AMD SEVÇå¾²ÈÆ¹ýÎó²î£¨CVE-2021-26311£©

Ðû²¼Ê±¼ä 2021-05-17

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2021-26311

ʱ   ¼ä

2021-05-17

Àà   ÐÍ

´úÂëÖ´ÐÐ

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ


Ó°Ïì¹æÄ£


PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

 

SEV£¨Secure Encrypted Virtualization£©ÊÇAMDÌá³öµÄÇå¾²¼ÓÃÜÐéÄ⻯ÊÖÒÕ£¬£¬£¬£¬£¬ £¬ËüʹÖ÷ÄÚ´æ¿ØÖÆÓþ߱¸¼ÓÃܹ¦Ð§ÒÔ¶ÔÐéÄâ»úÄÚ´æÊý¾Ý¾ÙÐб£»£»£»£»£»¤¡£¡£¡£¡£

¿ËÈÕ£¬£¬£¬£¬£¬ £¬Ð¾Æ¬ÖÆÔìÉÌAMDÕë¶ÔSEVÇå¾²ÈÆ¹ýÎó²î£¨×·×ÙΪCVE-2020-12967ºÍCVE-2021-26311£©Ðû²¼ÁËÏà¹Ø¹¥»÷Ö¸ÄÏ¡£¡£¡£¡£Õë¶ÔÕâÁ½¸öÎó²îµÄ¹¥»÷ºÍÏà¹ØÏ¸½Ú½«ÓÉÏà¹ØÑо¿Ð¡×éÔÚ½ñÄêµÄµÚ15½ìIEEE½ø¹¥ÊÖÒÕ×êÑлᣨWOOT'21£¬£¬£¬£¬£¬ £¬2021Äê5ÔÂ27ÈÕ£©ÉϽÒÏþ¡£¡£¡£¡£

AMD SEV¿ÉÒÔ¸ôÀëÐéÄâ»úºÍÐéÄâ»úÖÎÀí³ÌÐò£¬£¬£¬£¬£¬ £¬µ«×ÝȻʹÓÃÁËÊʵ±µÄ±£»£»£»£»£»¤»úÖÆ£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÒ²¿ÉÒÔʹÓÃÕâÁ½¸öÎó²îÕß½«í§Òâ´úÂë×¢Èëµ½ÐéÄâ»ú¡£¡£¡£¡£

AMD SEV/SEV-ESí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-12967£©

¸ÃÎó²îÊÇAMD SEV/SEV-ES¹¦Ð§ÖÐȱ·¦Ç¶Ì×Ò³±í±£»£»£»£»£»¤Ôì³ÉµÄ£¬£¬£¬£¬£¬ £¬ÈôÊǹ¥»÷ÕßÓµÓÐÆÆËðЧÀÍÆ÷ÖÎÀí³ÌÐòµÄȨÏÞ£¬£¬£¬£¬£¬ £¬Ôò¿ÉÄܵ¼ÖÂGuest VMÖеÄí§Òâ´úÂëÖ´ÐС£¡£¡£¡£

 

AMD SEV/SEV-ESí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-26311£©

¸ÃÎó²î±£´æÓÚAMD SEV/SEV-ES¹¦Ð§ÖС£¡£¡£¡£Æ¾Ö¤¸ÃÇ徲ͨ¸æ£¬£¬£¬£¬£¬ £¬¿ÉÒÔÔÚ֤ʵ»úÖÆÎ´¼ì²âµ½µÄGuestµØµã¿Õ¼äÖÐÖØÐÂÅÅÁÐÄڴ棬£¬£¬£¬£¬ £¬ÈôÊǹ¥»÷ÕßÓµÓÐÆÆËðЧÀÍÆ÷ÖÎÀí³ÌÐòµÄȨÏÞ£¬£¬£¬£¬£¬ £¬Ôò¿ÉÒÔʹÓôËÎó²îÖÆÊµÏÖGuest VMÖеÄí§Òâ´úÂëÖ´ÐС£¡£¡£¡£

 

Ó°Ïì¹æÄ£

¸ÃÎó²îÓ°ÏìËùÓÐAMD EPYC´¦Öóͷ£Æ÷£¨µÚÒ»/µÚ¶þ/µÚÈý´úAMD EPYC?´¦Öóͷ£Æ÷ºÍAMD EPYC?ǶÈëʽ´¦Öóͷ£Æ÷£©

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚAMDÒÑͨ¹ýSEV-SNP¹¦Ð§ÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬£¬ £¬µ«¸Ã¹¦Ð§½öÔÚµÚÈý´úAMD EPYC?ÖÐÖ§³Ö£¬£¬£¬£¬£¬ £¬½¨ÒéµÚÈý´úAMD EPYC?Óû§¾¡¿ìÓ¦ÓÃSEV-SNP¹¦Ð§¡£¡£¡£¡£

Ïà¹ØÁ´½Ó£º

https://developer.amd.com/sev/

 

0x03 ²Î¿¼Á´½Ó

https://developer.amd.com/sev/

https://uzl-its.github.io/undeserved-trust/

https://securityaffairs.co/wordpress/117981/security/amd-sev-attacks.html?

https://www.ieee-security.org/TC/SP2021/SPW2021/WOOT21/

 

 

0x04 ʱ¼äÏß

2021-05-16  Îó²îÅû¶

2021-05-17  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png