{"id":33659,"date":"2019-10-31T21:53:59","date_gmt":"2019-10-31T18:53:59","guid":{"rendered":"https:\/\/prohoster.info\/blog\/predstavlen-novyj-klass-uyazvimostej-v-protsessorah-intel\/"},"modified":"2019-10-31T21:53:59","modified_gmt":"2019-10-31T18:53:59","slug":"predstavlen-novyj-klass-uyazvimostej-v-protsessorah-intel","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/predstavlen-novyj-klass-uyazvimostej-v-protsessorah-intel","title":{"rendered":"Klas i ri i vulnerabiliteteve n\u00eb procesor\u00ebt Intel","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Kompania Intel <noindex><a rel=\"nofollow\" href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00233.html\">publikoi<\/a><\/noindex> informacion mbi t\u00eb re <noindex><a rel=\"nofollow\" href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/architecture-and-technology\/mds.html\">klas\u00ebn e dob\u00ebsive<\/a><\/noindex> n\u00eb procesor\u00ebt e tij &#8212; <noindex><a rel=\"nofollow\" href=\"https:\/\/mdsattacks.com\/\">MDS<\/a><\/noindex> (Sampling i t\u00eb Dh\u00ebnave Mikroarkitekturale). Si\u00e7 jan\u00eb shqet\u00ebsimet e kaluara t\u00eb klas\u00ebs Spectre, problemet e reja mund t\u00eb \u00e7ojn\u00eb n\u00eb rrjedhjen e t\u00eb dh\u00ebnave t\u00eb ndjeshme nga sistemi operativ, makinat virtuale dhe procese t\u00eb tjera. K\u00ebto \u00e7\u00ebshtje u identifikuan fillimisht nga punonj\u00ebsit dhe partner\u00ebt e Intel n\u00eb nj\u00eb auditim t\u00eb brendsh\u00ebm, pas t\u00eb cilit informacioni mbi probleme t\u00eb ngjashme n\u00eb Intel u b\u00eb i njohur p\u00ebr k\u00ebrkuesit e pavarur. Procesor\u00ebt AMD dhe ARM nuk jan\u00eb t\u00eb ndjesh\u00ebm ndaj k\u00ebsaj probleme.<\/p>\n<p>Duke u bazuar n\u00eb problemet e identifikuara nga k\u00ebrkuesit nga Universiteti Teknik i Grazit (Austria), <noindex><a rel=\"nofollow\" href=\"https:\/\/cpu.fail\/\">u zhvillua<\/a><\/noindex> disa sulme praktike p\u00ebrmes kanaleve an\u00ebsore:<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/zombieloadattack.com\/\">ZombieLoad<\/a><\/noindex>  (<noindex><a rel=\"nofollow\" href=\"https:\/\/zombieloadattack.com\/zombieload.pdf\">PDF<\/a><\/noindex>) &#8212; mund\u00ebson nxjerrjen e informacionit t\u00eb ndjesh\u00ebm nga procese t\u00eb tjera, sistemi operativ, makina virtuale dhe enklava t\u00eb mbrojtura (TEE, Ambienti i Ekzekutimit t\u00eb Besuesh\u00ebm). P\u00ebr shembull, \u00ebsht\u00eb demonstruar mund\u00ebsia p\u00ebr t\u00eb p\u00ebrcaktuar historin\u00eb e hapjes s\u00eb faqeve n\u00eb Tor browser, t\u00eb drejtuar n\u00eb nj\u00eb makin\u00eb virtuale tjet\u00ebr, si dhe p\u00ebr t\u00eb p\u00ebrcaktuar \u00e7el\u00ebsat e qasjes dhe fjal\u00ebkalimet e p\u00ebrdorura n\u00eb aplikacione;\n<p><center><br \/>\n<video controls=\"\" style=\"width: 720px; max-width:100%\" poster=\"https:\/\/zombieloadattack.com\/public\/images\/demo.jpg\"  src=\"https:\/\/zombieloadattack.com\/public\/videos\/demo_720.mp4\"><source src=\"https:\/\/zombieloadattack.com\/public\/videos\/demo_720.mp4\" type=\"video\/mp4\" label=\"720p\"><\/video><\/center><\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/mdsattacks.com\/\">, por ndan burimin e rrjedhjes.