{"id":33659,"date":"2019-10-31T21:53:59","date_gmt":"2019-10-31T18:53:59","guid":{"rendered":"https:\/\/prohoster.info\/blog\/predstavlen-novyj-klass-uyazvimostej-v-protsessorah-intel\/"},"modified":"2019-10-31T21:53:59","modified_gmt":"2019-10-31T18:53:59","slug":"predstavlen-novyj-klass-uyazvimostej-v-protsessorah-intel","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/predstavlen-novyj-klass-uyazvimostej-v-protsessorah-intel","title":{"rendered":"Nj\u00eb klas\u00eb e re e vulnerabiliteteve n\u00eb procesor\u00ebt Intel \u00ebsht\u00eb prezantuar.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Kompania Intel <noindex><a rel=\"nofollow\" href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00233.html\">publikoi<\/a><\/noindex> informacione mbi nj\u00eb t\u00eb re <noindex><a rel=\"nofollow\" href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/architecture-and-technology\/mds.html\">klas\u00ebn e dob\u00ebsive<\/a><\/noindex> n\u00eb procesor\u00ebt e tij &#8212; <noindex><a rel=\"nofollow\" href=\"https:\/\/mdsattacks.com\/\">MDS<\/a><\/noindex> (Sampling i t\u00eb Dh\u00ebnave Mikroarkitekturale). Si\u00e7 ndodhi me sulmet e kaluara t\u00eb klas\u00ebs Spectre, problemet e reja mund t\u00eb shkaktojn\u00eb rrjedhjen e t\u00eb dh\u00ebnave t\u00eb ndjeshme t\u00eb sistemit operativ, makinave virtuale dhe proceseve t\u00eb tjera. Pretendohet se problemet u identifikuan fillimisht nga punonj\u00ebsit dhe partner\u00ebt e Intel gjat\u00eb nj\u00eb auditi t\u00eb brendsh\u00ebm, pas s\u00eb cil\u00ebs informacioni mbi probleme t\u00eb ngjashme n\u00eb Intel u shp\u00ebrnda nga studiues t\u00eb pavarur. Procesor\u00ebt AMD dhe ARM nuk jan\u00eb t\u00eb prekur nga ky problem.<\/p>\n<p>N\u00eb baz\u00eb t\u00eb problemeve t\u00eb identifikuara nga studiuesit e Universitetit Teknik t\u00eb Grazit (Austria) <noindex><a rel=\"nofollow\" href=\"https:\/\/cpu.fail\/\">u zhvillua<\/a><\/noindex> nj\u00eb s\u00ebr\u00eb sulmesh praktike p\u00ebrmes kanaleve t\u00eb jashtme:<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/zombieloadattack.com\/\">ZombieLoad<\/a><\/noindex>  (<noindex><a rel=\"nofollow\" href=\"https:\/\/zombieloadattack.com\/zombieload.pdf\">PDF<\/a><\/noindex>) &#8212; lejon nxjerrjen e informacionit t\u00eb besuesh\u00ebm nga procese t\u00eb tjera, sistemi operativ, makina virtuale dhe enclave t\u00eb mbrojtura (TEE, Mjedisi i Ekzekutimit t\u00eb Besuesh\u00ebm). P\u00ebr shembull, \u00ebsht\u00eb demonstruar mund\u00ebsia e p\u00ebrcaktimit t\u00eb historis\u00eb s\u00eb hapjes s\u00eb faqeve n\u00eb shfletuesin Tor, i cili \u00ebsht\u00eb ekzekutuar n\u00eb nj\u00eb makin\u00eb virtuale tjet\u00ebr, si dhe p\u00ebrcaktimi i \u00e7elSave t\u00eb aksesit dhe fjal\u00ebkalimeve t\u00eb p\u00ebrdorura n\u00eb aplikacione;\n<p><center><br \/>\n<video controls=\"\" style=\"width: 720px; max-width:100%\" poster=\"https:\/\/zombieloadattack.com\/public\/images\/demo.jpg\"  src=\"https:\/\/zombieloadattack.com\/public\/videos\/demo_720.mp4\"><source