AMD ืืื ืืขืืืืจื ื ืึทื ืฆืืืื ืืึทืคืึทืื ืืขืืืึธืืก ืืขื ืขื ืืืืขื ืึทืคืืื ืืืึธืก ืงืขื ืขื ืืืืคึผืึทืก ืื AMD SEV (Secure Encrypted Virtualization) ืืืืขืจืืืื ืืขืงืึทื ืืืึทื. ืืขืจ ืคึผืจืึธืืืขื ืึทืคืขืงืฅ ืื ืขืจืฉืืขืจ, ืจืืข ืืื ืืจืื ืืืจืืช ืคืื AMD EPYC ืคึผืจืึทืกืขืกืขืจื (ืืืืืจื ืืืืฃ ืื Zen1 - Zen3 ืืืงืจืึธืึทืจืืฉืืืขืงืืืจืข), ืืื ืืขืืื ื ืืื ืขืืืขืืื AMD EPYC ืคึผืจืึทืกืขืกืขืจื.
AMD SEV ืืืืฃ ืื ืืึทืื ืืืึทืจื ืืืจืื ืืื ืืจืึทื ืกืคึผืขืจืึทื ื ืขื ืงืจืืคึผืฉืึทื ืคืื ืืืืจืืืึทื ืืึทืฉืื ืืึผืจืื, ืืื ืืืึธืก ืืืืื ืื ืงืจืึทื ื ืืึทืกื ืกืืกืืขื ืืื ืึทืงืกืขืก ืฆื ืืขืงืจืืคึผืืื ืืึทืื, ืืื ืื ืืขืจืข ืืืืจืืืึทื ืืืฉืื ืขื ืืื ืื ืืืืคึผืขืจืืืืืืขืจ ืืึทืงืืืขื ืึท ืื ืงืจืืคึผืืื ืืึทื ื ืคืื ืืึทืื ืืืขื ืืืจ ืคึผืจืืืื ืฆื ืึทืงืกืขืก ืืขื ืืึผืจืื. ืื ืืืืขื ืึทืคืืื ืืฉืื ืืึธืื ืึท ืึทืืึทืงืขืจ ืืื ืึทืืืื ืืกืืจืึทืืืืืข ืจืขืื ืืืืฃ ืื ืกืขืจืืืขืจ ืืื ืงืึธื ืืจืึธื ืคืื ืื ืืืืคึผืขืจืืืืืืขืจ ืฆื ืืืืคึผืึทืก AMD SEV ืจืืกืืจืืงืฉืึทื ื ืืื ืืืกืคืืจื ืืืืขืจ ืงืึธื ืืื ืืขื ืงืึธื ืืขืงืกื ืคืื ืคึผืจืึธืืขืงืืขื ืืืืจืืืึทื ืืืฉืื ืขื.
ืืืืขื ืึทืคืืื ืืฉืื:
- CVE-2021-26311 (ืึทื ืืขืจืืื ืืึทืคืึทืื) - ืืืจื ืืึทื ืืคึผืืึทืืืืฉืึทื ืคืื ืืฉืึทื ืืื ื ืื ืกืืจ ืคืื ืืึผืจืื ืืืึทืงืก ืืื ืื ืึทืืจืขืก ืคึผืืึทืฅ ืคืื ืื ืืึทืกื ืกืืกืืขื, ืืืื ืืืจ ืืึธืื ืงืึธื ืืจืึธื ืืืืขืจ ืื ืืืืคึผืขืจืืืืืืขืจ, ืืืจ ืงืขื ืขื ืืืกืคืืจื ืืืื ืงืึธื ืืื ืื ืืึทืกื ืืืืจืืืึทื ืืึทืฉืื, ืืจืึธืฅ ืื ื ืืฆื ืคืื ืึทืื ืกืขืื / ืกืขืื-ืขืก ืฉืืฅ. ืจืขืกืขืึทืจืืฉืขืจืก ืืึธืื ืฆืืืขืืจืืื ืึท ืคึผืจืึธืืืึทืืืืคึผ ืคืื ืึท ืื ืืืืขืจืกืึทื ืืืืืจืข ืืืึธืก ืจืืืจืืคึผืก ืืืึทืงืก ืคืื ืืึธืืืื UEFI ืืื ื ืืฆื ืฆืืจืืงืงืืืขื-ืึธืจืืขื ืืื ืคึผืจืึธืืจืึทืืืื ื (ROP - Return-Oriented Programming) ืืขืงื ืืงืก ืฆื ืึธืจืืึทื ืืืืจื ืื ืืืจืืคืืจืื ื ืคืื ืึทืจืืืืจืึทืจืืฉ ืงืึธื.
