·þÎñÆ÷¡¢´æ´¢¡¢ÍøÂç²úÆ·¹ºÖÃÈÈÏߣº400-860-6708 ERP¡¢¹ÜÀíÈí¼þ¹ºÖÃÈÈÏߣº400-018-7700ÔÆ·þÎñ²úÆ·ÏúÊÛÈÈÏߣº400-607-6657
Çå¾²Ô¤¾¯-Linux Grub2 BootHoleÎó²î
Ô¤¾¯±àºÅ£ºINSPUR-SA-202008-001
³õʼÐû²¼Ê±¼ä£º2020-08-12 16:49:57
¸üÐÂÐû²¼Ê±¼ä£º2020-09-01 08:28:46
Îó²î¸ÅÊö£º

Çå¾²Ñо¿¹«Ë¾ EclypsiumÆعâÁËLinux Grub2Ö¸µ¼¼ÓÔسÌÐòÖÐÒ»¸öÃûΪ¡°BootHole¡±£¨CVE-2020-10713£©µÄÎó²î¡£´ËÎó²îÔÊÐí¹¥»÷ÕßЮÖÆÖ¸µ¼Àú³Ì²¢ÔÚϵͳÆô¶¯Ê±´úÖ´ÐжñÒâ´úÂ룬×ÝȻʹÓÃUEFI Secure BootµÄϵͳҲ¿ÉÒÔʹÓôËÎó²îÈƹý¡£
Grub2 boot loaderͨ¹ýgrub.cfgÎļþÉèÖ㬸ÃÎļþÖаüÀ¨¶à¸ötokens×Ö·û´®¡£ÔÚ³õʼָµ¼¼ÓÔسÌÐò£¨³ÆΪshim£©¼ÓÔØÖ®ºó£¬×îÏȼÓÔØÏ¢ÕùÎögrub.cfgÉèÖÃÎļþ¡£ÔÚÆÊÎö½×¶Î£¬ÉèÖÃÎļþµÄÄÚÈݱ»¸´ÖƵ½ÄÚ´æµÄÄÚ²¿»º³åÇøÖд洢¡£µ±tokens³¤¶È´óÓÚÄÚ²¿»º³åÇø¾Þϸʱ»áµ¼Ö»º³åÇøÒç³öÎÊÌâ¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂ룬½øÒ»²½Ð®ÖÆÅÌËã»úµÄÖ¸µ¼Àú³Ì²¢ÈƹýSecure Boot±£»¤¡£

ÒÑÍê³ÉÐÞ¸´µÄ²úÆ·°æ±¾£º
²úÆ·Ãû³Æ ÊÜÓ°Ïì²úÆ·°æ±¾ ÐÞ¸´²¹¶¡°ü/Éý¼¶°ü°æ±¾
¡¡¡¡AS13000 AS13000 > 3.5.0.1  grub2-2.02-0.65-AS13000-update.tar.gz
ICS ICS<=5.8.1  V5.8.1°æ±¾Í¨¹ý²¹¶¡¾ÙÐÐÐÞ¸´£¬²¹¶¡°üÃû³Æ£º
IncloudSphere-V5R08B017-b1-M001.hotfix.zip
IncloudSphere-V5R08B017-b1-S001.hotfix.zip£»
СÓÚV5.8.1°æ±¾²úÆ·£¬ÐèÒªÏÈÉý¼¶µ½v5.8.1°æ±¾£¬ÔÙͨ¹ý²¹¶¡¾ÙÐÐÐÞ¸´¡£
ICOS ICOS>=5.2,ICOS<=5.8 ICOS-CVE-2020-10713.rar
ISIB ISIB-V2.1.1-20200605_1610-CN֮ǰµÄ°æ±¾ ISIB-v2.1.1-sp1-x86_64-20200831.rpm
ISPIM 1. ISPIM-V2.1.1-20200827_2041_CN֮ǰµÄ°æ±¾
2. ISPIM-V2.1.1-20200827_2112_EN֮ǰµÄ°æ±¾
1. ISPIM-V2.1.1-20200827_2041_CN
2. ISPIM-V2.1.1-20200827_2112_EN
3. ²¹¶¡°ü£ºispimV2.1.1-sp1-x86_64-20200831.rpm

Ó°ÏìЧ¹û£º

¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂ룬½øÒ»²½Ð®ÖÆÅÌËã»úµÄÖ¸µ¼Àú³Ì²¢ÈƹýSecure Boot±£»¤, ¿ØÖÆÊÜÓ°ÏìµÄ×°±¸¡£

Îó²îµÃ·Ö£º
CVE V3.1 Vector(Base) Base Score V3.1 Vector(Temporal Score) Temporal Score
CVE-2020-10713 AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H 8.2 E:U/RL:O/RC:C 7.1

