืขืœ ื”ื”ื™ืคืจื•ื•ื™ื–ืจ, ืชื•ื›ืœ ืœื”ืคืขื™ืœ ืืช ื”ืงื•ื“ ืฉืœืš ื‘ืžื›ื•ื ื” ื”ื•ื™ืจื˜ื•ืืœื™ืช ื”ืื•ืจื—ืช, ืœืžืจื•ืช ื”ืฉื™ืžื•ืฉ ืฉืœ ื”ื’ื ืช AMD SEV/SEV-ES. ื—ื•ืงืจื™ื ื”ื›ื™ื ื• ืื‘ ื˜ื™ืคื•ืก ืฉืœ ื ื™ืฆื•ืœ ืื•ื ื™ื‘ืจืกืœื™ ืฉืžืงื‘ืฅ ืžื—ื“ืฉ ื‘ืœื•ืงื™ื ืฉืœ UEFI ื˜ืขื•ืŸ ื•ืžืฉืชืžืฉ ื‘ื˜ื›ื ื™ืงื•ืช ืชื›ื ื•ืช ืžื•ื ื—ื” ื”ื—ื–ืจื” (ROP) ื›ื“ื™ ืœืืจื’ืŸ ืืช ื”ื‘ื™ืฆื•ืข ืฉืœ ืงื•ื“ ืฉืจื™ืจื•ืชื™.
  • ื” ื”ืขื‘ืจืช ื”ืฉืœื™ื˜ื” ืœืงื•ื“ ื–ื”. ื”ืฉื™ื˜ื” ืžืืคืฉืจืช ืœืงื‘ืœ ืฉืœื™ื˜ื” ืžืœืื” ืขืœ ืžืขืจื›ืช ื”ืื•ืจื—ื™ื ื”ืžื•ื’ื ืช ื•ืœื—ืœืฅ ืžืžื ื” ื ืชื•ื ื™ื ื—ืกื•ื™ื™ื.

ื›ื“ื™ ืœื”ืชืžื•ื“ื“ ืขื ืฉื™ื˜ื•ืช ื”ื”ืชืงืคื” ื”ืžื•ืฆืขื•ืช, AMD ื”ื›ื™ื ื” ืืช ื”ืจื—ื‘ื” SEV-SNP (Secure Nested Paging), ื”ื–ืžื™ื ื” ื›ืขื“ื›ื•ืŸ ืงื•ืฉื—ื” ืœื“ื•ืจ ื”ืฉืœื™ืฉื™ ืฉืœ ืžืขื‘ื“ื™ AMD EPYC ื•ืžื‘ื˜ื™ื—ื” ืคืขื•ืœื” ืžืื•ื‘ื˜ื—ืช ืฉืœ ื˜ื‘ืœืื•ืช ื“ืคื™ ื–ื™ื›ืจื•ืŸ ืžืงื•ื ื ื•ืช. ื‘ื ื•ืกืฃ ืœื”ืฆืคื ืช ื–ื™ื›ืจื•ืŸ ื›ืœืœื™ืช ื•ืกื™ื•ืžืช SEV-ES (ืžืฆื‘ ืžื•ืฆืคืŸ) ื”ืžื’ื ื” ืขืœ ืื•ื’ืจื™ CPU, SEV-SNP ืžืกืคืง ื”ื’ื ืช ืฉืœืžื•ืช ื–ื™ื›ืจื•ืŸ ื ื•ืกืคืช ืฉื™ื›ื•ืœื” ืœืขืžื•ื“ ื‘ืคื ื™ ื”ืชืงืคื•ืช ืฉืœ ื”ื™ืคืจื•ื•ื™ื–ื•ืจื™ื ื•ืžืกืคืงืช ื”ื’ื ื” ื ื•ืกืคืช ืžืคื ื™ ื”ืชืงืคื•ืช ืฉืœ ืขืจื•ืฅ ืฆื“ื“ื™.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”