ä¸å½ã»ä¸æµ·ã§éãããè¦æ¬å¸ã§ç±³åå°ä½å¤§æAMDã®ã«ã¦ã³ã¿ã¼ã«ç«ã¤è¨ªå客ãIMAGINECHINAæä¾ï¼2013å¹´7æ25æ¥æ®å½±ãè³æåçï¼ã(c)WENG LEI / IMAGINECHINA ã3æ14æ¥ AFPãã¤ã¹ã©ã¨ã«ã®æ å ±ã»ãã¥ãªãã£ã¼ä¼æ¥CTSã©ãï¼CTS Labsï¼ã¯13æ¥ãç±³åå°ä½å¤§æã¢ããã³ã¹ãã»ãã¤ã¯ãã»ããã¤ã¹ï¼AMDï¼ã®ææ°CPUããããã»ããã«ãã³ã³ãã¥ã¼ã¿ã¼ããããã¯ã¼ã¯ã®ä¹ã£åãã«å©ç¨ãããæããããæ¬ é¥ãè¦ã¤ãã£ãã¨æããã«ããã ä»å¹´åãã«ã¯ãç±³ã¤ã³ãã«ï¼Intelï¼è£½ã®CPUã«ããã¹ãã¯ã¿ã¼ï¼Spectreï¼ãããã¡ã«ããã¦ã³ï¼Meltdownï¼ãã¨å¼ã°ããåæ§ã®èå¼±ï¼ãããããï¼æ§ãè¦ã¤ãããã³ã³ãã¥ã¼ã¿ã¼ã»ãã¥ãªãã£ã¼ããããæ¸å¿µãåºã¾ã£ã¦ããã CTSãå ¬è¡¨ãã20ãã¼ã¸ã®å ±åæ¸ã«ããã°ãä»åè¦ã¤ãã£ãæ¬ é¥ã¯13件ã§ãåé¡ã®è£½åã¯ä¸è¬æ¶è²»è åãã®è£½
AMDã¯ãå社ã®è¤æ°ã®ããã»ããµã«13件ã®ã»ãã¥ãªãã£èå¼±æ§ãããã¨ããå ±åã«ã¤ãã¦èª¿æ»ãã¦ããã ãããã¡ã¼ã«ã¼ã®AMDã¯ç±³å½æé3æ13æ¥ã®å£°æã§ãCTS Labsã®èª¿æ»çµæã«ã¤ãã¦ã調æ»ã¨åæãéæé²ãã¦ãããã¨è¿°ã¹ããCTS Labsã¯ãã¾ãç¥ããã¦ããªãããã¤ã¹ã©ã¨ã«ã®ãã«ã¢ããã«æ¬ç¤¾ãç½®ããµã¤ãã¼ã»ãã¥ãªãã£ã®æ°èä¼æ¥ã ã AMDã声æãçºè¡¨ããæ°æéåã«ãCTS Labsã¯ãRYZENFALLããMASTER KEYããFALLOUTããCHIMERAãã¨åä»ãã13ã®èå¼±æ§ã«ã¤ãã¦èª¬æããã¦ã§ããµã¤ããç 究è«æãåç»ãå ¬éãããæ»æè ããããã®èå¼±æ§ãå©ç¨ããã¨ãè¨å¤§ãªæ°ã®ç«¯æ«ã«æè¼ããã¦ããAMDã®ãRyzenãããã³ãEPYCãããã»ããµããæ©å¯ãã¼ã¿ãåå¾ã§ããå¯è½æ§ãããã¨ä¸»å¼µãã¦ããã å ¬éããããã¯ã¤ããã¼ãã¼ã«ã¯ããããã®èå¼±æ§ã®å ·ä½çãªå 容ã詳ããè¨è¿°ããã¦
Amazon Web Servicesï¼AWSï¼ã¯ããSpectreãããã³ãMeltdownãã¨åä»ããããCPUã®èå¼±æ§ã«é¢ãã¦å社ã®å¯¾å¿ãã¾ã¨ããWebãã¼ã¸ãProcessor Speculative Execution Research Disclosureãã«ããã¦ããã§ã«èå¼±æ§å¯¾çãæ¸ãã ãã¨ãå ±åãã¦ãã¾ãã AWSãããããç¹è¨ãã¼ã¸ãè¨ããã®ã¯çãããã¨ã§ãæ¬ä»¶ã®éè¦æ§ã¨ç·æ¥æ§ã®é«ããããããã¾ãã ãã ãGoogleãèå¼±æ§ã®è©³ç´°ãªå ±åã¨å¯¾çã®çµç·¯ãªã©ã詳細ã«ããã°ã§é示ããã®ã«å¯¾ããAWSã®æ å ±æä¾ã¯å®åçã§ãã£ãããããã®ã«ãªã£ã¦ãã¾ãã Amazon EC2ã®ã¯ã¼ã¯ãã¼ãã«æ§è½ä½ä¸ã¯è¦ãããªã ä¸è¨ã¯Amazon EC2ã«é¢ããå ±åãå¼ç¨ãããã®ã§ãããã¹ã¦ã®å¯¾çãæ¸ãã ã¨å ±åããã¦ãã¾ããã¾ããOSã®ã¢ãããã¼ããæ¨å¥¨ããã¦ãã¾ãã All instances
