{"id":114955,"date":"2024-04-09T21:31:00","date_gmt":"2024-04-09T19:31:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/novyj-variant-ataki-bhi-na-cpu-intel-pozvolyayushhij-obojti-zashhitu-v-yadre-linux"},"modified":"2024-04-09T21:31:00","modified_gmt":"2024-04-09T19:31:00","slug":"novyj-variant-ataki-bhi-na-cpu-intel-pozvolyayushhij-obojti-zashhitu-v-yadre-linux","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/novyj-variant-ataki-bhi-na-cpu-intel-pozvolyayushhij-obojti-zashhitu-v-yadre-linux","title":{"rendered":"Nj\u00eb variant i ri i sulmit BHI ndaj CPU-ve Intel, q\u00eb mund\u00ebson anashkalimin e mbrojtjes n\u00eb kernelin Linux","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nj\u00eb grup k\u00ebrkuesish nga Universiteti i Lir\u00eb i Amsterdamit zbuloi nj\u00eb metod\u00eb t\u00eb re sulmi \"Native BHI\" (CVE-2024-2201), e cila lejon q\u00eb n\u00eb sistemet me procesor\u00eb Intel t\u00eb p\u00ebrcaktohet p\u00ebrmbajtja e memories s\u00eb b\u00ebrtham\u00ebs Linux gjat\u00eb ekzekutimit t\u00eb nj\u00eb exploiti n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit. N\u00eb rastin e aplikimit t\u00eb sulmit n\u00eb sistemet e virtualizimit, sulmuesi nga sistemet e mysafir\u00ebve mund t\u00eb p\u00ebrcaktoj\u00eb p\u00ebrmbajtjen e memories s\u00eb ambientit t\u00eb hostit ose sistemeve t\u00eb tjera t\u00eb mysafir\u00ebve.     <\/p>\n<p>Metoda Native BHI ofron nj\u00eb teknik\u00eb t\u00eb ndryshme p\u00ebr shfryt\u00ebzimin e dob\u00ebsis\u00eb BHI (Branch History Injection, CVE-2022-0001), e cila shmang m\u00ebnyrat e mbrojtjes t\u00eb zbatuara m\u00eb par\u00eb. Metoda e sulmit BHI e propozuar n\u00eb vitin 2022 p\u00ebrfshinte shfryt\u00ebzimin e dob\u00ebsis\u00eb n\u00eb kuad\u00ebr t\u00eb nj\u00eb niveli privilegji, p\u00ebr \u00e7ka eksploiti bazohej n\u00eb ekzekutimin e nj\u00eb programi eBPF t\u00eb ngarkuar nga p\u00ebrdoruesi n\u00eb b\u00ebrtham\u00eb. P\u00ebr t'u bllokuar dob\u00ebsia, ishte e mjaftueshme t\u00eb kufizohej q \u0434\u043e\u0441\u0442\u0443\u043f\u0430 p\u00ebr ekzekutimin e kodit eBPF p\u00ebr p\u00ebrdoruesit e zakonsh\u00ebm.     <\/p>\n<p>Metoda e re Native BHI nuk k\u00ebrkon akses n\u00eb eBPF dhe lejon kryerjen e nj\u00eb sulmi nga nj\u00eb p\u00ebrdorues pa privilegje n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit. Metoda bazohet n\u00eb ekzekutimin e gadgjeteve ekzistuese n\u00eb kodin e b\u00ebrtham\u00ebs \u2014 sekuencave komandash q\u00eb \u00e7ojn\u00eb n\u00eb ekzekutimin spekulativ t\u00eb instrukcioneve. P\u00ebr t\u00eb k\u00ebrkuar n\u00eb b\u00ebrthama gadgjete t\u00eb p\u00ebrshtatshme, \u00ebsht\u00eb zhvilluar nj\u00eb mjet i ve\u00e7ant\u00eb InSpectre Gadget, i cili gjat\u00eb analiz\u00ebs s\u00eb b\u00ebrthamas 6.6-rc4 identifikoi 1511 gadgjete Spectre dhe 2105 gadgjete ndihm\u00ebs p\u00ebr menaxhim.      <center><img decoding=\"async\" alt=\"Nj\u00eb variant i ri i sulmit BHI ndaj CPU-ve Intel, q\u00eb mund\u00ebson anashkalimin e mbrojtjes n\u00eb kernelin Linux\" src=\"\/wp-content\/uploads\/2024\/04\/93734194d4b9a6cfe5a62d7d73915d83.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>Bazuar n\u00eb gadgetet e gjetura, hulumtuesit kan\u00eb p\u00ebrgatitur nj\u00eb eksploit q\u00eb jep mund\u00ebsin\u00eb p\u00ebr t\u00eb nxjerr\u00eb nga bufferat e b\u00ebrtham\u00ebs nj\u00eb varg me hashin e fjal\u00ebkalimit t\u00eb p\u00ebrdoruesit root, t\u00eb ngarkuar nga skedari \/etc\/shadow. Shpejt\u00ebsia e nxjerrjes s\u00eb t\u00eb dh\u00ebnave nga memoria e b\u00ebrtham\u00ebs \u00ebsht\u00eb af\u00ebrsisht 3.5 Kb n\u00eb sekond\u00eb.      <center>  <div class=\"youtube-placeholder\" data-id=\"24HcE1rDMdo\" onclick=\"loadVideo(this)\">\r\n        <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/24HcE1rDMdo\/hqdefault.jpg\" alt=\"Luaj videon\" loading=\"lazy\" width=\"480\" height=\"360\" style=\"width:100%;height:auto;\">\r\n        <div class=\"play-button\"><\/div>\r\n    <\/div><\/center>      <\/p>\n<p>Metoda BHI \u00ebsht\u00eb nj\u00eb variant i zgjeruar i sulmit Spectre-v2, n\u00eb t\u00eb cilin p\u00ebr t\u00eb anashkaluar mbrojtjen e shtuar (Intel eIBRS dhe Arm CSV2) dhe p\u00ebr t\u00eb organizuar rrjedhjen e t\u00eb dh\u00ebnave p\u00ebrdoret z\u00ebvend\u00ebsimi i vlerave n\u00eb bufferin e historis\u00eb globale t\u00eb kalimeve (Branch History Buffer), i p\u00ebrdorur n\u00eb CPU p\u00ebr t\u00eb p\u00ebrmir\u00ebsuar sakt\u00ebsin\u00eb e parashikimit t\u00eb kalimeve duke marr\u00eb parasysh historin\u00eb e kalimeve t\u00eb m\u00ebparshme. Gjat\u00eb sulmit, p\u00ebrmes manipulimeve me historin\u00eb e kalimeve krijohen kushte p\u00ebr parashikimin e gabuar t\u00eb kalimit dhe ekzekutimin spekulativ t\u00eb instrukcioneve t\u00eb nevojshme, rezultati i t\u00eb cilave mbetet n\u00eb cache.    <\/p>\n<p>Dallimet nga sulmi Spectre-v2 p\u00ebrfshijn\u00eb p\u00ebrdorimin e nj\u00eb tamponi me histori t\u00eb kalimeve (Branch History Buffer) n\u00eb vend t\u00eb tamponit t\u00eb parashikimit t\u00eb deg\u00ebve (Branch Target Buffer). P\u00ebr t\u00eb nxjerr\u00eb t\u00eb dh\u00ebna nga memoria, sulmuesi duhet t\u00eb krijoj\u00eb kushte t\u00eb tilla q\u00eb, kur kryhet nj\u00eb operacion spekulativ, adresa do t\u00eb merret nga nj\u00eb zon\u00eb q\u00eb duhet t\u00eb p\u00ebrcaktohet. Pas kryerjes s\u00eb kalimit spekulativ t\u00eb t\u00eb dh\u00ebnave, adresa e lexuar nga memoria mbetet n\u00eb cache, pas s\u00eb cil\u00ebs mund t\u00eb p\u00ebrdoren nj\u00eb nga metodat p\u00ebr t\u00eb p\u00ebrcaktuar p\u00ebrmbajtjen e caches n\u00eb baz\u00eb t\u00eb analiz\u00ebs s\u00eb ndryshimit t\u00eb koh\u00ebs s\u00eb qasjes n\u00eb t\u00eb dh\u00ebnat e cache-uar dhe jo t\u00eb cache-uar.     <\/p>\n<p>Sulmimi Native BHI nuk mbron p\u00ebrdorimin e instrukcioneve Intel IBT (Indirect Branch Tracking) dhe mekanizmi hibrid i mbrojtjes s\u00eb rrjedh\u00ebs s\u00eb ekzekutimit FineIBT t\u00eb implementuar n\u00eb b\u00ebrthamat Linux, i cili kombinon p\u00ebrdorimin e instrukcioneve harduerike IBT dhe mbrojtjen software kCFI (kernel Control Flow Integrity) p\u00ebr t\u00eb bllokuar shkeljen e rendit normal t\u00eb ekzekutimit (control flow). FineIBT lejon ekzekutimin p\u00ebrmes nj\u00eb kalimi indirekt vet\u00ebm n\u00eb rast se kalimi \u00ebsht\u00eb n\u00eb nj\u00eb instrukcion ENDBR, i vendosur n\u00eb fillim t\u00eb funksionit. P\u00ebr m\u00eb tep\u00ebr (n\u00eb analogji me mekanizmin kCFI), pas k\u00ebsaj, kryhet nj\u00eb verifikim i hashes q\u00eb garanton t\u00eb pandryshueshm\u00ebrin\u00eb e treguesve.     <\/p>\n<p>P\u00ebr mbrojtje ndaj variantit t\u00eb ri t\u00eb sulmit, n\u00eb b\u00ebrtham\u00ebn Linux \u00ebsht\u00eb shtuar nj\u00eb ndryshim me implementimin e nj\u00eb modaliteti t\u00eb ri mbrojt\u00ebs, i cili p\u00ebrdor burime mbrojt\u00ebse harduerike t\u00eb propozuara nga Intel (BHI_DIS_S) ose nj\u00eb mbrojtje alternativ\u00eb software, e cila \u00ebsht\u00eb implementuar p\u00ebr mbrojtjen e hipervizorit. