AMD SEVÇå¾²ÈÆ¹ýÎó²î£¨CVE-2021-26311£©
Ðû²¼Ê±¼ä 2021-05-170x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-26311 | ʱ ¼ä | 2021-05-17 |
Àà ÐÍ | ´úÂëÖ´ÐÐ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | Ó°Ïì¹æÄ£ | ||
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà |
0x01 Îó²îÏêÇé
SEV£¨Secure Encrypted Virtualization£©ÊÇAMDÌá³öµÄÇå¾²¼ÓÃÜÐéÄ⻯ÊÖÒÕ£¬£¬£¬£¬£¬£¬ËüʹÖ÷ÄÚ´æ¿ØÖÆÓþ߱¸¼ÓÃܹ¦Ð§ÒÔ¶ÔÐéÄâ»úÄÚ´æÊý¾Ý¾ÙÐб£»£»£»£»£»¤¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬£¬Ð¾Æ¬ÖÆÔìÉÌAMDÕë¶ÔSEVÇå¾²ÈÆ¹ýÎó²î£¨×·×ÙΪCVE-2020-12967ºÍCVE-2021-26311£©Ðû²¼ÁËÏà¹Ø¹¥»÷Ö¸ÄÏ¡£¡£¡£¡£Õë¶ÔÕâÁ½¸öÎó²îµÄ¹¥»÷ºÍÏà¹ØÏ¸½Ú½«ÓÉÏà¹ØÑо¿Ð¡×éÔÚ½ñÄêµÄµÚ15½ìIEEE½ø¹¥ÊÖÒÕ×êÑлᣨWOOT'21£¬£¬£¬£¬£¬£¬2021Äê5ÔÂ27ÈÕ£©ÉϽÒÏþ¡£¡£¡£¡£
AMD SEV¿ÉÒÔ¸ôÀëÐéÄâ»úºÍÐéÄâ»úÖÎÀí³ÌÐò£¬£¬£¬£¬£¬£¬µ«×ÝȻʹÓÃÁËÊʵ±µÄ±£»£»£»£»£»¤»úÖÆ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒ²¿ÉÒÔʹÓÃÕâÁ½¸öÎó²îÕß½«í§Òâ´úÂë×¢Èëµ½ÐéÄâ»ú¡£¡£¡£¡£
AMD SEV/SEV-ESí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-12967£©
¸ÃÎó²îÊÇAMD SEV/SEV-ES¹¦Ð§ÖÐȱ·¦Ç¶Ì×Ò³±í±£»£»£»£»£»¤Ôì³ÉµÄ£¬£¬£¬£¬£¬£¬ÈôÊǹ¥»÷ÕßÓµÓÐÆÆËðЧÀÍÆ÷ÖÎÀí³ÌÐòµÄȨÏÞ£¬£¬£¬£¬£¬£¬Ôò¿ÉÄܵ¼ÖÂGuest VMÖеÄí§Òâ´úÂëÖ´ÐС£¡£¡£¡£
AMD SEV/SEV-ESí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-26311£©
¸ÃÎó²î±£´æÓÚAMD SEV/SEV-ES¹¦Ð§ÖС£¡£¡£¡£Æ¾Ö¤¸ÃÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚ֤ʵ»úÖÆÎ´¼ì²âµ½µÄGuestµØµã¿Õ¼äÖÐÖØÐÂÅÅÁÐÄڴ棬£¬£¬£¬£¬£¬ÈôÊǹ¥»÷ÕßÓµÓÐÆÆËðЧÀÍÆ÷ÖÎÀí³ÌÐòµÄȨÏÞ£¬£¬£¬£¬£¬£¬Ôò¿ÉÒÔʹÓôËÎó²îÖÆÊµÏÖGuest VMÖеÄí§Òâ´úÂëÖ´ÐС£¡£¡£¡£
Ó°Ïì¹æÄ£
¸ÃÎó²îÓ°ÏìËùÓÐAMD EPYC´¦Öóͷ£Æ÷£¨µÚÒ»/µÚ¶þ/µÚÈý´úAMD EPYC?´¦Öóͷ£Æ÷ºÍAMD EPYC?ǶÈëʽ´¦Öóͷ£Æ÷£©
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚAMDÒÑͨ¹ýSEV-SNP¹¦Ð§ÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬£¬£¬µ«¸Ã¹¦Ð§½öÔÚµÚÈý´úAMD EPYC?ÖÐÖ§³Ö£¬£¬£¬£¬£¬£¬½¨ÒéµÚÈý´úAMD EPYC?Óû§¾¡¿ìÓ¦ÓÃSEV-SNP¹¦Ð§¡£¡£¡£¡£
Ïà¹ØÁ´½Ó£º
https://developer.amd.com/sev/
0x03 ²Î¿¼Á´½Ó
https://developer.amd.com/sev/
https://uzl-its.github.io/undeserved-trust/
https://securityaffairs.co/wordpress/117981/security/amd-sev-attacks.html?
https://www.ieee-security.org/TC/SP2021/SPW2021/WOOT21/
0x04 ʱ¼äÏß
2021-05-16 Îó²îÅû¶
2021-05-17 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/