ãCPUã®èå¼±æ§ãã«æå ã®ã²ã¼ã PCã¯å¯¾çã§ãã¦ããã®ããWindowsç°å¢ã§ç°¡åã«ãã§ãã¯ã§ãããã¼ã«ãä½ã£ã¦ã¿ã ã©ã¤ã¿ã¼ï¼ç±³ç° è¡ 12â åç±³æé2018å¹´1æ3æ¥ã«Googleã®ã»ãã¥ãªãã£ç 究ãã¼ã ãProject Zeroããçºè¡¨ããCPUã®èå¼±æ§ã«ã¤ãã¦ï¼4Gamerã§ã¯å ã«ï¼èå¼±æ§ã®æ¦è¦ã¨ï¼ã²ã¼ãã¼ã¯ã©ããã¹ããã¨ãã£ãç¹ãã¾ã¨ãã¦ããï¼é¢é£è¨äºï¼ã ããããã¾ã æ°æ¥ããçµéãã¦ããªããï¼é¢é£å社ã®å¯¾å¿ã¯è¿ éã§ï¼æ¬ç¨¿ãå·çãã¦ãã1æ10æ¥ã®æç¹ã§ã»ã¼åºæã£ããã¾ãï¼ã²ã¼ãã¼ãªãæ°ã«ãªãã§ããããæ§è½ã¸ã®å½±é¿ãã«ã¤ãã¦ãï¼å社ããå ¬å¼ã³ã¡ã³ããåºã¤ã¤ããç¶æ³ã ã ä»åã¯ï¼4Gamerèªè ã®ä¸ã§ãã¨ãã«ã¦ã¼ã¶ã¼æ°ãå¤ãã¨æãããWindowså´ã®å¯¾å¿ãä¸å¿ã«ï¼ããã¾ã§ã®åããã¾ã¨ãã¦ã¿ããã Variant2ã®å¯¾çã«ã¯BIOSï¼UEFIï¼ã®ã¢ãããã¼ããå¿ è¦ 1æ5æ¥æ²è¼ã®
2018å¹´ã®å¹´æãæ©ã ãæ°ãã«çºè¦ããããããã»ããµã®èå¼±ï¼ãããããï¼æ§ãã«é¢ãã¦ããã¾ãã¾ãªæ å ±ãé£ã³äº¤ããä¸é¨ã§ã¯èª¤è§£ãæ··ä¹±ãæãã¦ããã å§ã¾ãã¯ãè±ITæ å ±ãµã¤ãã®The Registerãå ¬éãã1æ2æ¥ï¼ç¾å°æéï¼ã®è¨äºã ããIntelããã»ããµã®ãã°ãçºè¦ããããã¼ãã¦ã§ã¢ã®å¤æ´ãå¿ è¦ã§ãããã½ããã¦ã§ã¢ã§ã®ã»ãã¥ãªãã£å¯¾çã¯ããã©ã¼ãã³ã¹ã®å¤§å¹ ãªä½ä¸ãå¼ãèµ·ãããã¨ã®å 容ã§ããã®ãã¥ã¼ã¹ãé§ãå·¡ã£ã¦ä¸éãé¨ãããã ãã®å¾ãGoogleã¯ãã®èå¼±æ§ã®æ å ±ãã¼ã¸ãå ¬éããIntelããåæ§ã®èå¼±æ§ã¯AMDãArmã«ãããã対çã§ååä¸ãã¨çºè¡¨ãMicrosoftããã»ãã¥ãªãã£å¯¾çã«ããæ§è½ã¸ã®å½±é¿ã¯ä¸è¬ã¦ã¼ã¶ã¼ï¼ã³ã³ã·ã¥ã¼ãã¼ï¼ã§ã¯éå®çãã¨å ±åãããªã©ãé¢ä¿å社ããã®å½±é¿ã対çã«ã¤ãã¦ã次ã ã¨æ å ±ãå ¬éãã¦ãããä¸é£ã®é¨åã®æ¦è¦ãå¤æãã¦ããã ä»åã®ãã®é¨åã§ä½ãåé¡
