{"id":39773,"date":"2018-08-15T15:58:10","date_gmt":"2018-08-15T13:58:10","guid":{"rendered":"https:\/\/www.planet3dnow.de\/cms\/?p=39773"},"modified":"2018-08-15T22:53:00","modified_gmt":"2018-08-15T20:53:00","slug":"l1-terminal-fault-luecken-in-intel-cpu-erfordern-weitere-patches","status":"publish","type":"post","link":"https:\/\/www.planet3dnow.de\/cms\/39773-l1-terminal-fault-luecken-in-intel-cpu-erfordern-weitere-patches\/","title":{"rendered":"<span class=\"dquo\">\u201c<\/span><span class=\"caps\">L1<\/span> Terminal Fault\u201d-L\u00fccken in Intel-CPU erfordern weitere Patches"},"content":{"rendered":"<p>Die Nega\u00adtiv\u00adschla\u00adgen\u00adzei\u00adlen (aus tech\u00adni\u00adscher Sicht; wirt\u00adschaft\u00adlich hat Intel ja gera\u00adde erst ein Rekord\u00adquar\u00adtal hin\u00adge\u00adlegt) rei\u00ad\u00dfen nicht ab. Gestern Abend haben Sicher\u00adheits\u00adfor\u00adscher von Uni\u00adver\u00adsi\u00adt\u00e4\u00adten in Bel\u00adgi\u00aden, Isra\u00adel, Aus\u00adtra\u00adli\u00aden und den <span class=\"caps\">USA<\/span> <a href=\"https:\/\/foreshadowattack.eu\/\" rel=\"noopener\" target=\"_blank\">drei neue Sicher\u00adheits\u00adl\u00fc\u00adcken ver\u00ad\u00f6f\u00adfent\u00adlicht<\/a>, die \u00c4hn\u00adlich\u00adkei\u00adten zu den bereits im Janu\u00adar ver\u00ad\u00f6f\u00adfent\u00adli\u00adchen Spect\u00adre-L\u00fccken auf\u00adwei\u00adsen und ins\u00adbe\u00adson\u00adde\u00adre auf Cloud\u00adser\u00advern aus\u00adge\u00adnutzt wer\u00adden k\u00f6n\u00adnen. Betrof\u00adfen sind davon nach aktu\u00adel\u00adlem Kennt\u00adnis\u00adstand nur Pro\u00adzes\u00adso\u00adren des Her\u00adstel\u00adlers Intel, min\u00addes\u00adtens seit der ers\u00adten Core-i-Gene\u00adra\u00adti\u00adon. Aus\u00adge\u00adnom\u00admen sind jene Atom-Pro\u00adzes\u00adso\u00adren (z.B. Clover\u00adview), die auf In-Order-Exe\u00adcu\u00adti\u00adon setzten.<\/p>\n<p>Die drei neu\u00aden L\u00fccken h\u00f6ren auf die&nbsp;Namen:<\/p>\n<ul>\n<li>Fores\u00adha\u00addow (<span class=\"caps\">L1<\/span> Ter\u00admi\u00adnal Fault \u2014 <span class=\"caps\">SGX<\/span>) \/ <span class=\"caps\">CVE-2018<\/span>\u20133615<\/li>\n<li><span class=\"caps\">L1<\/span> Ter\u00admi\u00adnal Fault \u2014 <span class=\"caps\">OS<\/span> Ker\u00adnel, <span class=\"caps\">SMM<\/span> \/ <span class=\"caps\">CVE-2018<\/span>\u20133620<\/li>\n<li><span class=\"caps\">L1<\/span> Ter\u00admi\u00adnal Fault \u2014 Vir\u00adtu\u00adal Machi\u00adnes \/ <span class=\"caps\">CVE-2018<\/span>\u20133646<\/li>\n<\/ul>\n<p>Gemein ist allen Drei\u00aden, dass Angrei\u00adfer aus ihren zuge\u00adwie\u00adse\u00adnen Berei\u00adchen aus\u00adbre\u00adchen und Daten bzw. Spei\u00adcher\u00adbe\u00adrei\u00adche ande\u00adrer Pro\u00adzes\u00adse aus\u00adle\u00adsen k\u00f6n\u00adnen, auf die sie eigent\u00adlich kei\u00adnen Zugriff haben soll\u00adten. Das ist ins\u00adbe\u00adson\u00adde\u00adre f\u00fcr Betrei\u00adber von Cloud\u00adser\u00advern kri\u00adtisch, da hier meh\u00adre\u00adre VMs und Kun\u00adden auf einer phy\u00adsi\u00adschen Maschi\u00adne lau\u00adfen. Daher wird zun\u00e4chst ein\u00admal emp\u00adfoh\u00adlen, VMs kei\u00adne gemein\u00adsa\u00admen CPU-Ker\u00adne zuzu\u00adwei\u00adsen. Zudem haben BSD-Ent\u00adwick\u00adler bereits vor gerau\u00admer Zeit emp\u00adfoh\u00adlen, <a href=\"https:\/\/www.planet3dnow.de\/cms\/38685-weitere-sicherheitsluecke-in-intel-cpus-tlbleed-trickst-hyperthreading-aus\/\"><span class=\"caps\">SMT<\/span> ali\u00adas Hyper\u00adTh\u00adre\u00ada\u00adding zu deak\u00adti\u00advie\u00adren<\/a>, da sich durch die gemein\u00adsa\u00adme Res\u00adsour\u00adcen\u00adnut\u00adzung eines Kerns wei\u00adte\u00adre Schwach\u00adstel\u00adlen erge\u00adben. Zusam\u00admen mit den wei\u00adte\u00adren Betriebs\u00adsys\u00adtem-Patches und Micro\u00adcode-Updates bef\u00fcrch\u00adten Ser\u00adver\u00adbe\u00adtrei\u00adber nach den Lin\u00adde\u00adrun\u00adgen Per\u00adfor\u00admance-Ein\u00adbu\u00ad\u00dfen von 15 bis 50 % je nach Szenario.