AMD SEV°²È«Èƹý·ì϶£¨CVE-2021-26311£©
°ä²¼¹¦·ò 2021-05-170x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-26311 | ʱ ¼ä | 2021-05-17 |
Àà ÐÍ | ´úÂëÖ´ÐÐ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | Ó°ÏìÁìÓò | ||
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà |
0x01 ·ì϶ÏêÇé

SEV£¨Secure Encrypted Virtualization£©ÊÇAMDÌá³öµÄ°²È«¼ÓÃÜÐé¹¹»¯¼¼Êõ£¬£¬£¬£¬£¬£¬£¬£¬ËüʹÖ÷ÄÚ´æ½ÚÔìÓþ߱¸¼ÓÃÜÖ°ÄÜÒÔ¶ÔÐé¹¹»úÄÚ´æÊý¾Ý½øÐб£»£»£»£»£»¤¡£¡£¡£¡£¡£¡£¡£¡£
½üÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Ð¾Æ¬Ôì×÷ÉÌAMDÕë¶ÔSEV°²È«Èƹý·ì϶£¨×·×ÙΪCVE-2020-12967ºÍCVE-2021-26311£©°ä²¼ÁËÓйع¥»÷Ö¸ÄÏ¡£¡£¡£¡£¡£¡£¡£¡£Õë¶ÔÕâÁ½¸ö·ì϶µÄ¹¥»÷ºÍÓйØÏ¸½Ú½«ÓÉÓйØ×êÑÐÓ××éÔÚ½ñÄêµÄµÚ15½ìIEEE½ø¹¥¼¼Êõ×êÑлᣨWOOT'21£¬£¬£¬£¬£¬£¬£¬£¬2021Äê5ÔÂ27ÈÕ£©Éϰ䷢¡£¡£¡£¡£¡£¡£¡£¡£
AMD SEVÄܹ»¸ôÀëÐé¹¹»úºÍÐé¹¹»úÖÎÀí·¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬µ«¼´±ãʹÓÃÁËÊʵ±µÄ±£»£»£»£»£»¤»úÔ죬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒ²Äܹ»ÀûÓÃÕâÁ½¸ö·ì϶Õß½«ËÁÒâ´úÂë×¢Èëµ½Ðé¹¹»ú¡£¡£¡£¡£¡£¡£¡£¡£
AMD SEV/SEV-ESËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-12967£©
¸Ã·ì϶ÊÇAMD SEV/SEV-ESÖ°ÄÜÖв»×ãǶÌ×Ò³±í±£»£»£»£»£»¤Ôì³ÉµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÈôÊǹ¥»÷ÕßÕ¼ÓзÛËé·þÎñÆ÷ÖÎÀí·¨Ê½µÄȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÄܵ¼ÖÂGuest VMÖеÄËÁÒâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£
AMD SEV/SEV-ESËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-26311£©
¸Ã·ì϶´æÔÚÓÚAMD SEV/SEV-ESÖ°ÄÜÖС£¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý¸Ã°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»ÔÚÖ¤Ã÷»úÔìδ¼ì²âµ½µÄGuestµØÖ·¿Õ¼äÖгÁзÖÁÐÄڴ棬£¬£¬£¬£¬£¬£¬£¬ÈôÊǹ¥»÷ÕßÕ¼ÓзÛËé·þÎñÆ÷ÖÎÀí·¨Ê½µÄȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬ÔòÄܹ»ÀûÓô˷ì϶ÔìʵÏÖGuest VMÖеÄËÁÒâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£
Ó°ÏìÁìÓò
¸Ã·ì϶ӰÏìËùÓÐAMD EPYC´¦ÖÃÆ÷£¨µÚÒ»/µÚ¶þ/µÚÈý´úAMD EPYC?´¦ÖÃÆ÷ºÍAMD EPYC?ǶÈëʽ´¦ÖÃÆ÷£©
0x02 ´ëÖý¨Òé
ĿǰAMDÒÑͨ¹ýSEV-SNPÖ°Äܽ¨¸´ÁË´Ë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬µ«¸ÃÖ°ÄܽöÔÚµÚÈý´úAMD EPYC?ÖÐÖ§³Ö£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéµÚÈý´úAMD EPYC?Óû§¾¡¿ìÀûÓÃSEV-SNPÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£
ÓйØÁ´½Ó£º
https://developer.amd.com/sev/
0x03 ²Î¿¼Á´½Ó
https://developer.amd.com/sev/
https://uzl-its.github.io/undeserved-trust/
https://securityaffairs.co/wordpress/117981/security/amd-sev-attacks.html?
https://www.ieee-security.org/TC/SP2021/SPW2021/WOOT21/
0x04 ¹¦·òÏß
2021-05-16 ·ì϶Åû¶
2021-05-17 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