Googleãçºè¦ãããCPUã®èå¼±æ§ãã¨ã¯ä½ãªã®ããã²ã¼ãã¼ã«æ§ããæ£ããæããããã®æ¹æ³ã¾ã¨ã ã©ã¤ã¿ã¼ï¼ç±³ç° è¡ ä¸è¬ã¡ãã£ã¢ã«ããã¥ã¼ã¹ã¨ãã¦åãä¸ããããã®ã§ï¼2017å¹´æ«ããã«ããã«é¨ããã ãããCPUã®èå¼±æ§ãã«ã¤ãã¦ã¯ï¼4Gamerèªè ãå¤ããèãåãã§ãããã¨ã ãããæµ·å¤ã§ã¯ï¼ãSpectreãï¼ã¹ãã¯ã¿ã¼ï¼ããMeltdownãï¼ã¡ã«ããã¦ã³ï¼ã¨ãã£ããã©ããã©ãããååãä»ãã¦ããã®ã§ï¼ãã¡ããç®ã«ããã¨ããèªè ãããã¨æãã ãIntel製ã®CPUã ããæã¤èå¼±æ§ã§ï¼AMD製ã®CPUãªãåé¡ãªããããå§ã¾ã£ã¦ï¼ãããããAMD製ã®CPUãåæ§ã®èå¼±æ§ãæ±ãã¦ãããï¼ããã«ã¯ãã¡ã¢ãªãã¼ã¸ã³ã°æ¹å¼ã®ä»®æ³è¨æ¶ã使ãCPUã®ãã¹ã¦ãæã¤èå¼±æ§ã§ããããªã©ã¨ï¼æ å ±ãé¯ç¶ãã¦ããã®ã§ï¼ä½ãä¿¡ãããããã®ãåãããªãã¨ãã人ãå¤ãã®ã§ã¯ãªãããããããããï¼ã¡ã¢ãªãã¼ã¸ã³ã°æ¹å¼
å¤ææ¼¢æã£ã¦ãåºæ¬çã«ã¯è¦ããªãããã æãªã¬ãããããããã ããããªãã¨ããããã åªåã足ããªãã£ã¦ããç²¾ç¥è«ã®åå°ã«ãªã£ã¦ãæå³ã§ç¾ä»£ã§ã¯ãç©æ¥µçã«å»æ¢ãã¹ããã ã¨ãæãã ãã ããªã¬ã®ãè¦ããªããã£ã¦ã®ã¯ãå å¢ç°ã®ä¸»å¼µã¨ã¯ç«ã¡ä½ç½®ãéãã å å¢ç°ã®ã人çãå·¦å³ããåé¨ã«å¿ é ã¨ãããªãã¨ãã主張ã«ã¯åè«ã§ãããã ãããèãã¦æ¬²ããã ããããã®ç«èç¹ï¼ã¹ãã©ãã¥ã¼ã³ã¨ã®éãï¼é«çå¦æ ¡å¦ç¿æå°è¦é ãã¹ã¿ã¼ãã«ããã®ã¯åæãã¦ããããã¨æãã ããããã¨ãå¤ææ¼¢æã£ã¦ãå½èªãã®ä»¥ä¸ã®6ã¤ã®ç§ç®ã®ãã¡2ã¤ã«ãããã å½èªç·åå½èªè¡¨ç¾ç¾ä»£æAç¾ä»£æBå¤å ¸Aå¤å ¸Bå¤å ¸Aã¨å¤å ¸Bã ããªã ã ããããã³ã¡ã®ãæ¼¢æã«ã¯ââã¨ããå¹è½ããããã¨è¨ãã®ã¯å ¨é¨ãã¡ã§ã ãããè¨ããªããæ¼¢æãããã¹ãã©ãã¥ã¼ã³ãã«ç½®ãæãã¦ãåãè«ç«ã¦åºæ¥ãããªï¼ã£ã¦ãªãã ãã®è«ç«ã¦ã ã¨åè«ã«ãªã£ã¦ãªãã£ã¦ã®ã¯è¯ãåãã
by ã©ã¤ããã¢ãã¥ã¼ã¹ç·¨éé¨ ãã£ããè¨ã㨠æ±å¤§ç100人ã¸ã®èª¿æ»ã§ã¯ã47人ããã¢ããç¿ã£ãçµé¨ãæã£ã¦ãã è³ç§å¦ã®è¦³ç¹ã§ãããã¢ãã®å¹æã¯å®è¨¼ããã¦ãã¦ããã¨é³æ¥½ã¸ã£ã¼ããªã¹ã 人éæ§ç¥è½ãHQãã«ããã¦ãçªåºãã¦é«ãå¹æãè¦ãããã¨ãã æä¾ç¤¾ã®é½åã«ãããåé¤ããã¾ããã æ¦è¦ã®ã¿æ²è¼ãã¦ããã¾ãã é¢é£ãã¥ã¼ã¹ ã©ã³ãã³ã° ç·å å½å æ¿æ²» æµ·å¤ çµæ¸ IT ã¹ãã¼ã è¸è½ 女å