<\/p>\n<p><iframe loading=\"lazy\" width=\"560\" height=\"315\" src=\"https:\/\/www.youtube.com\/embed\/ynB1inl4G3c\" frameborder=\"0\" allow=\"autoplay; encrypted-media\" allowfullscreen><\/iframe> <iframe loading=\"lazy\" width=\"560\" height=\"315\" src=\"https:\/\/www.youtube.com\/embed\/8ZF6kX6z7pM\" frameborder=\"0\" allow=\"autoplay; encrypted-media\" allowfullscreen><\/iframe><\/p>\n<p>Lin\u00addern\u00adde Patches sind gestern Abend in den Linux-Ker\u00adnel 4.19 ein\u00adge\u00adflos\u00adsen, der im Okto\u00adber zur Ver\u00ad\u00f6f\u00adfent\u00adli\u00adchung ansteht. Aber wie \u00fcblich bei kri\u00adti\u00adschen Updates wur\u00adden die Patches auch r\u00fcck\u00adpor\u00adtiert, sodass sie in den n\u00e4chs\u00adten Tagen zur Ver\u00adf\u00fc\u00adgung ste\u00adhen soll\u00adten. Auch mit dem gest\u00adri\u00adgen Micro\u00adsoft-Patch\u00adday sind <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4343900\/windows-7-update-kb4343900\" rel=\"noopener\" target=\"_blank\">eini\u00adge Updates ver\u00ad\u00f6f\u00adfent\u00adlicht<\/a> wor\u00adden, wel\u00adche die neu \u00f6ffent\u00adlich gewor\u00adde\u00adnen Spect\u00adre-NG-L\u00fccken lin\u00addern sol\u00adlen. Im Gegen\u00adsatz zu Cloud\u00addiens\u00adten ist am Desk\u00adtop eher nicht mit gro\u00ad\u00dfen Per\u00adfor\u00admance-Ein\u00adbu\u00ad\u00dfen zu rechnen.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Die Nega\u00adtiv\u00adschla\u00adgen\u00adzei\u00adlen (aus tech\u00adni\u00adscher Sicht; wirt\u00adschaft\u00adlich hat Intel ja gera\u00adde erst ein Rekord\u00adquar\u00adtal hin\u00adge\u00adlegt) rei\u00ad\u00dfen nicht ab. Gestern Abend haben Sicher\u00adheits\u00adfor\u00adscher von Uni\u00adver\u00adsi\u00adt\u00e4\u00adten in Bel\u00adgi\u00aden, Isra\u00adel, Aus\u00adtra\u00adli\u00aden und den <span class=\"caps\">USA<\/span> drei neue Sicher\u00adheits\u00adl\u00fc\u00adcken ver\u00ad\u00f6f\u00adfent\u00adlicht, die \u00c4hn\u00adlich\u00adkei\u00adten zu den bereits im Janu\u00adar ver\u00ad\u00f6f\u00adfent\u00adli\u00adchen Spect\u00adre-L\u00fccken haben und ins\u00adbe\u00adson\u00adde\u00adre auf Cloud\u00adser\u00advern aus\u00adge\u00adnutzt wer\u00adden k\u00f6n\u00adnen. (\u2026) <a class=\"moretag\" href=\"https:\/\/www.planet3dnow.de\/cms\/39773-l1-terminal-fault-luecken-in-intel-cpu-erfordern-weitere-patches\/\">Wei\u00adter\u00adle\u00adsen&nbsp;\u00bb<\/a><\/p>\n","protected":false},"author":2,"featured_media":6269,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"wp_typography_post_enhancements_disabled":false,"ngg_post_thumbnail":0,"footnotes":""},"categories":[12],"tags":[1533,1534,1419,1420],"class_list":["post-39773","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aktuelles","tag-foreshadow","tag-l1tf","tag-meltdown","tag-spectre","entry"],"share_on_mastodon":{"url":"","error":""},"_links":{"self":[{"href":"https:\/\/www.planet3dnow.de\/cms\/wp-json\/wp\/v2\/posts\/39773","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.planet3dnow.de\/cms\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.planet3dnow.de\/cms\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.planet3dnow.de\/cms\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.planet3dnow.de\/cms\/wp-json\/wp\/v2\/comments?post=39773"}],"version-history":[{"count":10,"href":"https:\/\/www.planet3dnow.de\/cms\/wp-json\/wp\/v2\/posts\/39773\/revisions"}],"predecessor-version":[{"id":39826,"href":"https:\/\/www.planet3dnow.de\/cms\/wp-json\/wp\/v2\/posts\/39773\/revisions\/39826"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.planet3dnow.de\/cms\/wp-json\/wp\/v2\/media\/6269"}],"wp:attachment":[{"href":"https:\/\/www.planet3dnow.de\/cms\/wp-json\/wp\/v2\/media?parent=39773"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.planet3dnow.de\/cms\/wp-json\/wp\/v2\/categories?post=39773"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.planet3dnow.de\/cms\/wp-json\/wp\/v2\/tags?post=39773"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}