<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/mdsattacks.com\/files\/ridl.pdf\">PDF<\/a><\/noindex>) &#8212; lejon organizimin e rrjedhjes s\u00eb informacionit midis hap\u00ebsirave t\u00eb ndryshme t\u00eb izoluara n\u00eb procesor\u00ebt Intel, si\u00e7 jan\u00eb buferat e mbushjes, buferat e ruajtjes dhe portet e ngarkimit. Shembuj t\u00eb zhvillimit t\u00eb sulmeve jan\u00eb treguar p\u00ebr organizimin e rrjedhjeve nga procese t\u00eb tjera, sistemi operativ, makina virtuale dhe enklava t\u00eb mbrojtura. P\u00ebr shembull, \u00ebsht\u00eb treguar se si t\u00eb dihet p\u00ebrmbajtja e hash-it t\u00eb fjal\u00ebkalimit root nga \/etc\/shadow gjat\u00eb p\u00ebrpjekjeve periodike t\u00eb autentifikimit (sulmi zgjati 24 or\u00eb);\n<p><center><div class=\"youtube-placeholder\" data-id=\"JXPebaGY8RA\" onclick=\"loadVideo(this)\">\r\n        <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/JXPebaGY8RA\/hqdefault.jpg\" alt=\"Luaj videon\" loading=\"lazy\" width=\"480\" height=\"360\" style=\"width:100%;height:auto;\">\r\n        <div class=\"play-button\"><\/div>\r\n    <\/div><\/center><\/p>\n<p>P\u00ebr m\u00eb tep\u00ebr, \u00ebsht\u00eb treguar nj\u00eb shembull i kryerjes s\u00eb sulmit duke p\u00ebrdorur JavaScript dhe WebAssembly gjat\u00eb hapjes s\u00eb nj\u00eb faqeje t\u00eb d\u00ebmshme n\u00eb motorin SpiderMonkey (n\u00eb shfletuesit modern\u00eb, nj\u00eb sulm i till\u00eb \u00ebsht\u00eb shum\u00eb i pamundur p\u00ebr shkak t\u00eb kufizimeve t\u00eb sakt\u00ebsis\u00eb s\u00eb or\u00ebs dhe masave p\u00ebr mbrojtjen nga Spectre);<\/p>\n<p><center><div class=\"youtube-placeholder\" data-id=\"KAgoDQmod1Y\" onclick=\"loadVideo(this)\">\r\n        <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/KAgoDQmod1Y\/hqdefault.jpg\" alt=\"Luaj videon\" loading=\"lazy\" width=\"480\" height=\"360\" style=\"width:100%;height:auto;\">\r\n        <div class=\"play-button\"><\/div>\r\n    <\/div><\/center><\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/mdsattacks.com\/\">Fallout<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/mdsattacks.com\/files\/fallout.pdf\">PDF<\/a><\/noindex>) &#8212; ofron mund\u00ebsin\u00eb p\u00ebr t\u00eb lexuar t\u00eb dh\u00ebnat, t\u00eb regjistruara s\u00eb fundmi nga sistemi operativ dhe p\u00ebr t\u00eb p\u00ebrcaktuar shp\u00ebrndarjen e memories s\u00eb OS p\u00ebr thjesht\u00ebzimin e zhvillimit t\u00eb sulmeve t\u00eb tjera;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/cpu.fail\/store_to_leak_forwarding.pdf\">Store-To-Leak Forwarding<\/a><\/noindex> &#8212; shfryt\u00ebzon optimizimet e CPU p\u00ebr pun\u00ebn me buferin e ruajtjes dhe mund t\u00eb p\u00ebrdoret p\u00ebr t\u00eb anashkaluar mekanizmin e rast\u00ebsis\u00eb s\u00eb adres\u00ebs s\u00eb hap\u00ebsir\u00ebs n\u00eb b\u00ebrtham\u00eb (KASLR), p\u00ebr t\u00eb monitoruar gjendjen e sistemit operativ ose p\u00ebr <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cyberus-technology.de\/posts\/2019-05-14-zombieload.html\">organizimin e<\/a><\/noindex> rrjedhje n\u00eb kombinim me gjenerator\u00eb t\u00eb bazuar n\u00eb metodat Spectre.