ÊÖÒÕϸ½Ú£º

Îó²îÔµ¹ÊÔ­ÓÉ£ºGRUB2 ÔÚ´¦Öóͷ£Æä×ÔÉíµÄÉèÖÃÎļþ grub.cfg ʱ±£´æ»º³åÇøÒç³öÎó²î¡£¹¥»÷Õßͨ¹ý½¨ÉèÌØÖÆµÄ grub.cfg Îļþ£¬ÔÚÏÂÒ»´ÎÖØÆôºó¹¥»÷Õß¿ÉÒÔ²»ÊÜÏÞÖƵĿØÖÆÊÜÓ°ÏìµÄ×°±¸¡£
ʹÓÃÌõ¼þ£ºÔ¶³Ìroot»á¼û£¬¿ÉÐÞ¸Ägrub.cfgÎļþ¡£

°æ±¾»ñÈ¡Á´½Ó£º

AS13000Óû§Ö±½ÓÁªÏµ¿Í»§·þÎñÖ°Ô±»ò·¢ËÍÓʼþÖÁsun.meng@inspur.com£¬»ñÈ¡²¹¶¡£¬ÒÔ¼°Ïà¹ØµÄÊÖÒÕЭÖú¡£
ICOS¡¢ICSÓû§Ö±½ÓÁªÏµÖ§³ÖÖ°Ô±»ñÈ¡²¹¶¡ÒÔ¼°Ïà¹ØµÄÊÖÒÕЭÖú¡£
ISPIM:ÏÂÔØ
ISIB:ÏÂÔØ

¹æ±Ü²½·¥£º

ÔÝÎÞÕë¶Ô´ËÎó²îµÄ»º½â²½·¥

Îó²îȪԴ£º

Çå¾²Ñо¿¹«Ë¾ EclypsiumÅû¶

¸üмͼ£º

20200812-V1.0-Initial Release
20200831-V1.1-Update ÔöÌíÊÜÓ°Ïì²úÆ·Çåµ¥
20200901-V1.2-Update ÔöÌíÊÜÓ°Ïì²úÆ·Çåµ¥

FAQs£º

ÎÞ

K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾Çå¾²Ó¦¼±ÏìÓ¦¶ÔÍâ·þÎñ£º

K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾Ò»Ö±Ö÷Õž¡È«Á¦°ü¹Ü²úÆ·Óû§µÄ×îÖÕÀûÒ棬×ñÕÕÈÏÕæÈεÄÇå¾²ÊÂÎñÅû¶ԭÔò£¬²¢Í¨¹ý²úÆ·Çå¾²ÎÊÌâ´¦Öóͷ£»úÖÆ´¦Öóͷ£²úÆ·Çå¾²ÎÊÌâ¡£
·´ÏìK8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾Ïà¹ØµÄ²úÆ·Çå¾²ÎÊÌâ,Çë·´ÏìÖÁK8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾PSIRTÓÊÏäsec@inspur.com£¬ÏêÇé²Î¿¼£º/lcjtww/2312126/2432763/index.html

¹ØÓÚK8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾

ÐÂÎÅÓëÔ˶¯

ÔõÑù¹ºÖÃ

̽Ë÷K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾

ͨÓ÷þÎñÆ÷ ´æ´¢ È˹¤ÖÇÄÜ °®¶¼»áÍø K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾ÔÆ K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾ÔÆERP

Ö§³ÖÓë·þÎñ

¿ìËÙÁ´½Ó

ºÏ×÷»ï°éÉú̬ µç×ӲɹºÆ½Ì¨ ͶÐÐÏîÄ¿ Ͷ×ÊÕß¹Øϵ Æ·µÂ×ñ´Ó

ÔÚÉ罻ýÌåÉϹØ×¢ÎÒÃÇ

k8¡¤¿­·¢(Öйú)ÌìÉúÓ®¼Ò¡¤Ò»´¥¼´·¢

?1996 - 2020 INSPUR Co., Ltd. ³ICP±¸05019369ºÅ

³¹«Íø°²±¸ 37010202001184ºÅ

K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾

²¦´ò×Éѯµç»°

  • ·þÎñÆ÷¡¢´æ´¢¡¢ÍøÂç²úÆ·¹ºÖÃÈÈÏߣº

    400-860-6708

  • ERP¡¢¹ÜÀíÈí¼þ¹ºÖÃÈÈÏߣº

    400-018-7700

  • ÔÆ·þÎñ²úÆ·ÏúÊÛÈÈÏߣº

    400-607-6657

  • K8¿­·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾ÍøÂçÊÛºóÈÈÏߣº

    400-691-1766

ºô½ÐÔÚÏß¿Í·þ

  • ·þÎñÆ÷´æ´¢ÍøÂç²úÆ·ÏúÊÛ ·þÎñÆ÷´æ´¢ÊÛºó ERPÊÛÇ°ÊÛºó ÔÆ·þÎñ²úÆ·ÏúÊÛ
ÍøÕ¾µØͼ