å··ã§ã¯Intel, AMD, ARMãå·»ãè¾¼ãã CPUã®ãã° "Meltdown", "Spectre" ã話é¡ã§ãã ãããã®åé¡ãå 容ãèªã¿é²ãã¦ããã¨ãã³ã³ãã¥ã¼ã¿ã¢ã¼ããã¯ãã£ã«ãããéè¦ãªè¦ç´ ãå¤ãå«ãã§ãããã¨ãåãã£ã¦æ¥ã¾ããã ã¤ã¾ãããã®CPUã®ã»ãã¥ãªãã£åé¡ãèªã¿è§£ãã¦ããã¨ç¾ä»£ã®ãã¤ã¯ãããã»ããµãæã¤ãæ§è½åä¸ã®ããã®ãããªãæ©è½è¿½å ã®ä¸ç«¯ãè¦ãã¦ããã®ã§ã¯ãªããã¨æããGoogle, Intelã®æç®ãèªã¿è§£ãã¦ã¿ããã¨ã«ãã¾ããã ããç§ã¯ã»ãã¥ãªãã£ã®å°é家ã§ã¯ããã¾ããããéå»ã«ãã¹ã¯ãããPCåãã®ãããªå¤§è¦æ¨¡ãªCPUè¨è¨ã«åå ãããã¨ãããã¾ããã ããã¾ã§ã³ã³ãã¥ã¼ã¿ã¢ã¼ããã¯ãã£ã«æ¯è¼çè¿ãå ´æã«ãã人éã¨ãã¦ããã®åé¡ã®æ¬è³ªã¯ã©ãã«ããã®ããå¯è½ãªéãèªã¿è§£ãã¦ãããç¾ä»£ã®ãã¤ã¯ãããã»ããµãæã¤é«æ§è½ãã¤é«æ©è½ãªå é¨å®è£ ã«ã¤ãã¦è§£ãæããã¦ãã
Googleãçºè¦ãããCPUã®èå¼±æ§ãã¨ã¯ä½ãªã®ããã²ã¼ãã¼ã«æ§ããæ£ããæããããã®æ¹æ³ã¾ã¨ã ã©ã¤ã¿ã¼ï¼ç±³ç° è¡ ä¸è¬ã¡ãã£ã¢ã«ããã¥ã¼ã¹ã¨ãã¦åãä¸ããããã®ã§ï¼2017å¹´æ«ããã«ããã«é¨ããã ãããCPUã®èå¼±æ§ãã«ã¤ãã¦ã¯ï¼4Gamerèªè ãå¤ããèãåãã§ãããã¨ã ãããæµ·å¤ã§ã¯ï¼ãSpectreãï¼ã¹ãã¯ã¿ã¼ï¼ããMeltdownãï¼ã¡ã«ããã¦ã³ï¼ã¨ãã£ããã©ããã©ãããååãä»ãã¦ããã®ã§ï¼ãã¡ããç®ã«ããã¨ããèªè ãããã¨æãã ãIntel製ã®CPUã ããæã¤èå¼±æ§ã§ï¼AMD製ã®CPUãªãåé¡ãªããããå§ã¾ã£ã¦ï¼ãããããAMD製ã®CPUãåæ§ã®èå¼±æ§ãæ±ãã¦ãããï¼ããã«ã¯ãã¡ã¢ãªãã¼ã¸ã³ã°æ¹å¼ã®ä»®æ³è¨æ¶ã使ãCPUã®ãã¹ã¦ãæã¤èå¼±æ§ã§ããããªã©ã¨ï¼æ å ±ãé¯ç¶ãã¦ããã®ã§ï¼ä½ãä¿¡ãããããã®ãåãããªãã¨ãã人ãå¤ãã®ã§ã¯ãªãããããããããï¼ã¡ã¢ãªãã¼ã¸ã³ã°æ¹å¼
by Sh4rp_i ãã10å¹´éã«è£½é ãããIntelã®ããã»ããµã«ãè¨è¨ä¸ã®æ¬ é¥ãè¦ã¤ããã¾ãããææªã®å ´åããã¹ã¯ã¼ãããã°ã¤ã³ãã¼ããã£ãã·ã¥ãã¡ã¤ã«ãªã©ãæ ¼ç´ãããã«ã¼ãã«ã¡ã¢ãªã¼ã®å 容ãèªã¿åãããæããããã¨ã®ãã¨ãªã®ã§ãããIntel x86ãã¼ãã¦ã§ã¢ã«åå¨ããæ¬ é¥ã®ããããã¤ã¯ãã³ã¼ãã¢ãããã¼ãã§ã¯å¯¾å¿ä¸å¯è½ã§ãåOSãã½ããã¦ã§ã¢ã¬ãã«ã§ä¿®æ£ãããããããã°ã®ãªãæ°ããªããã»ããµãå°å ¥ããå¿ è¦ãããã¨ã®ãã¨ã 'Kernel memory leaking' Intel processor design flaw forces Linux, Windows redesign ⢠The Register https://www.theregister.co.uk/2018/01/02/intel_cpu_design_flaw/ ãã®ãã°ã¯ããã¼ã¿ãã¼ã¹ã¢ããªã±ã¼ã·ã§