src=\"https:\/\/zombieloadattack.com\/public\/videos\/demo_720.mp4\" type=\"video\/mp4\" label=\"720p\"><\/video><\/center><\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/mdsattacks.com\/\">RIDL<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/mdsattacks.com\/files\/ridl.pdf\">PDF<\/a><\/noindex>) &#8212; lejon organizimin e rrjedhjes s\u00eb informacionit midis zonave t\u00eb ndryshme izoluara n\u00eb procesor\u00ebt Intel, si\u00e7 jan\u00eb tamponet e mbushjes, tamponet e ruajtjes dhe portet e ngarkes\u00ebs. Shembuj t\u00eb kryerjes s\u00eb sulmeve jan\u00eb treguar p\u00ebr t\u00eb organizuar rrjedhje nga procese t\u00eb tjera, sistemi operativ, makina virtuale dhe enclave t\u00eb mbrojtura. P\u00ebr shembull, \u00ebsht\u00eb treguar si t\u00eb dish p\u00ebrmbajtjen e hash-it t\u00eb fjal\u00ebkalimit root nga \/etc\/shadow gjat\u00eb p\u00ebrpjekjeve periodike t\u00eb autentifikimit (sulmimi zgjati 24 or\u00eb);\n<p><center><div class=\"youtube-placeholder\" data-id=\"JXPebaGY8RA\" onclick=\"loadVideo(this)\">\r\n        <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/JXPebaGY8RA\/hqdefault.jpg\" alt=\"Luaj videon\" loading=\"lazy\" width=\"480\" height=\"360\" style=\"width:100%;height:auto;\">\r\n        <div class=\"play-button\"><\/div>\r\n    <\/div><\/center><\/p>\n<p>P\u00ebr m\u00eb tep\u00ebr, \u00ebsht\u00eb treguar nj\u00eb shembull i realizimit t\u00eb sulmit me p\u00ebrdorimin e JavaScript dhe WebAssembly gjat\u00eb hapjes s\u00eb nj\u00eb faqeje t\u00eb d\u00ebmshme n\u00eb motorin SpiderMonkey (n\u00eb shfletuesit modern\u00eb t\u00eb plot\u00eb, nj\u00eb sulm i till\u00eb \u00ebsht\u00eb i pak\u00ebt p\u00ebr shkak t\u00eb kufizimeve t\u00eb sakt\u00ebsis\u00eb s\u00eb or\u00ebs dhe masave p\u00ebr mbrojtjen nga Spectre);<\/p>\n<p><center><div class=\"youtube-placeholder\" data-id=\"KAgoDQmod1Y\" onclick=\"loadVideo(this)\">\r\n        <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/KAgoDQmod1Y\/hqdefault.jpg\" alt=\"Luaj videon\" loading=\"lazy\" width=\"480\" height=\"360\" style=\"width:100%;height:auto;\">\r\n        <div class=\"play-button\"><\/div>\r\n    <\/div><\/center><\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/mdsattacks.com\/\">Fallout<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/mdsattacks.com\/files\/fallout.pdf\">PDF<\/a><\/noindex>) &#8212; ofron mund\u00ebsin\u00eb p\u00ebr t\u00eb lexuar t\u00eb dh\u00ebna q\u00eb jan\u00eb regjistruar s\u00eb fundmi nga sistemi operativ dhe p\u00ebr t\u00eb p\u00ebrcaktuar shp\u00ebrndarjen e memories t\u00eb OS p\u00ebr t\u00eb leht\u00ebsuar kryerjen e sulmeve t\u00eb tjera;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/cpu.fail\/store_to_leak_forwarding.pdf\">Store-To-Leak Forwarding<\/a><\/noindex> &#8212; optimizon CPU p\u00ebr pun\u00ebn me mbajt\u00ebsin dhe mund t\u00eb p\u00ebrdoret p\u00ebr t\u00eb anashkaluar mekanizmin e randomizimit t\u00eb hap\u00ebsir\u00ebs s\u00eb adres\u00ebs s\u00eb kernelit (KASLR), p\u00ebr t\u00eb monitoruar gjendjen e sistemit operativ ose p\u00ebr <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cyberus-technology.de\/posts\/2019-05-14-zombieload.html\">organizimin<\/a><\/noindex> shkarkimeve n\u00eb kombinim me pajisje t\u00eb bazuara n\u00eb metodat Spectre.