ื™ื ื˜ืขืœ ื”ืื˜ ืคืืจืขืคื ื˜ืœืขื›ื˜ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืึท ื ื™ื™ึทืข ืงืœืึทืก ืคื•ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–

ื™ื ื˜ืขืœ ื”ืื˜ ืคืืจืขืคื ื˜ืœืขื›ื˜ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืึท ื ื™ื™ึทืข ืงืœืึทืก ืคื•ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื–ื™ื™ึทืŸ ืคึผืจืึทืกืขืกืขืจื– - MDS (Microarchitectural Data Sampling). ื•ื•ื™ ืคืึทืจื’ืึทื ื’ืขื ื”ื™ื™ื˜ ืกืคึผืขืงื˜ืขืจ ืื ืคืืœืŸ, ื“ื™ ื ื™ื™ึทืข ื™ืฉื•ื– ืงืขืŸ ืคื™ืจืŸ ืฆื• ืœื™ืงืึทื“ื–ืฉ ืคื•ืŸ ืคึผืจืึทืคึผืจื™ื™ืึทื˜ืขืจื™ ื“ืึทื˜ืŸ ืคื•ืŸ ื“ื™ ืึธืคึผืขืจื™ื™ื˜ื™ื ื’ ืกื™ืกื˜ืขื, ื•ื•ื™ืจื˜ื•ืึทืœ ืžืืฉื™ื ืขืŸ ืื•ืŸ ืคืจืขืžื“ ืคึผืจืึทืกืขืกืึทื–. ืขืก ืื™ื– ืึทืœืขื“ื–ืฉื“ ืึทื– ื“ื™ ืคืจืื‘ืœืขืžืขืŸ ื–ืขื ืขืŸ ืขืจืฉื˜ืขืจ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื“ื•ืจืš ื™ื ื˜ืขืœ ืขืžืคึผืœื•ื™ื™ื– ืื•ืŸ ืคึผืึทืจื˜ื ืขืจืก ื‘ืขืฉืึทืก ืึทืŸ ื™ื ืขืจืœืขืš ืงืึธื ื˜ืจืึธืœื™ืจืŸ. ืื™ืŸ ื™ื•ื ื™ ืื•ืŸ ืื•ื™ื’ื•ืกื˜ 2018, ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืคึผืจืึธื‘ืœืขืžืก ืื™ื– ืื•ื™ืš ืฆื•ื’ืขืฉื˜ืขืœื˜ ืฆื• ื™ื ื˜ืขืœ ื“ื•ืจืš ืคืจื™ื™ึท ืจื™ืกืขืจื˜ืฉืขืจื–, ื ืึธืš ื•ื•ืึธืก ื›ึผืžืขื˜ ืึท ื™ืึธืจ ืคื•ืŸ ืฉืœืึธืก ืึทืจื‘ืขื˜ ืื™ื– ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืžื™ื˜ ืžืึทื ื™ืึทืคืึทืงื˜ืฉืขืจืขืจื– ืื•ืŸ ืึธืคึผืขืจื™ื™ื˜ื™ื ื’ ืกื™ืกื˜ืขื ื“ืขื•ื•ืขืœืึธืคึผืขืจืก ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ืžืขื’ืœืขืš ื‘ืึทืคืึทืœืŸ ื•ื•ืขืงื˜ืึธืจืก ืื•ืŸ ืฆื•ืฉื˜ืขืœืŸ ืคื™ืงืกื™ื–. AMD ืื•ืŸ ARM ืคึผืจืึทืกืขืกืขืจื– ื–ืขื ืขืŸ ื ื™ืฉื˜ ืึทืคืขืงื˜ืึทื“ ื“ื•ืจืš ื“ืขื ืคึผืจืึธื‘ืœืขื.

ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–:

CVE-2018-12126 - MSBDS (Microarchitectural Store Buffer Data Sampling), ืึธืคึผื–ื•ืš ืคื•ืŸ ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ืกื˜ืึธืจื™ื“ื–ืฉ ื‘ืึทืคืขืจื–. ื’ืขื•ื•ื™ื™ื ื˜ ืื™ืŸ ื“ื™ ืคืึธืœืึทื•ื˜ ื‘ืึทืคืึทืœืŸ. ื“ืขืจ ื’ืจืึทื“ ืคื•ืŸ ื’ืขืคืึทืจ ืื™ื– ื‘ืืฉืœืืกืŸ ืฆื• ื–ื™ื™ืŸ 6.5 ืคื•ื ืงื˜ืŸ (CVSS);

CVE-2018-12127 - MLPDS (Microarchitectural Load Port Data Sampling), ืึธืคึผื–ื•ืš ืคื•ืŸ ืžืึทืกืข ืคึผืึธืจื˜ ืื™ื ื”ืึทืœื˜. ื’ืขื•ื•ื™ื™ื ื˜ ืื™ืŸ ื“ื™ RIDL ื‘ืึทืคืึทืœืŸ. CVSS 6.5;

CVE-2018-12130 - MFBDS (Microarchitectural Fill Buffer Data Sampling), ืึธืคึผื–ื•ืš ืคื•ืŸ ืคึผืœืึธืžื‘ื™ืจืŸ ื‘ืึทืคืขืจ ืื™ื ื”ืึทืœื˜. ื’ืขื•ื•ื™ื™ื ื˜ ืื™ืŸ ZombieLoad ืื•ืŸ RIDL ืื ืคืืœืŸ. CVSS 6.5;

CVE-2019-11091 - MDSUM (ืžื™ื™ืงืจืึธื•ืึทืจื˜ืฉื™ื˜ืขืงื˜ื•ืจืึทืœ ื“ืึทื˜ืึท ืกืึทืžืคึผืœื™ื ื’ ื•ื ืงืึทื˜ืฉืขืึทื‘ืœืข ื–ื›ึผืจื•ืŸ), ืึธืคึผื–ื•ืš ืคื•ืŸ ื•ื ืงืึทื˜ืฉืึทื‘ืึทืœ ื–ื›ึผืจื•ืŸ ืื™ื ื”ืึทืœื˜. ื’ืขื•ื•ื™ื™ื ื˜ ืื™ืŸ ื“ื™ RIDL ื‘ืึทืคืึทืœืŸ. CVSS 3.8.

ืžืงื•ืจ: linux.org.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’