- CVE-2020-12967 (SEVerity attack) - ืื ืคืขืื ืคืื ืืขืืขืจืืง ืฉืืฅ ืคืื ื ืขืกืืขื ืืึผืจืื ืืืึทื ืืืฉื ืืื AMD SEV/SEV-ES ืึทืืึทืื, ืืืื ืืืจ ืืึธืื ืึทืงืกืขืก ืฆื ืื ืืืืคึผืขืจืืืืืืขืจ, ืฆื ืึธืจืืึทื ืืืืจื ืื ืกืึทืืกืืืืืฉืึทื ืคืื ืงืึธื ืืื ืื ืืึทืกื ืกืืกืืขื ืงืขืจื ืืื ืึธืจืืึทื ืืืืจื. ืื ืึทืจืืืขืจืคืืจื ืคืื ืงืึธื ืืจืึธื ืฆื ืืขื ืงืึธื. ืืขืจ ืืืคึฟื ืึทืืึทืื ืืืจ ืฆื ืืึทืงืืืขื ืคืื ืงืึธื ืืจืึธื ืืืืขืจ ืื ืคึผืจืึธืืขืงืืขื ืืึทืกื ืกืืกืืขื ืืื ืขืงืกืืจืึทืงื ืงืึทื ืคืึทืืขื ืืฉืึทื ืืึทืื ืคืื ืขืก.
ืฆื ืึทื ืืงืขืื ืฉืืขืื ืื ืคืืจืืขืืืืื ืืึทืคืึทืื ืืขืืืึธืืก, AMD ืืื ืฆืืืขืืจืืื ืื SEV-SNP (Secure Nested Paging) ืคืึทืจืืขื ืืขืจืื ื, ืื ืืืฆื ืืื ืึท ืคืืจืืืืึทืจืข ืืขืจืืืึทื ืืืงื ืคึฟืึทืจ ืื ืืจืื ืืืจ ืคืื AMD EPYC ืคึผืจืึทืกืขืกืขืจื ืืื ืคึผืจืึทืืืืืืื ื ืืืืขืจ ืึธืคึผืขืจืึทืฆืืข ืืื ื ืขืกืืขื ืืึผืจืื ืืืึทื ืืืฉื. ืืื ืึทืืืฉืึทื ืฆื ืึทืืืขืืืื ืืึผืจืื ืขื ืงืจืืคึผืฉืึทื ืืื ืื SEV-ES (Encrypted State) ืคืึทืจืืขื ืืขืจืื ื ืืืึธืก ืคึผืจืึทืืขืงืฅ ืงืคึผื ืจืขืืืฉืืกืืขืจื, SEV-SNP ืืื ื ืึธื ืฉืืฅ ืคืื ืืึผืจืื ืึธืจื ืืืขืืงืืึทื ืืืึธืก ืงืขื ืขื ืืืืืกืืึทื ื ืื ืคืืื ืคืื ืืืืคึผืขืจืืืืืืขืจื ืืื ืืื ื ืึธื ืฉืืฅ ืงืขืื ืืืึทื-ืงืึทื ืึทื ืื ืคืืื.
ืืงืืจ: opennet.ru