\n<\/ul>\n<p>Identifikuar <noindex><a rel=\"nofollow\" href=\"https:\/\/software.intel.com\/security-software-guidance\/software-guidance\/microarchitectural-data-sampling\">mang\u00ebsive<\/a><\/noindex>:<\/p>\n<ul>\n<li class=\"l\"> CVE-2018-12126 &#8212; MSBDS (Sampling i T\u00eb Dh\u00ebnave t\u00eb Buferit t\u00eb Ruajtjes n\u00eb Mikroarkitektur\u00eb), rikuperimi i p\u00ebrmbajtjes s\u00eb buferave t\u00eb ruajtjes. P\u00ebrdoret n\u00eb sulmin Fallout. Shkalla e rrezikshm\u00ebris\u00eb \u00ebsht\u00eb p\u00ebrcaktuar n\u00eb 6.5 pik\u00eb (CVSS);\n<li class=\"l\"> CVE-2018-12127 &#8212; MLPDS (Sampling i T\u00eb Dh\u00ebnave t\u00eb Portit t\u00eb Ngarkimit n\u00eb Mikroarkitektur\u00eb), rikuperimi i p\u00ebrmbajtjes s\u00eb portave t\u00eb ngarkimit. P\u00ebrdoret n\u00eb sulmin RIDL. CVSS 6.5;\n<li class=\"l\"> CVE-2018-12130 &#8212; MFBDS (Sampling i T\u00eb Dh\u00ebnave t\u00eb Buferit t\u00eb Mbushjes n\u00eb Mikroarkitektur\u00eb), rikuperimi i p\u00ebrmbajtjes s\u00eb buferave t\u00eb mbushjes. P\u00ebrdoret n\u00eb sulmet ZombieLoad dhe RIDL. CVSS 6.5;\n<li class=\"l\"> CVE-2019-11091 &#8212; MDSUM (Sampling i T\u00eb Dh\u00ebnave n\u00eb Mikroarkitektur\u00eb Memoria e Paedukueshme), rikuperimi i p\u00ebrmbajtjes s\u00eb memories jo t\u00eb gjitha. P\u00ebrdoret n\u00eb sulmin RIDL. CVSS 3.8.\n<\/ul>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/software.intel.com\/security-software-guidance\/insights\/deep-dive-intel-analysis-microarchitectural-data-sampling\">Kuptimi<\/a><\/noindex> problemet e identifikuara n\u00eb kapacitetin e p\u00ebrdorimit t\u00eb metodave t\u00eb analiz\u00ebs nga kanalet an\u00ebsore ndaj t\u00eb dh\u00ebnave n\u00eb strukturat mikroarkitekturore, t\u00eb cilat aplikacionet nuk kan\u00eb qasje direkte. B\u00ebhet fjal\u00eb p\u00ebr struktura t\u00eb tilla me nivel t\u00eb ul\u00ebt si bufferat e plot\u00ebsimit (Line Fill Buffer), bufferat e ruajtjes (Store Buffer) dhe portat e ngarkes\u00ebs (Load Port), t\u00eb cilat jan\u00eb blloqe m\u00eb t\u00eb vogla se cache i nivelit t\u00eb par\u00eb (L1D), cache i ngarkes\u00ebs s\u00eb t\u00eb dh\u00ebnave (RDCL) ose L1TF (Gabimi i Terminalit t\u00eb L1), dhe p\u00ebr rrjedhoj\u00eb p\u00ebrfshijn\u00eb m\u00eb pak informacion dhe p\u00ebrdit\u00ebsohen m\u00eb intensivisht.<br \/>\n<center><img decoding=\"async\" alt=\"Klas i ri i vulnerabiliteteve n\u00eb procesor\u00ebt Intel\" src=\"\/wp-content\/uploads\/2019\/05\/205ff034e070b8b057f01c02d6381c2a.