I-Intel ishicilele ulwazi mayelana nesigaba esisha sobungozi

I-Intel ishicilele ulwazi mayelana nekilasi elisha lobungozi kubacubunguli bayo - MDS (Microarchitectural Data Sampling). Njengokuhlasela kwe-Specter okwedlule, izinkinga ezintsha zingaholela ekuvuzeni kwedatha yobunikazi kusistimu yokusebenza, imishini ebonakalayo, nezinqubo zangaphandle. Kusolwa ukuthi izinkinga ziqale zahlonzwa ngabasebenzi be-Intel nabasebenzisana nabo ngesikhathi socwaningo lwangaphakathi. NgoJuni nango-Agasti 2018, ulwazi mayelana nezinkinga luphinde lwanikezwa i-Intel ngabacwaningi abazimele, ngemva kwalokho cishe unyaka wonke womsebenzi ohlanganyelwe wenziwa nabakhiqizi nabathuthukisi besistimu yokusebenza ukuze kutholakale ama-vectors okuhlasela okungenzeka futhi balethe ukulungiswa. I-AMD ne-ARM processors abathinteki kule nkinga.

Ubungozi obuhlonziwe:

CVE-2018-12126 - MSBDS (Microarchitectural Store Buffer Data Sampling), ukubuyiselwa kokuqukethwe kwebhafa yokugcina. Isetshenziswe ekuhlaselweni kwe-Fallout. Izinga lengozi linqunywa ukuthi libe amaphuzu angu-6.5 (CVSS);

CVE-2018-12127 - MLPDS (Microarchitectural Load Port Data Sampling), ukutholwa kokuqukethwe kwembobo yokulayisha. Isetshenziswe ekuhlaselweni kwe-RIDL. I-CVSS 6.5;

CVE-2018-12130 - MFBDS (Microarchitectural Fill Buffer Data Sampling), ukubuyiselwa kokuqukethwe kwebhafa yokugcwalisa. Isetshenziswa ekuhlaselweni kwe-ZombieLoad ne-RIDL. I-CVSS 6.5;

I-CVE-2019-11091 - MDSUM (I-Microarchitectural Data Sampling Uncacheable Memory), ukubuyiselwa kokuqukethwe kwememori okungenakufinyeleleka. Isetshenziswe ekuhlaselweni kwe-RIDL. I-CVSS 3.8.

Source: linux.org.ru

Engeza amazwana