ç±³å½æéã®1æ3æ¥ãã³ã³ãã¥ã¼ã¿ç³»æ å ±ãµã¤ããThe Registerãããã¤ã³ãã«è£½ããã»ããµã®ãã°ãåå ã¨ããæ·±å»ãªã»ãã¥ãªãã£ãã¼ã«ãçºè¦ããããã¨å ±éããã®å¯¾çã«ã¯ãã¼ãã¦ã§ã¢ãã®ãã®ã®å¤æ´ãå¿ è¦ã§ãããã½ããã¦ã¨ã¢ã§å¯¾çãè¡ã£ãå ´åã«ã¯å¤§å¹ ãªæ§è½ä½ä¸ãå¼ãèµ·ããã¨ã®å 容ãå«ãè¨äºãçºè¡¨ããã ãã°ã¯ã¤ã³ãã«è£½ããã»ããµã®ã¿ã§çºçãããã¹ã¯ã¼ãããã°ã¤ã³ãã¼ããã£ãã·ã¥ãã¡ã¤ã«ãªã©ããã«ã¼ãã«ã¡ã¢ãªï¼åºæ¬ã½ããã®æ ¸ã¨ãªãé¨åã§èªã¿æ¸ãããã¡ã¢ãªï¼ããçãã¦ãã¾ããã¨ããå 容ãæ¬å½ã§ããã°ãã¤ã³ãã«ã«ã¨ã£ã¦è´å½çã¨ãããã失æ ã ã ãã®æ å ±ã¯ç´å¾ã®ã¤ã³ãã«ã®æ ªä¾¡ã«ãå°ãªããã¬å½±é¿ãä¸ããããã£ããããã®å®æ ã¨ã¯ã©ã®ãããªãã®ãªã®ã ãããã ãã®ãã°ã¯ã¤ã³ãã«ã ãã®åé¡ã§ã¯ãªã å®ã¯ãã®ãã°ã¯ã¤ã³ãã«ã ãã®åé¡ã§ã¯ãªãããã¾ããã½ã³ã³ã ãã®åé¡ã§ããªãã極ãã¦åºãç¯å²ã®å½±é¿ããããã°ã§
2018å¹´1æ3æ¥ã«CPUã«é¢é£ãã3ã¤ã®èå¼±æ§æ å ±ãå ¬éããã¾ãããå ±åè ã«ããã¨ãããã®èå¼±æ§ã¯MeltdownãSpectreã¨å¼ç§°ããã¦ãã¾ããããã§ã¯é¢é£æ å ±ãã¾ã¨ãã¾ãã èå¼±æ§ã®æ¦è¦ å ±åè ãèå¼±æ§æ å ±ã次ã®å°ç¨ãµã¤ãã§å ¬éããã Meltdown and Spectre (ã¾ãã¯ãã¡ã) 3ã¤ã®èå¼±æ§ã®æ¦è¦ãã¾ã¨ããã¨æ¬¡ã®éãã èå¼±æ§ã®å称 Meltdown Spectre CVE CVE-2017-5754ï¼Rogue data cache loadï¼ CVE-2017-5753ï¼Bounds check bypassï¼ CVE-2017-5715ï¼Branch target injectionï¼ å½±é¿ãåããCPU Intel IntelãAMDãARM CVSSv3 åºæ¬å¤ 4.7(JPCERT/CC) 5.6(NIST) âã«åã PoC å ±åè éå ¬é è«æä¸ã«x
ç岡ããã@第9å·»3ï¼12çºå£² @rukiuki_k ä»å¹´ã¯é¶´å²¡å «å¹¡å®®è¡ã£ã¦ãããã§ããã©ããããã®è¦åå¡ã®ç·å¥³ã®å¶æãã«ãã³ãããã¦ããã£ããç´ ãè¦åå¡ãç®ã®ä¿é¤ãããã¼ ç§ã¯è¦éãã¦ãã¾ã£ããã©åè¡è ã®è¨¼è¨ã§ã¯ã³ã¼ãè±ãã 姿ããã£ãããã¨ã®ã㨠åçæ®ãæããã®ãï¼çªå£æãã redcoats.net 2018-01-04 17:52:36