\n<\/ul>\n<p>Identifikuar <noindex><a rel=\"nofollow\" href=\"https:\/\/software.intel.com\/security-software-guidance\/software-guidance\/microarchitectural-data-sampling\">dob\u00ebsin\u00eb<\/a><\/noindex>:<\/p>\n<ul>\n<li class=\"l\"> CVE-2018-12126 &#8212; MSBDS (Microarchitectural Store Buffer Data Sampling), rikthimi i p\u00ebrmbajtjeve t\u00eb mbajt\u00ebsve. P\u00ebrdoret n\u00eb sulmin Fallout. Shkalla e rrezikut \u00ebsht\u00eb vendosur n\u00eb 6.5 pik\u00eb (CVSS);\n<li class=\"l\"> CVE-2018-12127 &#8212; MLPDS (Microarchitectural Load Port Data Sampling), rikthimi i p\u00ebrmbajtjes s\u00eb porteve t\u00eb ngarkes\u00ebs. P\u00ebrdoret n\u00eb sulmin RIDL. CVSS 6.5;\n<li class=\"l\"> CVE-2018-12130 &#8212; MFBDS (Microarchitectural Fill Buffer Data Sampling), rikthimi i p\u00ebrmbajtjes s\u00eb mbush\u00ebsve. P\u00ebrdoret n\u00eb sulmet ZombieLoad dhe RIDL. CVSS 6.5;\n<li class=\"l\"> CVE-2019-11091 &#8212; MDSUM (Microarchitectural Data Sampling Uncacheable Memory), rikthimi i p\u00ebrmbajtjes s\u00eb memories q\u00eb nuk \u00ebsht\u00eb e mbajtshme. P\u00ebrdoret n\u00eb sulmin RIDL. CVSS 3.8.\n<\/ul>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/software.intel.com\/security-software-guidance\/insights\/deep-dive-intel-analysis-microarchitectural-data-sampling\">Q\u00ebllimi<\/a><\/noindex> probleme t\u00eb zbuluara n\u00eb aplikimin e metodave t\u00eb analiz\u00ebs p\u00ebr kanalet an\u00ebsore n\u00eb t\u00eb dh\u00ebnat brenda strukturave mikroarkitekturore, t\u00eb cilat aplikacionet nuk kan\u00eb qasje t\u00eb drejtp\u00ebrdrejt\u00eb. B\u00ebhet fjal\u00eb p\u00ebr struktura t\u00eb tilla me nivel t\u00eb ul\u00ebt si tamponet e plot\u00ebsimit (Line Fill Buffer), tamponet e ruajtjes (Store Buffer) dhe portat e ngarkimit (Load Port), t\u00eb cilat jan\u00eb blloqe m\u00eb t\u00eb vogla krahasuar me memorin\u00eb cache t\u00eb nivelit t\u00eb par\u00eb (L1D), memorin\u00eb e ngarkimit t\u00eb t\u00eb dh\u00ebnave (RDCL) ose L1TF (L1 Terminal Fault) dhe p\u00ebr pasoj\u00eb p\u00ebrfshijn\u00eb m\u00eb pak informacion dhe p\u00ebrdit\u00ebsohen m\u00eb intensivisht.<br \/>\n<center><img decoding=\"async\" alt=\"Nj\u00eb klas\u00eb e re e vulnerabiliteteve n\u00eb procesor\u00ebt Intel \u00ebsht\u00eb prezantuar.\" src=\"\/wp-content\/uploads\/2019\/05\/205ff034e070b8b057f01c02d6381c2a.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p>Sulmet n\u00eb kanale an\u00ebsore ndaj strukturave mikroarkitekturore jan\u00eb ndjesh\u00ebm m\u00eb t\u00eb v\u00ebshtira p\u00ebr t'u realizuar krahasuar me metodat e rikuperimit t\u00eb p\u00ebrmbajtjes s\u00eb memoris\u00eb cache dhe k\u00ebrkojn\u00eb ndjekjen dhe analiz\u00ebn e volumit t\u00eb konsideruesh\u00ebm t\u00eb t\u00eb dh\u00ebnave p\u00ebr t\u00eb p\u00ebrcaktuar lidhjen e tyre me adresat e caktuara n\u00eb memorje (n\u00eb thelb, sulmuesi nuk mund t\u00eb kap\u00eb t\u00eb dh\u00ebna t\u00eb caktuara me q\u00ebllim, por mund t\u00eb akumuloj\u00eb rrjedhje p\u00ebr nj\u00eb koh\u00eb t\u00eb gjat\u00eb dhe t\u00eb aplikoje metoda statistikore p\u00ebr t\u00eb rikonstruktuar disa lloje t\u00eb caktuara t\u00eb t\u00eb dh\u00ebnave). P\u00ebr m\u00eb tep\u00ebr, sulmi prek vet\u00ebm t\u00eb dh\u00ebnat n\u00eb t\u00eb nj\u00ebjtin b\u00ebrthame fizike CPU, si\u00e7 \u00ebsht\u00eb kodi i sulmuesit.