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p>Sulmet nga kanale an\u00ebsore ndaj strukturave mikroarkitekturore jan\u00eb ndjesh\u00ebm m\u00eb t\u00eb v\u00ebshtira p\u00ebr t'u realizuar krahasuar me metodat e rikuperimit t\u00eb p\u00ebrmbajtjes s\u00eb cache-it dhe k\u00ebrkojn\u00eb ndjekjen dhe analizimin e sasive t\u00eb m\u00ebdha t\u00eb t\u00eb dh\u00ebnave p\u00ebr t\u00eb p\u00ebrcaktuar lidhjen e tyre me adresa t\u00eb caktuara n\u00eb memorie (thelb\u00ebsisht, sulmuesi nuk mund t\u00eb kap\u00eb drejtp\u00ebrdrejt t\u00eb dh\u00ebna t\u00eb caktuara, por mund t\u00eb akumuloj\u00eb rrjedhje p\u00ebr nj\u00eb koh\u00eb t\u00eb gjat\u00eb dhe t\u00eb p\u00ebrdor\u00eb metoda statistikore p\u00ebr t\u00eb rikonstruktuar lloje t\u00eb caktuara t\u00eb t\u00eb dh\u00ebnave). P\u00ebr m\u00eb tep\u00ebr, sulmi prek vet\u00ebm t\u00eb dh\u00ebnat n\u00eb t\u00eb nj\u00ebjtin b\u00ebrtham\u00eb fizike CPU si\u00e7 \u00ebsht\u00eb kodi i sulmuesit.<\/p>\n<p>Metodat e propozuara p\u00ebr identifikimin e p\u00ebrmbajtjes s\u00eb strukturave mikroarkitekturore bazohen n\u00eb at\u00eb q\u00eb k\u00ebto struktura p\u00ebrdoren gjat\u00eb p\u00ebrpunimit spekulativ t\u00eb p\u00ebrjashtimeve (fault) ose operacioneve t\u00eb ngarkes\u00ebs dhe ruajtjes.<br \/>\nGjat\u00eb kryerjes spekulative, p\u00ebrmbajtja e strukturave t\u00eb brendshme riorientohet p\u00ebr p\u00ebrpunim n\u00eb regjistra ose cache. Operacionet spekulative nuk p\u00ebrfundojn\u00eb dhe rezultati anulohet, por p\u00ebrmbajtja e riorientuar mund t\u00eb p\u00ebrcaktohet p\u00ebrmes metodave t\u00eb analiz\u00ebs s\u00eb cache-it nga kanalet an\u00ebsore.<\/p>\n<p>Portat e ngarkes\u00ebs p\u00ebrdoren nga procesori p\u00ebr t\u00eb marr\u00eb t\u00eb dh\u00ebna nga memoria ose n\u00ebn-sistemi i input\/output dhe p\u00ebr t\u00eb ofruar informacionin e marr\u00eb n\u00eb regjistrat e CPU. P\u00ebr shkak t\u00eb karakteristik\u00ebs s\u00eb implementimit, t\u00eb dh\u00ebnat nga operacionet e vjetra t\u00eb ngarkes\u00ebs mbeten n\u00eb portat deri sa t\u00eb shkruhen rishtas nga t\u00eb dh\u00ebna t\u00eb reja, \u00e7ka lejon p\u00ebrcaktimin indirekt t\u00eb gjendjes s\u00eb t\u00eb dh\u00ebnave n\u00eb portin e ngarkes\u00ebs p\u00ebrmes manipulimeve me p\u00ebrjashtimet (fault) dhe instrukcioneve SSE\/AVX\/AVX-512 q\u00eb ngarkojn\u00eb m\u00eb shum\u00eb se 64 bit t\u00eb dh\u00ebna. N\u00eb k\u00ebto kushte, operacionet e ngarkes\u00ebs spekulativisht ekspozojn\u00eb vlerat e vjetra t\u00eb t\u00eb dh\u00ebnave nga strukturat e brendshme n\u00eb operacionet var\u00ebsuese. Nj\u00eb m\u00ebnyr\u00eb e ngjashme organizon rrjedhjen p\u00ebrmes tamponit t\u00eb ruajtjes, i cili p\u00ebrdoret p\u00ebr t\u00eb p\u00ebrshpejtuar shkrimin n\u00eb cache t\u00eb CPU dhe p\u00ebrfshin nj\u00eb tabel\u00eb adresash, vlerash dhe flagash, si dhe p\u00ebrmes tamponit t\u00eb mbushjes, i cili p\u00ebrmban t\u00eb dh\u00ebna q\u00eb mungojn\u00eb n\u00eb cache L1 (cache-miss), deri sa ato ngarkohen nga cache t\u00eb niveleve t\u00eb tjera.<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/pics_base\/0_1557869220.png\"><img decoding=\"async\" alt=\"Klas i ri i vulnerabiliteteve n\u00eb procesor\u00ebt Intel\" src=\"\/wp-content\/uploads\/2019\/05\/1f8bf290cd6ecbec5a5f17cc3103010d.