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/vps\/abuzoustojchivye-vps\/\"   title=\"KVM\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"4389\">KVM<\/a>. Zhvilluesit e hipervizorit Xen gjithashtu l\u00ebshuan nj\u00eb korrigjim q\u00eb bazohet n\u00eb p\u00ebrdorimin e modalitetit BHI_DIS_S, duke kufizuar parashikimet n\u00eb baz\u00eb t\u00eb historis\u00eb s\u00eb kalimeve. Mb\u00ebshtetje p\u00ebr BHI_DIS_S \u00ebsht\u00eb e disponueshme n\u00eb procesor\u00ebt, duke filluar nga Intel Alder Lake, si dhe CPU server, duke filluar nga Intel Sapphire Rapids. Ka dhe nj\u00eb mod t\u00eb mbrojtjes software, i cili bazohet n\u00eb p\u00ebrdorimin e sekuencave p\u00ebr pastrimin e tamponit t\u00eb historis\u00eb s\u00eb kalimeve, por ai \u00e7on n\u00eb nj\u00eb r\u00ebnie m\u00eb t\u00eb dukshme t\u00eb performanc\u00ebs.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60963\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u0410\u043c\u0441\u0442\u0435\u0440\u0434\u0430\u043c\u0441\u043a\u043e\u0433\u043e \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043d\u043e\u0432\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0430\u0442\u0430\u043a\u0438 &#171;Native BHI&#187; (CVE-2024-2201), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0439 \u043d\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u0441 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u0430\u043c\u0438 Intel \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u043f\u0430\u043c\u044f\u0442\u0438 \u044f\u0434\u0440\u0430 Linux \u043f\u0440\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0438 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u0430 \u0432 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f. \u0412 \u0441\u043b\u0443\u0447\u0430\u0435 \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043a \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438, \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u0438\u0437 \u0433\u043e\u0441\u0442\u0435\u0432\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u043c\u043e\u0436\u0435\u0442 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u043f\u0430\u043c\u044f\u0442\u0438 \u0445\u043e\u0441\u0442-\u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f \u0438\u043b\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u0433\u043e\u0441\u0442\u0435\u0432\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c. \u041c\u0435\u0442\u043e\u0434 Native BHI \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u0435\u0442 \u0438\u043d\u0443\u044e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":114956,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-114955","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u0410\u043c\u0441\u0442\u0435\u0440\u0434\u0430\u043c\u0441\u043a\u043e\u0433\u043e \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043d\u043e\u0432\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0430\u0442\u0430\u043a\u0438 &quot;Native BHI&quot; (CVE-2024-2201), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0439 \u043d\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u0441 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u0430\u043c\u0438 Intel \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u043f\u0430\u043c\u044f\u0442\u0438 \u044f\u0434\u0440\u0430 Linux \u043f\u0440\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/novyj-variant-ataki-bhi-na-cpu-intel-pozvolyayushhij-obojti-zashhitu-v-yadre-linux\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 BHI \u043d\u0430 CPU Intel, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0439 \u043e\u0431\u043e\u0439\u0442\u0438 \u0437\u0430\u0449\u0438\u0442\u0443 \u0432 \u044f\u0434\u0440\u0435 Linux | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u0410\u043c\u0441\u0442\u0435\u0440\u0434\u0430\u043c\u0441\u043a\u043e\u0433\u043e \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043d\u043e\u0432\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0430\u0442\u0430\u043a\u0438 &quot;Native BHI&quot; (CVE-2024-2201), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0439 \u043d\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u0441 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u0430\u043c\u0438 Intel \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u043f\u0430\u043c\u044f\u0442\u0438 \u044f\u0434\u0440\u0430 Linux \u043f\u0440\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/novyj-variant-ataki-bhi-na-cpu-intel-pozvolyayushhij-obojti-zashhitu-v-yadre-linux\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-04-09T19:31:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-04-09T19:31:00+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Nj\u00eb variant i ri sulmi BHI mbi CPU Intel, i cili lejon kalimin e mbrojtjes n\u00eb b\u00ebrtham\u00ebn Linux | ProHoster","description":"Nj\u00eb grup studiuesish nga Universiteti i Lir\u00eb i Amsterdamit zbuloi nj\u00eb metod\u00eb t\u00eb re sulmi \"Native BHI\" (CVE-2024-2201), e cila lejon n\u00eb sistemet me procesor\u00eb Intel t\u00eb p\u00ebrcaktoj\u00eb p\u00ebrmbajtjen e memories s\u00eb b\u00ebrtham\u00ebs Linux.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/novyj-variant-ataki-bhi-na-cpu-intel-pozvolyayushhij-obojti-zashhitu-v-yadre-linux","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 BHI \u043d\u0430 CPU Intel, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0439 \u043e\u0431\u043e\u0439\u0442\u0438 \u0437\u0430\u0449\u0438\u0442\u0443 \u0432 \u044f\u0434\u0440\u0435 Linux | ProHoster","og:description":"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u0410\u043c\u0441\u0442\u0435\u0440\u0434\u0430\u043c\u0441\u043a\u043e\u0433\u043e \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043d\u043e\u0432\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0430\u0442\u0430\u043a\u0438 &quot;Native BHI&quot; (CVE-2024-2201), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0439 \u043d\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u0441 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u0430\u043c\u0438 Intel \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u043f\u0430\u043c\u044f\u0442\u0438 \u044f\u0434\u0440\u0430 Linux \u043f\u0440\u0438.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/novyj-variant-ataki-bhi-na-cpu-intel-pozvolyayushhij-obojti-zashhitu-v-yadre-linux","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-04-09T19:31:00+00:00","article:modified_time":"2024-04-09T19:31:00+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"114955","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 21:54:46","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-22 21:54:46","updated":"2026-01-22 21:54:46","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/114955","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=114955"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/114955\/revisions"}],"predecessor-version":[{"id":164266,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/114955\/revisions\/164266"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/114956"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=114955"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=114955"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=114955"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}