声åªã®å°åå¯ããã¨æ¥é«éèãããã5æ¥çºå£²ã®ãã³ã¬èªãã¤ã³ã°ã¬ã³ã¬ã³ãï¼ã¹ã¯ã¦ã§ã¢ã»ã¨ããã¯ã¹ï¼2å·ã®è¡¨ç´ã«ç»å ´ããã å°åããã¨æ¥é«ããã¯ã1æã«ã¹ã¿ã¼ããããã¬ãã¢ãã¡ããã ãããã®ãããã¨ï¼ãã«åºæ¼ãããã¨ãããåå·ã§ãâ競æ¼âã2人ã¯ã人æ°ä»²è¯ã声åªã³ã³ããã¨ç´¹ä»ãããä½ãå¯ãåã£ãããé¡ãè¿ã¥ãã¦ããåçãªã©ãæ²è¼ãããã åå·ã¯ããã ãããã®ãããã¨ï¼ãã®ã³ãã«ã©ã¤ãºãå·»é ã«ã©ã¼ã飾ã£ãã
ãããããç´å¾ã®ããçç±ãæãã¦ããã ä»å¹´ãããããã»ã³ã¿ã¼è©¦é¨ã ãä½ã®ç½ªããªãé«æ ¡çãã¡ãããå¤æã»æ¼¢æãã¨ããæè¨ã²ã¼ã ãå¼·å¶ãããä¸å½ã«ã人çãå·¦å³ããã¦ããã ããã¯å®å¦è³ä¸ä¸»ç¾©è ã§ã¯ãªããå¦åãã社ä¼ã«å¯¾ãã¦æçã§ããå¿ è¦ã¯ããã£ã½ã£ã¡ããªãããããããå¤æã»æ¼¢æãã¨ãã"å¦å"ããæ ¹æ¬çã«ç¡æå³ã ã¨ç«è¨¼ããã ãã®éå ·ã¯ãªãã大å¦ã§å°éçã«ç 究ãã¦ãã人ãã¡ã«ã¨ã£ã¦ãå¤æã»æ¼¢æã¯ã©ãã¾ã§ããé¢ç½ãã¦ããé åããããã®ãç解ã§ããããå½¹ã«ç«ã¤ç«ããªãããããªãã¦ã好ããã§å¦ã¹ãã®ã¯ç´ æµãªãã¨ã ã¨æããã好ããªäººã®ããã«ãããã£ãå ´ãç¨æããã®ã¯ç¤¾ä¼ã®ç¾©åã ã¨æããå¤å°ãªãã¨ãå ±æè½åã¨è¯å¿ããããã ã£ãããæå¦é¨ä¸è¦è«ã¨ãè¨ã£ã¦ãªãã§ç¨éæå ¥ããããã£ã¦æãã ããããã«è¨ãããã®ã¯ãããã§ã®å¤æã»æ¼¢æä¸è¦è«ã¨ã大å¦ã§ã®æå¦é¨ä¸è¦è«ã¯å ¨ããã¨ãªãè°è«ã ã£ã¦ãã¨ã å°éçãªå¦åãã
ç§ã¯30æ³ãç®åã«ãã27æ³ã®å¥³ã ã ä¸éä¸è¬çã«è¦ãã°çµå©é©é½¢æã®å¹´é½¢ã§å¨ãã®ã»ã¨ãã©ãçµå©ãã¦ãã¦åä¾ãããã ãã®å¹´ã«ãªã£ã¦è¨ãããäºãå¤ãã®ã¯ãçµå©ãã¨è¨ãè¨èã ã æ°å¹´åããç§ã®æ¯ãç§ã®çµå©ãæ¥ãããããªè¨èãå£ã«ããããã«ãªã£ãã ããã¤çµå©ããã®ï¼ã ãæ©ãçµå©ããªããã è¨ãããè¨èããã¥ã¢ã³ã¹ãéã£ãã¨ãã¦ãæ¦ããããªè¨èãæ¯æ¥ã®ããã«è¨ãããããã«ãªã£ãã æ¯ã®è¨èãæ£ããã¨ãæã£ã¦ããªããééã£ã¦ããã¨ãæã£ã¦ã¯ããªãã 確ãã«å¹´é½¢ãèããã°çµå©ãèããå¹´ã§ã¯ããããç§èªèº«ãçµå©ã«å¯¾ãã¦ã¾ã£ããèå³ããªãããã§ããªãã£ãããã ããã ãä»ã¯ã©ããã¦ãåéã¨éãã ãä¸äººã§ããäºã楽ããã¦ãè¯ãç¸ãããã°çµå©ãã¨èãã¦ã¯ãããä»ã¯ã¾ã ããã¨è¨ãèãã§ããã ãã ã£ãã®ã ã ã§ããæ¯ã«ã¯ç§ã®ãã®èãã¯ä¼ãããªããã¾ã èãã¦ããªãã¨è¨ãã°ããããªã®ã¯ãã¡ã ã¨è¨ããããã®ãã¡ã¨çã