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Problemi <noindex><a rel=\"nofollow\" href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/architecture-and-technology\/engineering-new-protections-into-hardware.html\">preket<\/a><\/noindex> modelet e procesor\u00ebve Intel, q\u00eb prodhohen q\u00eb nga viti 2011 (duke filluar nga gjenerata e 6-t\u00eb). N\u00eb t\u00eb nj\u00ebjt\u00ebn koh\u00eb, dob\u00ebsit\u00eb harduerike bllokohen duke filluar nga disa modele t\u00eb gjenerat\u00ebs 8 dhe 9 t\u00eb Intel Core dhe 2 t\u00eb gjenerat\u00ebs Intel Xeon Scalable (mund t\u00eb kontrollohet p\u00ebrmes bit ARCH_CAP_MDS_NO n\u00eb IA32_ARCH_CAPABILITIES MSR). Dob\u00ebsit\u00eb gjithashtu tashm\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/architecture-and-technology\/mds.html\">jan\u00eb eliminuar<\/a><\/noindex> n\u00eb nivelin e firmware, mikro-kodit dhe sistemeve operative. Sipas vler\u00ebsimit t\u00eb Intel, humbja e performanc\u00ebs pas aktivizimit t\u00eb korrigjimeve p\u00ebr shumic\u00ebn e p\u00ebrdoruesve <noindex><a rel=\"nofollow\" href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/architecture-and-technology\/mds.html\">nuk tejkalon<\/a><\/noindex> 3%. Kur teknologjia Hyper-Threading \u00ebsht\u00eb e \u00e7aktivizuar, ulja e performanc\u00ebs mund t\u00eb arrij\u00eb deri n\u00eb 9% n\u00eb testin SPECint_rate_base, deri n\u00eb 11% gjat\u00eb llogaritjeve t\u00eb numrave t\u00eb plot\u00eb dhe deri n\u00eb 19% gjat\u00eb ekzekutimit t\u00eb aplikacioneve Java n\u00eb server (kur HT \u00ebsht\u00eb aktivizuar, humbja e performanc\u00ebs \u00ebsht\u00eb pothuajse e pap\u00ebrfillshme). Korrigjimet praktikisht nuk ndikojn\u00eb n\u00eb performanc\u00ebn e operacioneve t\u00eb lidhura me input\/output.<\/p>\n<p>N\u00eb kernelin Linux, mbrojtja nga MDS <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=fa4bff165070dc40a3de35b78e4f8da8e8d85ec5\">\u00ebsht\u00eb shtuar<\/a><\/noindex> n\u00eb p\u00ebrdit\u00ebsimet e sotme <noindex><a rel=\"nofollow\" href=\"https:\/\/www.kernel.org\/\">4.19.43, 4.14.119 dhe 4.9.176. Metoda e mbrojtjes<\/a><\/noindex>  \t5.1.2, 5.0.16,<br \/>\nbazohet <noindex><a rel=\"nofollow\" href=\"https:\/\/www.kernel.org\/doc\/html\/latest\/x86\/mds.html#mds\">n\u00eb pastrimin e p\u00ebrmbajtjes s\u00eb bufeve mikroarkitektonike n\u00eb momentin e rikthimit nga b\u00ebrthama n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit ose gjat\u00eb kalimit t\u00eb kontrollit n\u00eb sistemin e mysafir\u00ebve, p\u00ebr t\u00eb cilin p\u00ebrdoret instruksioni VERW. P\u00ebr t\u00eb punuar mbrojtjet, k\u00ebrkohet mb\u00ebshtetje p\u00ebr modalitetin MD_CLEAR, e implementuar n\u00eb p\u00ebrdit\u00ebsimin e fundit t\u00eb mikro-kodit. P\u00ebr mbrojtje t\u00eb plot\u00eb gjithashtu rekomandohet \u00e7aktivizimi i Hyper Threading. P\u00ebr t\u00eb kontrolluar ndjeshm\u00ebrin\u00eb e sistemit ndaj dob\u00ebsis\u00eb n\u00eb kernelin Linux.