Intel yakaburitsa ruzivo nezve kirasi nyowani yekusagadzikana

Intel yakaburitsa ruzivo nezve kirasi nyowani yekusagadzikana muma processors ayo - MDS (Microarchitectural Data Sampling). Kufanana nekurwiswa kweSpecter kwakapfuura, nyaya nyowani dzinogona kukonzeresa kuburitswa kwedata revaridzi kubva kune inoshanda sisitimu, chaiwo muchina, uye maitiro ekunze. Zvinonzi matambudziko akatanga kuzivikanwa neIntel vashandi pamwe nevabatsiri panguva yekuongorora kwemukati. MunaChikumi naNyamavhuvhu 2018, ruzivo rwematambudziko rwakapihwawo kuIntel nevaongorori vakazvimiririra, mushure mezvo rinenge gore rekushanda pamwe chete rakaitwa nevagadziri uye vanogadzira masisitimu ekushandisa kuti vaone zvinogona kurwisa mavector uye kuendesa zvigadziriso. AMD uye ARM processors haina kukanganiswa nedambudziko.

Zvinozivikanwa vulnerabilities:

CVE-2018-12126 - MSBDS (Microarchitectural Store Buffer Data Sampling), kudzoreredza zviri mukati mekuchengetedza mabhafa. Inoshandiswa muFallout kurwisa. Iyo dhigirii yengozi inotemerwa kuve 6.5 mapoinzi (CVSS);

CVE-2018-12127 - MLPDS (Microarchitectural Load Port Data Sampling), kudzoreredza kwemukati mekutakura zvinhu. Inoshandiswa mukurwisa kweRIDL. CVSS 6.5;

CVE-2018-12130 - MFBDS (Microarchitectural Zadza Buffer Data Sampling), kudzoreredza kwekuzadza buffer zviri mukati. Inoshandiswa muZombieLoad uye RIDL kurwisa. CVSS 6.5;

CVE-2019-11091 - MDSUM (Microarchitectural Data Sampling Uncacheable Memory), kudzoreredza kwezvisingaverengeki ndangariro zviri mukati. Inoshandiswa mukurwisa kweRIDL. CVSS 3.8.

Source: linux.org.ru

Voeg