ãã¤ã¯ãã½ãããCPUã®èå¼±æ§å¯¾çã§Azureã®è¨ç»ã¡ã³ããååããå ¨ãªã¼ã¸ã§ã³ã®ä»®æ³ãã·ã³ãä»æããå¼·å¶åèµ·åãGoogleã¯å¯¾çæ¸ã¿ã¨çºè¡¨ ã¤ã³ãã«ãAMDãARMãªã©ã®CPUã«åå¨ããèå¼±æ§ãçºè¦ãããåé¡ã§ããã¤ã¯ãã½ããã¯ãããããè¨ç»ããã¦ããMicrosoft Azureã®è¨ç»ã¡ã³ããã³ã¹æéãæ¥ããååãããä»æ¥1æ4æ¥ã®8æåï¼æ¥æ¬æéï¼ããAzure IaaS ä»®æ³ãã·ã³ãå¼·å¶çã«é 次åèµ·åãããã¨çºè¡¨ãã¾ããã CPU ã®èå¼±æ§ãã Azure ã®ã客æ§ãä¿è·ããããã« â Japan Azure Technical Support Engineers' Blog [éè¦: 2018 / 1 / 4 æ´æ°] [åç¥] 2018 å¹´ 1 æ 2 æ¥ãã Azure IaaS ä»®æ³ãã·ã³ã®ã¡ã³ããã³ã¹æéãéå§ãã¾ã â Japan Azure Technical Sup
森永ã§ãã æ°å¹´æ©ã 大å¤ãªèå¼±æ§ãåºã¦ãã¦ã»ãã¥ãªãã£ã¯ã©ã¹ã¿ãããã¤ãã¦ã¾ãã å 容ã«ãã£ã¦2ã¤ã®èå¼±æ§ã«åããã¦ãã¦ããMeltdownãã¨ãSpectreãã¨ååãã¤ãããã¦ãã¾ãã ç¾å¨ä½¿ç¨ããã¦ããã»ã¼å ¨ã¦ã®CPUã«ããã¦å¯¾è±¡ã¨ãªãããã¨ããç¸å½å½±é¿ç¯å²ãåºãèå¼±æ§ã§ãã ã¾ã 詳細ãå ¬éããã¦ããªãé¨åãããã¾ããããããã§å¯¾å¦ã§ããèå¼±æ§ã§ãã®ã§è½ã¡çãã¦å¯¾å¿ããç¶å ±ãå¾ ã¡ã¾ãããã ç¾å¨åãã£ã¦ããç¯å²ã®æ å ±ãã¾ã¨ãã¾ãã Meltdown and Spectre æ¦è¦ ä»åã®èå¼±æ§ã¯å¤§ãã3ã¤ã«åãããã¾ãã Variant 1: bounds check bypass (CVE-2017-5753) Variant 2: branch target injection (CVE-2017-5715) Variant 3: rogue data cache load (CV
2018å¹´1æ3æ¥ã«CPUã«é¢é£ãã3ã¤ã®èå¼±æ§æ å ±ãå ¬éããã¾ãããå ±åè ã«ããã¨ãããã®èå¼±æ§ã¯MeltdownãSpectreã¨å¼ç§°ããã¦ãã¾ããããã§ã¯é¢é£æ å ±ãã¾ã¨ãã¾ãã èå¼±æ§ã®æ¦è¦ å ±åè ãèå¼±æ§æ å ±ã次ã®å°ç¨ãµã¤ãã§å ¬éããã Meltdown and Spectre (ã¾ãã¯ãã¡ã) 3ã¤ã®èå¼±æ§ã®æ¦è¦ãã¾ã¨ããã¨æ¬¡ã®éãã èå¼±æ§ã®å称 Meltdown Spectre CVE CVE-2017-5754ï¼Rogue data cache loadï¼ CVE-2017-5753ï¼Bounds check bypassï¼ CVE-2017-5715ï¼Branch target injectionï¼ å½±é¿ãåããCPU Intel IntelãAMDãARM CVSSv3 åºæ¬å¤ 4.7(JPCERT/CC) 5.6(NIST) âã«åã PoC å ±åè éå ¬é è«æä¸ã«x
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}