<\/a><\/noindex> n\u00eb pastrimin e p\u00ebrmbajtjes s\u00eb mikroarkitektur\u00ebs buffers gjat\u00eb rikthimit nga b\u00ebrthama n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit ose gjat\u00eb kalimit t\u00eb kontrollit n\u00eb sistemin mysliman, p\u00ebr t\u00eb cil\u00ebn p\u00ebrdoret instruksioni VERW. P\u00ebr funksionimin e mbrojtjes k\u00ebrkohet mb\u00ebshtetje p\u00ebr modin MD_CLEAR, i implementuar n\u00eb p\u00ebrdit\u00ebsimin e fundit t\u00eb mikro-kodit. P\u00ebr mbrojtje t\u00eb plot\u00eb, rekomandohet gjithashtu q\u00eb t\u00eb \u00e7aktivizohet Hyper Threading. P\u00ebr t\u00eb verifikuar n\u00ebse sistemi \u00ebsht\u00eb i ndjesh\u00ebm ndaj dob\u00ebsive t\u00eb b\u00ebrtham\u00ebs Linux <noindex><a rel=\"nofollow\" href=\"https:\/\/www.kernel.org\/doc\/html\/latest\/admin-guide\/hw-vuln\/mds.html\">\u00ebsht\u00eb shtuar<\/a><\/noindex> menaxheri &#171; \/sys\/devices\/system\/cpu\/vulnerabilities\/mds &#187;. P\u00ebr menaxhimin e aktivizimit t\u00eb modaliteteve t\u00eb ndryshme t\u00eb bllokimit t\u00eb dob\u00ebsive n\u00eb b\u00ebrtham\u00eb, \u00ebsht\u00eb shtuar parametri &#171; mds= &#187;, i cili mund t\u00eb marr\u00eb vlerat &#171; full &#187;, &#171; full,nosmt &#187; (\u00e7aktivizimi i Hyper-Threads), &#171; vmwerv &#187; dhe &#171; off &#187;.<\/p>\n<p> Paketat e p\u00ebrdit\u00ebsimeve jan\u00eb tashm\u00eb l\u00ebshuar p\u00ebr <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2018-12127\">RHEL<\/a><\/noindex> dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2018\/CVE-2018-12127.html\">Ubuntu<\/a><\/noindex>, por ende mbeten t\u00eb pa aksesueshme p\u00ebr <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2018-12130\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?releases=F30&#038;type=security\">Fedora<\/a><\/noindex> dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/www.suse.com\/security\/cve\/CVE-2018-12127\/\">SUSE<\/a><\/noindex>.<br \/>\nKorrigjimi p\u00ebr bllokimin e rrjedhjeve t\u00eb t\u00eb dh\u00ebnave nga makinat virtuale gjithashtu <noindex><a rel=\"nofollow\" href=\"https:\/\/xenbits.xen.org\/xsa\/advisory-297.html\">formuar<\/a><\/noindex> p\u00ebr hipervizorin Xen. P\u00ebr t\u00eb mbrojtur sistemet e virtualizimit, q\u00eb kryejn\u00eb thirrjen e komand\u00ebs L1D_FLUSH para se t'i kalojn\u00eb kontrollin nj\u00eb makine virtuale tjet\u00ebr dhe p\u00ebr t\u00eb mbrojtur enklavat Intel SGX, \u00ebsht\u00eb e mjaftueshme p\u00ebrdit\u00ebsimi i mikro-kodit.  <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50684\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Intel \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u043c \u043a\u043b\u0430\u0441\u0441\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0441\u0432\u043e\u0438\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u0430\u0445 &#8212; MDS (Microarchitectural Data Sampling). \u041a\u0430\u043a \u0438 \u043f\u0440\u043e\u0448\u043b\u044b\u0435 \u0430\u0442\u0430\u043a\u0438 \u043a\u043b\u0430\u0441\u0441\u0430 Spectre \u043d\u043e\u0432\u044b\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u043c\u043e\u0433\u0443\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0442\u0435\u0447\u043a\u0435 \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b, \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0430\u0448\u0438\u043d \u0438 \u0447\u0443\u0436\u0438\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432. \u0423\u0442\u0432\u0435\u0440\u0436\u0434\u0430\u0435\u0442\u0441\u044f, \u0447\u0442\u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0441\u043f\u0435\u0440\u0432\u0430 \u0431\u044b\u043b\u0438 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0441\u043e\u0442\u0440\u0443\u0434\u043d\u0438\u043a\u0430\u043c\u0438 \u0438 \u043f\u0430\u0440\u0442\u043d\u0451\u0440\u0430\u043c\u0438 Intel \u0432 \u0445\u043e\u0434\u0435 \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u0435\u0433\u043e \u0430\u0443\u0434\u0438\u0442\u0430, \u043f\u043e\u043b\u0435 \u0447\u0435\u0433\u043e \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":25348,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-33659","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Intel \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u043c\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/predstavlen-novyj-klass-uyazvimostej-v-protsessorah-intel\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u043d\u043e\u0432\u044b\u0439 \u043a\u043b\u0430\u0441\u0441 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u0430\u0445 Intel | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Intel \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u043c\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/predstavlen-novyj-klass-uyazvimostej-v-protsessorah-intel\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:53:59+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:53:59+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Klass i ri i dob\u00ebsive n\u00eb procesor\u00ebt Intel u prezantua | ProHoster","description":"Kompania Intel publikoi informacion mbi nj\u00eb t\u00eb re","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/predstavlen-novyj-klass-uyazvimostej-v-protsessorah-intel","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u043d\u043e\u0432\u044b\u0439 \u043a\u043b\u0430\u0441\u0441 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u0430\u0445 Intel | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Intel \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u043c","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/predstavlen-novyj-klass-uyazvimostej-v-protsessorah-intel","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:53:59+00:00","article:modified_time":"2019-10-31T18:53:59+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"33659","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 16:12:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:36:34","updated":"2026-01-21 16:12:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/33659","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=33659"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/33659\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/25348"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=33659"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=33659"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=33659"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}