Retbleed ๋ณดํ˜ธ๋กœ ์ธํ•œ ์ปค๋„ 5.19์˜ ์‹ฌ๊ฐํ•œ ์„ฑ๋Šฅ ์ €ํ•˜

VMware ์—”์ง€๋‹ˆ์–ด๊ฐ€ Linux 5.19 ์ปค๋„์„ ์‚ฌ์šฉํ•˜๋ฉด์„œ Linux ์ปค๋„ ์ปค๋ฎค๋‹ˆํ‹ฐ์— ์ƒ๋‹นํ•œ ์„ฑ๋Šฅ ์ €ํ•˜๋ฅผ ์ดˆ๋ž˜ํ–ˆ์Šต๋‹ˆ๋‹ค. VMware ESXi ํ•˜์ดํผ๋ฐ”์ด์ € ํ™˜๊ฒฝ์—์„œ 5.19 ์ปค๋„์„ ์‹คํ–‰ํ•˜๋Š” VM์„ ํ…Œ์ŠคํŠธํ•œ ๊ฒฐ๊ณผ, ๋™์ผํ•œ ๊ตฌ์„ฑ์—์„œ 70 ์ปค๋„์„ ์‹คํ–‰ํ•˜๋Š” ๊ฒฝ์šฐ๋ณด๋‹ค ์ปดํ“จํŒ… ์„ฑ๋Šฅ์ด 30%, ๋„คํŠธ์›Œํ‚น ์„ฑ๋Šฅ์ด 13%, ์Šคํ† ๋ฆฌ์ง€ ์„ฑ๋Šฅ์ด 5.18% ์ €ํ•˜๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

์„ฑ๋Šฅ ์ €ํ•˜์˜ ์›์ธ์€ Spectre v2 ๋ณดํ˜ธ ์ฝ”๋“œ(spectre_v2=ibrs)์˜ ๋ณ€๊ฒฝ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค. ์ด ์ฝ”๋“œ๋Š” IBRS(Enhanced Indirect Branch Restricted Speculation) ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๊ตฌํ˜„๋˜์—ˆ์œผ๋ฉฐ, ์ด๋ฅผ ํ†ตํ•ด ์ธํ„ฐ๋ŸฝํŠธ ์ฒ˜๋ฆฌ, ์‹œ์Šคํ…œ ํ˜ธ์ถœ ๋ฐ ์ปจํ…์ŠคํŠธ ์Šค์œ„์น˜ ์ค‘์— ํˆฌ๊ธฐ์  ๋ช…๋ น์–ด ์‹คํ–‰์— ๋Œ€ํ•œ ์ ์‘ํ˜• ๊ถŒํ•œ ๋ถ€์—ฌ ๋ฐ ๋น„ํ™œ์„ฑํ™”๊ฐ€ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ์ด ๋ณดํ˜ธ ๊ธฐ๋Šฅ์€ ์ตœ๊ทผ ๋ฐœ๊ฒฌ๋œ CPU์˜ ํˆฌ๊ธฐ์  ๊ฐ„์ ‘ ๋ถ„๊ธฐ ์‹คํ–‰ ๋ฉ”์ปค๋‹ˆ์ฆ˜์˜ Retbleed ์ทจ์•ฝ์ ์„ ์ฐจ๋‹จํ•˜๊ธฐ ์œ„ํ•ด ํ™œ์„ฑํ™”๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด ์ทจ์•ฝ์ ์€ ์ปค๋„ ๋ฉ”๋ชจ๋ฆฌ์—์„œ ์ •๋ณด๋ฅผ ์ถ”์ถœํ•˜๊ฑฐ๋‚˜ ํ˜ธ์ŠคํŠธ ์‹œ์Šคํ…œ์„ ๊ณต๊ฒฉํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ฐ€์ƒ ๊ธฐ๊ธฐ๋ณดํ˜ธ ๊ธฐ๋Šฅ์„ ๋น„ํ™œ์„ฑํ™”(spectre_v2=off)ํ•˜๋ฉด ์„ฑ๋Šฅ์ด ์ด์ „ ์ˆ˜์ค€์œผ๋กœ ๋ณต๊ตฌ๋ฉ๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : opennet.ru