AMD SEV°²È«Èƹý·ì϶£¨CVE-2021-26311£©

°ä²¼¹¦·ò 2021-05-17

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-26311

ʱ   ¼ä

2021-05-17

Àà   ÐÍ

´úÂëÖ´ÐÐ

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ


Ó°ÏìÁìÓò


PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

 

SEV£¨Secure Encrypted Virtualization£©ÊÇAMDÌá³öµÄ°²È«¼ÓÃÜÐé¹¹»¯¼¼Êõ£¬ËüʹÖ÷ÄÚ´æ½ÚÔìÓþ߱¸¼ÓÃÜÖ°ÄÜÒÔ¶ÔÐé¹¹»úÄÚ´æÊý¾Ý½øÐб£»¤¡£

½üÈÕ£¬Ð¾Æ¬Ôì×÷ÉÌAMDÕë¶ÔSEV°²È«Èƹý·ì϶£¨×·×ÙΪCVE-2020-12967ºÍCVE-2021-26311£©°ä²¼ÁËÓйع¥»÷Ö¸ÄÏ¡£Õë¶ÔÕâÁ½¸ö·ì϶µÄ¹¥»÷ºÍÓйØÏ¸½Ú½«ÓÉÓйØ×êÑÐÓ××éÔÚ½ñÄêµÄµÚ15½ìIEEE½ø¹¥¼¼Êõ×êÑлᣨWOOT'21£¬2021Äê5ÔÂ27ÈÕ£©Éϰ䷢¡£

AMD SEVÄܹ»¸ôÀëÐé¹¹»úºÍÐé¹¹»úÖÎÀí·¨Ê½£¬µ«¼´±ãʹÓÃÁËÊʵ±µÄ±£»¤»úÔ죬¹¥»÷ÕßÒ²Äܹ»ÀûÓÃÕâÁ½¸ö·ì϶Õß½«ËÁÒâ´úÂë×¢Èëµ½Ðé¹¹»ú¡£

AMD SEV/SEV-ESËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-12967£©

¸Ã·ì϶ÊÇAMD SEV/SEV-ESÖ°ÄÜÖв»×ãǶÌ×Ò³±í±£»¤Ôì³ÉµÄ£¬ÈôÊǹ¥»÷ÕßÕ¼ÓзÛËé·þÎñÆ÷ÖÎÀí·¨Ê½µÄȨÏÞ£¬Ôò¿ÉÄܵ¼ÖÂGuest VMÖеÄËÁÒâ´úÂëÖ´ÐС£

 

AMD SEV/SEV-ESËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-26311£©

¸Ã·ì϶´æÔÚÓÚAMD SEV/SEV-ESÖ°ÄÜÖС£Æ¾¾Ý¸Ã°²È«²¼¸æ£¬Äܹ»ÔÚÖ¤Ã÷»úÔìδ¼ì²âµ½µÄGuestµØÖ·¿Õ¼äÖгÁзÖÁÐÄڴ棬ÈôÊǹ¥»÷ÕßÕ¼ÓзÛËé·þÎñÆ÷ÖÎÀí·¨Ê½µÄȨÏÞ£¬ÔòÄܹ»ÀûÓô˷ì϶ÔìʵÏÖGuest VMÖеÄËÁÒâ´úÂëÖ´ÐС£

 

Ó°ÏìÁìÓò

¸Ã·ì϶ӰÏìËùÓÐAMD EPYC´¦ÖÃÆ÷£¨µÚÒ»/µÚ¶þ/µÚÈý´úAMD EPYC?´¦ÖÃÆ÷ºÍAMD EPYC?ǶÈëʽ´¦ÖÃÆ÷£©

 

0x02 ´ëÖý¨Òé

ĿǰAMDÒÑͨ¹ýSEV-SNPÖ°Äܽ¨¸´ÁË´Ë·ì϶£¬µ«¸ÃÖ°ÄܽöÔÚµÚÈý´úAMD EPYC?ÖÐÖ§³Ö£¬½¨ÒéµÚÈý´úAMD EPYC?Óû§¾¡¿ìÀûÓÃSEV-SNPÖ°ÄÜ¡£

ÓйØÁ´½Ó£º

https://developer.amd.com/sev/

 

0x03 ²Î¿¼Á´½Ó

https://developer.amd.com/sev/

https://uzl-its.github.io/undeserved-trust/

https://securityaffairs.co/wordpress/117981/security/amd-sev-attacks.html?

https://www.ieee-security.org/TC/SP2021/SPW2021/WOOT21/

 

 

0x04 ¹¦·òÏß

2021-05-16  ·ì϶Åû¶

2021-05-17  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png