<\/p>\n<p>Metodat e propozuara p\u00ebr p\u00ebrcaktimin e p\u00ebrmbajtjes s\u00eb strukturave mikroarkitektonike bazohen n\u00eb faktin se k\u00ebto struktura p\u00ebrdoren gjat\u00eb p\u00ebrpunimit spekulativ t\u00eb p\u00ebrjashtimeve (fault) ose operacioneve t\u00eb ngarkimit dhe ruajtjes.<br \/>\nGjat\u00eb ekzekutimit spekulativ, p\u00ebrmbajtja e strukturave t\u00eb brendshme redirektohet p\u00ebr p\u00ebrpunim n\u00eb regjistra ose cache. Operacionet spekulative nuk p\u00ebrfundojn\u00eb dhe rezultati hidhet, por p\u00ebrmbajtja e redirektuar mund t\u00eb p\u00ebrcaktohet p\u00ebrmes metodave t\u00eb analiz\u00ebs s\u00eb cache n\u00ebp\u00ebrmjet kanaleve t\u00eb jashtme.<\/p>\n<p>Portat e ngarkes shfryt\u00ebzohen nga procesori p\u00ebr t\u00eb marr\u00eb t\u00eb dh\u00ebna nga memoria ose n\u00ebn-sistemi i hyrjes\/daljes dhe p\u00ebr t\u00eb ofruar informacionin e marr\u00eb n\u00eb registrot e CPU-s\u00eb. P\u00ebr shkak t\u00eb ve\u00e7orive t\u00eb realizimit, t\u00eb dh\u00ebnat nga operacionet e vjetra t\u00eb ngarkes\u00ebs mbeten n\u00eb portat deri sa t\u00eb shkruhen nga t\u00eb dh\u00ebna t\u00eb reja, duke lejuar k\u00ebshtu t\u00eb p\u00ebrcaktohet n\u00eb m\u00ebnyr\u00eb indirekte gjendja e t\u00eb dh\u00ebnave n\u00eb portin e ngarkes\u00ebs p\u00ebrmes manipulimeve me p\u00ebrjashtimet (fault) dhe instruksioneve SSE\/AVX\/AVX-512 q\u00eb ngarkojn\u00eb m\u00eb shum\u00eb se 64 bit t\u00eb dh\u00ebna. N\u00eb k\u00ebto kushte, operacionet e ngarkes\u00ebs speculativisht ndri\u00e7ojn\u00eb vlerat e vjetra t\u00eb dh\u00ebnave nga struktura t\u00eb brendshme n\u00eb operacione t\u00eb varura. N\u00eb nj\u00eb m\u00ebnyr\u00eb t\u00eb ngjashme organizohet shfryt\u00ebzimi p\u00ebrmes bufrit t\u00eb ruajtjes, i cili p\u00ebrdoret p\u00ebr t\u00eb p\u00ebrshpejtuar shkrimin n\u00eb cache-n e CPU-s\u00eb dhe p\u00ebrfshin nj\u00eb tabel\u00eb adresash, vlerash dhe flamujsh, si dhe p\u00ebrmes bufrit t\u00eb mbushjes, i cili p\u00ebrmban t\u00eb dh\u00ebna q\u00eb mungojn\u00eb n\u00eb cache-n L1 (cache-miss) deri n\u00eb koh\u00ebn e ngarkimit t\u00eb tyre nga caches t\u00eb niveleve t\u00eb tjera.<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/pics_base\/0_1557869220.png\"><img decoding=\"async\" alt=\"Nj\u00eb klas\u00eb e re e vulnerabiliteteve n\u00eb procesor\u00ebt Intel \u00ebsht\u00eb prezantuar.\" src=\"\/wp-content\/uploads\/2019\/05\/1f8bf290cd6ecbec5a5f17cc3103010d.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Problemi <noindex><a rel=\"nofollow\" href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/architecture-and-technology\/engineering-new-protections-into-hardware.html\">dhe<\/a><\/noindex> modelet e procesor\u00ebve Intel, t\u00eb l\u00ebshuara q\u00eb nga viti 2011 (duke filluar nga brezi i 6-t\u00eb). Megjithat\u00eb, dob\u00ebsit\u00eb e siguris\u00eb bllokohen duke filluar nga disa modele t\u00eb brezit t\u00eb 8-t\u00eb dhe 9-t\u00eb t\u00eb Intel Core dhe brezi i 2-t\u00eb i Intel Xeon Scalable (mund t\u00eb