å µåº«ç西宮å¸ã®ä»æå²³å¸å¸é·ï¼ï¼ï¼ï¼ãï¼æ¥ååãåå¸å½¹æå ã§ã®ä»äºå§ãå¼ã§ï¼æã®å¸é·é¸ã«ç«åè£ããªãèãã表æããå¾ãåæã®ããé§ãå¯ã£ãèªå£²æ°èã®ï¼ï¼ä»£ç·æ§è¨è ã«å¯¾ãã殺ãããã¨è¨ã£ã¦åæãæå¦ãããç¥æ¸æ°èãå«ããè¤æ°ã®è¨è ãç¾å ´ãç®æãã¦ãããç·æ§è¨è ã¯æ¨å¹´ï¼ï¼æã«ä»ææ°ã®èªå® ã«åæã«è¨ªãã¦ãããä»ææ°ã¯ããã«è ¹ãç«ã¦ã¦ããã¨ã¿ãããã主ãªããåãã¯æ¬¡ã®éãã ï¼ä»äºå§ãå¼çµäºå¾ãä¼å ´ããåºã¦ããä»æå¸é·ã«è¨è ï¼äººãè¿ã¥ãï¼ å¸é·ã殺ãã ï¼å¸é·ãèªå£²æ°èè¨è ã®é °ã«è§¦ãããæ©ãåºãï¼ èªå£²æ°èè¨è ãï¼å¼ã§ã®çºè¨ã®ï¼æå³åããæãã¦ãã ãããå°ãã§ãããã§ãã å¸é·ããåãããã ãé·ãããã¹ã£ãããã è¨è ãï¼å¼ã§ããã¹ã£ãããã¨ãã£ã¦ï¼è³ªåã«çããªããã¨ï¼çç±ï¼ã«ãªããªãã®ã§ã¯ã å¸é·ãâ¦ï¼ç¡è¨ï¼ è¨è ãé¸æã«åãã£ãããã§ãããã å¸é·ã⦠è¨è ãèªåã ãçºè¨ãã¦çµããã¨ããã®ã¯å¹¼ç¨
森永ã§ãã æ°å¹´æ©ã 大å¤ãªèå¼±æ§ãåºã¦ãã¦ã»ãã¥ãªãã£ã¯ã©ã¹ã¿ãããã¤ãã¦ã¾ãã å 容ã«ãã£ã¦2ã¤ã®èå¼±æ§ã«åããã¦ãã¦ããMeltdownãã¨ãSpectreãã¨ååãã¤ãããã¦ãã¾ãã ç¾å¨ä½¿ç¨ããã¦ããã»ã¼å ¨ã¦ã®CPUã«ããã¦å¯¾è±¡ã¨ãªãããã¨ããç¸å½å½±é¿ç¯å²ãåºãèå¼±æ§ã§ãã ã¾ã 詳細ãå ¬éããã¦ããªãé¨åãããã¾ããããããã§å¯¾å¦ã§ããèå¼±æ§ã§ãã®ã§è½ã¡çãã¦å¯¾å¿ããç¶å ±ãå¾ ã¡ã¾ãããã ç¾å¨åãã£ã¦ããç¯å²ã®æ å ±ãã¾ã¨ãã¾ãã Meltdown and Spectre æ¦è¦ ä»åã®èå¼±æ§ã¯å¤§ãã3ã¤ã«åãããã¾ãã Variant 1: bounds check bypass (CVE-2017-5753) Variant 2: branch target injection (CVE-2017-5715) Variant 3: rogue data cache load (CV
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}