CVE-2020-13844 | ARM CPU SLS·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-06-17

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-13844

ʱ    ¼ä

2020-06-17

Àà    ÐÍ

µÈ    ¼¶

ÖÐΣ

Ô¶³ÌÀûÓÃ

·ñ

Ó°ÏìÁìÓò

Arm Armv8-A


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



2020Äê6Ô£¬GoogleµÄSafeSideÓ××éÔÚARM´¦ÖÃÆ÷µÄArmv8-A£¨Cortex-A£©CPUϵͳ½á¹¹Öз¢ÏÖÁËÒ»¸öÃûΪ¡°Straight-Line Speculation £¬SLS¡±µÄзì϶£¨CVE-2020-13844£©¡£¸Ã·ì϶µ¼Ö¹¥»÷Õß¶ÔARM¼Ü¹¹´¦ÖÃÆ÷½øÐвàÐÅ·¹¥»÷¡£

SLSÊDzàÐÅ·¹¥»÷Àï±ÈÁ¦¾­µäµÄÒ»ÖÖ£¬Äܹ»Èô¦ÖÃÆ÷Ô¤ÏȽӼûÊý¾ÝÀ´ÌáÉý»úÄÜ£¬¶øºóÅׯúËùÓÐû±»Ê¹ÓùýµÄÍÆËã·ÖÖ§¡£ÖîÈç´ËÀàµÄ²àͨ·¹¥»÷Äܹ»Èù¥»÷Õß¿ÉÄÜ´Ó´¦ÖÃÆ÷ÇÔÈ¡Êý¾Ý¡£

ARMÈ·ÈÏSLSÊÇԭʼSpectre·ì϶µÄÒ»ÖÖ±äÌ壬Spectre·ì϶·¢ÏÖÓÚ2018Äê1Ô£¬¸Ã·ì϶µ¼Ö¹¥»÷ÕßÄܹ»ÇÔÈ¡ÍÆËã»úÄÚ´æÖеÄÐÅÏ¢£¬Éæ¼°´æ´¢ÔÚÃÜÂëÖÎÀíÆ÷»òä¯ÀÀÆ÷ÖеÄÃÜÂë¡¢Ó×ÎÒÕÕÆ¬¡¢µç×ÓÓʼþ¡¢¼´Ê±ÐÂÎÅ¡¢ÉõÖÁÊǹؼüÒµÎñÎĵµ¡£SLSºÍSpectre·ì϶µÄÓ°ÏìÁìÓò·ÖÆç£¬SLS½öÓ°ÏìArm Armv-A´¦ÖÃÆ÷£¬¶øSpectreÓ°ÏìËùÓÐÖ÷Á÷оƬÔì×÷É̵ÄCPU¡£

µ½Ä¿Ç°ÎªÖ¹£¬¸Ã·ì϶»¹Ã»ÓÐÔÚÒ°ÀûÓᣵ«Ë¼¿¼µ½ARM´¦ÖÃÆ÷µÄÀûÓÃÁìÓò¼«¶ÈÖ®¹ã£¬Éæ¼°ÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄÔÉõÖÁµ¥Æ¬»úµÈ£¬ËùÒԸ÷ì϶µÄÓ°ÏìÁìÓò±ÈÁ¦´ó¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡£¬Ô̺¬FreeBSD£¬OpenBSD£¬Trusted Firmware-AºÍOP-TEE¡£²¹¶¡Á´½Ó£º

https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability/latest-updates

ÆäËûһʱ´ëÊ©£º

ARMÔÚÆä°×ƤÊéÖÐÌṩÁË»º½â´ëÊ©£¬ÏÂÔØÁ´½Ó£º

https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability/downloads/arm-v8-5-a-cpu-updates


0x03 ÓйØÐÂÎÅ


https://cyware.com/news/arm-cpus-face-threats-from-new-variant-of-spectre-vulnerability-44250570/?web_view=true


0x04 ²Î¿¼Á´½Ó


https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability/downloads

https://spectreattack.com/#faq-systems-spectre


0x05 ¹¦·òÏß


2020-06-08 ARM¸üзì϶²¹¶¡

2020-06-17 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