kontrolloni p\u00ebrmes bitit ARCH_CAP_MDS_NO n\u00eb IA32_ARCH_CAPABILITIES MSR). Dob\u00ebsit\u00eb gjithashtu tashm\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/architecture-and-technology\/mds.html\">jan\u00eb zgjidhur<\/a><\/noindex> ndodhen n\u00eb nivelin e firmware, mikro-kodit dhe sistemeve operative. Sipas vler\u00ebsimeve nga Intel, humbja e performanc\u00ebs pas aktivizimit t\u00eb korrigjimeve p\u00ebr shumic\u00ebn e p\u00ebrdoruesve <noindex><a rel=\"nofollow\" href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/architecture-and-technology\/mds.html\">nuk kalon<\/a><\/noindex> 3%. Nd\u00ebrsa n\u00ebse \u00e7aktivizohet teknologjia Hyper-Threading, ulja e performanc\u00ebs mund t\u00eb arrij\u00eb deri n\u00eb 9% n\u00eb testin SPECint_rate_base, deri n\u00eb 11% gjat\u00eb llogaritjeve me t\u00ebr\u00eb numra dhe deri n\u00eb 19% gjat\u00eb ekzekutimit t\u00eb aplikacioneve Java n\u00eb server (nd\u00ebrsa me HT t\u00eb aktivizuar, ulja e performanc\u00ebs \u00ebsht\u00eb pothuajse e pap\u00ebrfillshme). Korrigjimet praktikisht nuk nd impactojn\u00eb n\u00eb performanc\u00ebn e operacioneve t\u00eb lidhura me hyrje\/dalje.<\/p>\n<p>N\u00eb b\u00ebrtham\u00ebn Linux, mbrojtja nga MDS <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=fa4bff165070dc40a3de35b78e4f8da8e8d85ec5\">shtuar<\/a><\/noindex> n\u00eb azhurnimet e sotme <noindex><a rel=\"nofollow\" href=\"https:\/\/www.kernel.org\/\">4.19.43, 4.14.119 dhe 4.9.176. Metoda e mbrojtjes<\/a><\/noindex>  \t5.1.2, 5.0.16,<br \/>\nnd\u00ebrtohet <noindex><a rel=\"nofollow\" href=\"https:\/\/www.kernel.org\/doc\/html\/latest\/x86\/mds.html#mds\">nd\u00ebrtohet<\/a><\/noindex> p\u00ebr pastrimin e p\u00ebrmbajtjes s\u00eb mikroarkitekturave t\u00eb bllokimeve gjat\u00eb rikthimit nga b\u00ebrthama n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit ose kur p\u00ebrcillet kontrolli te sistemi mysafir, p\u00ebr t\u00eb cilin p\u00ebrdoret udh\u00ebzimi VERW. P\u00ebr funksionimin e mbrojtjeve \u00ebsht\u00eb e nevojshme q\u00eb t\u00eb ket\u00eb mb\u00ebshtetje p\u00ebr modin MD_CLEAR, i implementuar n\u00eb azhurnimin e fundit t\u00eb mikrokodit. P\u00ebr mbrojtje t\u00eb plot\u00eb, gjithashtu rekomandohet fikja e Hyper Threading. P\u00ebr t\u00eb verifikuar ndjeshm\u00ebrin\u00eb e sistemit ndaj k\u00ebt\u00eb dob\u00ebsie n\u00eb kernelin Linux <noindex><a rel=\"nofollow\" href=\"https:\/\/www.kernel.org\/doc\/html\/latest\/admin-guide\/hw-vuln\/mds.html\">u shtua<\/a><\/noindex> p\u00ebrpunuesi &#171;\/sys\/devices\/system\/cpu\/vulnerabilities\/mds&#187;. P\u00ebr t\u00eb menaxhuar aktivizimin e m\u00ebnyrave t\u00eb ndryshme t\u00eb bllokimit t\u00eb dob\u00ebsive, n\u00eb kernel \u00ebsht\u00eb shtuar parametri &#171;mds=&#187;, i cili mund t\u00eb marr\u00eb vlera &#171;full&#187;, &#171;full,nosmt&#187; (ndalimi i Hyper-Threads), &#171;vmwerv&#187; dhe &#171;off&#187;.<\/p>\n<p> Azhurnimet e paketave tashm\u00eb jan\u00eb l\u00ebshuar p\u00ebr <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2018-12127\">RHEL<\/a><\/noindex> dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2018\/CVE-2018-12127.html\">Ubuntu<\/a><\/noindex>, por ende mbeten t\u00eb paqasshme p\u00ebr <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2018-12130\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?releases=F30&#038;type=security\">Fedora<\/a><\/noindex> dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/www.suse.com\/security\/cve\/CVE-2018-12127\/\">SUSE<\/a><\/noindex>.<br \/>\nKorrigjimi p\u00ebr bllokimin e rrjedhjeve t\u00eb t\u00eb dh\u00ebnave nga makinat virtuale gjithashtu <noindex><a rel=\"nofollow\" href=\"https:\/\/xenbits.xen.org\/xsa\/advisory-297.html\">formuar<\/a><\/noindex> p\u00ebr hipervizorin Xen. P\u00ebr t\u00eb mbrojtur sistemet e virtualizimit, t\u00eb cilat kryejn\u00eb thirrjen e komand\u00ebs L1D_FLUSH para se t\u00eb kalojn\u00eb kontrollin te nj\u00eb makin\u00eb virtuale tjet\u00ebr, dhe p\u00ebr t\u00eb mbrojtur enklavat Intel SGX mjafton azhurnimi i mikrokodit.  <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50684\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Intel \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u043c \u043a\u043b\u0430\u0441\u0441\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0441\u0432\u043e\u0438\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u0430\u0445 &#8212; MDS (Microarchitectural Data Sampling). \u041a\u0430\u043a \u0438 \u043f\u0440\u043e\u0448\u043b\u044b\u0435 \u0430\u0442\u0430\u043a\u0438 \u043a\u043b\u0430\u0441\u0441\u0430 Spectre \u043d\u043e\u0432\u044b\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u043c\u043e\u0433\u0443\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0442\u0435\u0447\u043a\u0435 \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b, \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0430\u0448\u0438\u043d \u0438 \u0447\u0443\u0436\u0438\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432. \u0423\u0442\u0432\u0435\u0440\u0436\u0434\u0430\u0435\u0442\u0441\u044f, \u0447\u0442\u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0441\u043f\u0435\u0440\u0432\u0430 \u0431\u044b\u043b\u0438 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0441\u043e\u0442\u0440\u0443\u0434\u043d\u0438\u043a\u0430\u043c\u0438 \u0438 \u043f\u0430\u0440\u0442\u043d\u0451\u0440\u0430\u043c\u0438 Intel \u0432 \u0445\u043e\u0434\u0435 \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u0435\u0433\u043e \u0430\u0443\u0434\u0438\u0442\u0430, \u043f\u043e\u043b\u0435 \u0447\u0435\u0433\u043e \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":25348,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-33659","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Intel \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u043c \u043a\u043b\u0430\u0441\u0441\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0441\u0432\u043e\u0438\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u0430\u0445 - MDS (Microarchitectural Data Sampling). \u041a\u0430\u043a \u0438 \u043f\u0440\u043e\u0448\u043b\u044b\u0435 \u0430\u0442\u0430\u043a\u0438 \u043a\u043b\u0430\u0441\u0441\u0430 Spectre \u043d\u043e\u0432\u044b\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u043c\u043e\u0433\u0443\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0442\u0435\u0447\u043a\u0435 \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b, \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0430\u0448\u0438\u043d \u0438 \u0447\u0443\u0436\u0438\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432. \u0423\u0442\u0432\u0435\u0440\u0436\u0434\u0430\u0435\u0442\u0441\u044f, \u0447\u0442\u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0441\u043f\u0435\u0440\u0432\u0430 \u0431\u044b\u043b\u0438 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0441\u043e\u0442\u0440\u0443\u0434\u043d\u0438\u043a\u0430\u043c\u0438 \u0438 \u043f\u0430\u0440\u0442\u043d\u0451\u0440\u0430\u043c\u0438 Intel \u0432 \u0445\u043e\u0434\u0435 \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u0435\u0433\u043e \u0430\u0443\u0434\u0438\u0442\u0430, \u043f\u043e\u043b\u0435 \u0447\u0435\u0433\u043e \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/predstavlen-novyj-klass-uyazvimostej-v-protsessorah-intel\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u043d\u043e\u0432\u044b\u0439 \u043a\u043b\u0430\u0441\u0441 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u0430\u0445 Intel | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Intel \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u043c \u043a\u043b\u0430\u0441\u0441\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0441\u0432\u043e\u0438\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u0430\u0445 - MDS (Microarchitectural Data Sampling). \u041a\u0430\u043a \u0438 \u043f\u0440\u043e\u0448\u043b\u044b\u0435 \u0430\u0442\u0430\u043a\u0438 \u043a\u043b\u0430\u0441\u0441\u0430 Spectre \u043d\u043e\u0432\u044b\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u043c\u043e\u0433\u0443\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0442\u0435\u0447\u043a\u0435 \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b, \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0430\u0448\u0438\u043d \u0438 \u0447\u0443\u0436\u0438\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432. \u0423\u0442\u0432\u0435\u0440\u0436\u0434\u0430\u0435\u0442\u0441\u044f, \u0447\u0442\u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0441\u043f\u0435\u0440\u0432\u0430 \u0431\u044b\u043b\u0438 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0441\u043e\u0442\u0440\u0443\u0434\u043d\u0438\u043a\u0430\u043c\u0438 \u0438 \u043f\u0430\u0440\u0442\u043d\u0451\u0440\u0430\u043c\u0438 Intel \u0432 \u0445\u043e\u0434\u0435 \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u0435\u0433\u043e \u0430\u0443\u0434\u0438\u0442\u0430, \u043f\u043e\u043b\u0435 \u0447\u0435\u0433\u043e \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/predstavlen-novyj-klass-uyazvimostej-v-protsessorah-intel\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:53:59+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:53:59+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Klas\u00eb e re dob\u00ebsish e prezantuar n\u00eb procesor\u00ebt Intel | ProHoster","description":"Kompania Intel publikoi informacione n\u00eb lidhje me nj\u00eb klas\u00eb t\u00eb re t\u00eb dob\u00ebsive n\u00eb procesor\u00ebt e saj - MDS (Microarchitectural Data Sampling). Ashtu si sulmet e m\u00ebparshme t\u00eb klas\u00ebs Spectre, problemet e reja mund t\u00eb \u00e7ojn\u00eb n\u00eb rrjedhjen e t\u00eb dh\u00ebnave t\u00eb mbyllura nga sistemi operativ, makinat virtuale dhe proceset e tjera. P\u00ebrdoruesit dhe partner\u00ebt e Intel pretendojn\u00eb se problemet fillimisht jan\u00eb identifikuar gjat\u00eb nj\u00eb auditimi t\u00eb brendsh\u00ebm.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/predstavlen-novyj-klass-uyazvimostej-v-protsessorah-intel","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u043d\u043e\u0432\u044b\u0439 \u043a\u043b\u0430\u0441\u0441 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u0430\u0445 Intel | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Intel \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u043c \u043a\u043b\u0430\u0441\u0441\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0441\u0432\u043e\u0438\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u0430\u0445 - MDS (Microarchitectural Data Sampling). \u041a\u0430\u043a \u0438 \u043f\u0440\u043e\u0448\u043b\u044b\u0435 \u0430\u0442\u0430\u043a\u0438 \u043a\u043b\u0430\u0441\u0441\u0430 Spectre \u043d\u043e\u0432\u044b\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u043c\u043e\u0433\u0443\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0442\u0435\u0447\u043a\u0435 \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b, \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u043c\u0430\u0448\u0438\u043d \u0438 \u0447\u0443\u0436\u0438\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432. \u0423\u0442\u0432\u0435\u0440\u0436\u0434\u0430\u0435\u0442\u0441\u044f, \u0447\u0442\u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0441\u043f\u0435\u0440\u0432\u0430 \u0431\u044b\u043b\u0438 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0441\u043e\u0442\u0440\u0443\u0434\u043d\u0438\u043a\u0430\u043c\u0438 \u0438 \u043f\u0430\u0440\u0442\u043d\u0451\u0440\u0430\u043c\u0438 Intel \u0432 \u0445\u043e\u0434\u0435 \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u0435\u0433\u043e \u0430\u0443\u0434\u0438\u0442\u0430, \u043f\u043e\u043b\u0435 \u0447\u0435\u0433\u043e \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0431","og:url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/predstavlen-novyj-klass-uyazvimostej-v-protsessorah-intel","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:53:59+00:00","article:modified_time":"2019-10-31T18:53:59+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"33659","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 16:12:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:36:34","updated":"2026-01-21 16:12:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/33659","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=33659"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/33659\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/25348"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=33659"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=33659"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=33659"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}