K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾Ôƹٷ½É̳Ç
ÌìÔªÊý¾ÝÍø
ÔÆERP¹Ù·½É̳Ç
×÷ΪÖйú×î¾ßÓ°ÏìÁ¦µÄITÆ·ÅÆÖ®Ò»£¬K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾½èÅÌËãÖ®Á¦£¬´òÔ컥Áª»¥Í¨µÄÊý¾ÝÉú̬£¬ÒÔÊý¾ÝÖ®Ãû£¬¿ªÆôÈ«ÐÂÕ³̵ÄÌìÏÂÎÄÃ÷¡£
Éó²é¸ü¶àÊÓƵ >K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾ÃñÕþÔÆƽ̨ƾ֤ÌìÏÂÃñÕþϽµµÍìÏÈ¡¢Õþ¸®²¿·ÖÒ»Á÷µÄ±ê×¼ÍýÏëÉè¼Æ£¬Æ½Ì¨ÈÚºÏÃñÕþÓªÒµ¹ÜÀí¡¢¹«¹²·þÎñ¡¢´óÊý¾Ý×ÊÔ´·þÎñ¡£
ÏàʶÏêÇé >K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾Ôƹٷ½É̳Ç
ÌìÔªÊý¾ÝÍø
ÔÆERP¹Ù·½É̳Ç
QEMU USBÄ£ÄâÆ÷Öб£´æÒ»¸öÔ½½ç¶ÁдÎó²î£¨CVE-2020-14364£©£¬´ËÎó²îÓÉÓÚQEMU USBÄ£¿éÖеÄÊý×éÔ½½ç¶ÁдÔì³É£¬Îó²îλÓÚ¡°./hw/usb/core.c¡± ÖС£¹¥»÷ÕßÔÚÓµÓÐÔÆÇéÐÎÐéÄâ»ú²Ù×÷ϵͳȨÏÞµÄÇéÐÎÏ£¬¿ÉÒÔʹÓøÃÎó²î»ñÈ¡ËÞÖ÷»úȨÏÞ£¬½ø¶ø¹¥»÷ÐéÄâ»úËùÔÚ×ÊÔ´³ØËùÓÐ×⻧Ö÷»ú¡£
2020.06.10£¬Ó¢ÌضûÐû²¼ÁËijЩ´¦Öóͷ£Æ÷ÖÐDZÔÚµÄÇå¾²Îó²î£¬¸ÃÎó²î¿ÉÄܵ¼ÖÂÐÅϢй¶¡£
intel-sa-00320£ºCVE-2020-0543
Ò»ÖÖ³ÆΪÌØÊâ¼Ä´æÆ÷»º³åÇøÊý¾Ý²ÉÑù£¨SRBDS£©µÄÐÂÓòÈƹý˲ִ̬Ðй¥»÷¿ÉÄÜÔÊÐíͨ¹ýÔÚCPUµÄÈκν¹µãÉÏÖ´ÐжñÒâ´úÂëÍƶÏÀ´×ÔÌØÊâ¼Ä´æÆ÷µÄÊý¾ÝÖµ¡£
Intel CSME¡¢TXEºÍSPSÖеÄ×Óϵͳ±£´æÕûÊýÒç³öÎó²îCVE-2020-0545¡£ÍâµØÌØȨÓû§¿ÉʹÓøÃÎó²îÔì³É¾Ü¾ø·þÎñ¡£
Çå¾²Ñо¿¹«Ë¾ EclypsiumÆعâÁËLinux Grub2Ö¸µ¼¼ÓÔسÌÐòÖÐÒ»¸öÃûΪ¡°BootHole¡±£¨CVE-2020-10713£©µÄÎó²î¡£´ËÎó²îÔÊÐí¹¥»÷ÕßЮÖÆÖ¸µ¼Àú³Ì²¢ÔÚϵͳÆô¶¯Ê±´úÖ´ÐжñÒâ´úÂ룬×ÝȻʹÓÃUEFI Secure BootµÄϵͳҲ¿ÉÒÔʹÓôËÎó²îÈƹý¡£
Grub2 boot loaderͨ¹ýgrub.cfgÎļþÉèÖ㬸ÃÎļþÖаüÀ¨¶à¸ötokens×Ö·û´®¡£ÔÚ³õʼָµ¼¼ÓÔسÌÐò£¨³ÆΪshim£©¼ÓÔØÖ®ºó£¬×îÏȼÓÔØÏ¢ÕùÎögrub.cfgÉèÖÃÎļþ¡£ÔÚÆÊÎö½×¶Î£¬ÉèÖÃÎļþµÄÄÚÈݱ»¸´ÖƵ½ÄÚ´æµÄÄÚ²¿»º³åÇøÖд洢¡£µ±tokens³¤¶È´óÓÚÄÚ²¿»º³åÇø¾Þϸʱ»áµ¼Ö»º³åÇøÒç³öÎÊÌâ¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂ룬½øÒ»²½Ð®ÖÆÅÌËã»úµÄÖ¸µ¼Àú³Ì²¢ÈƹýSecure Boot±£»¤¡£
CVE-2020-11651£ºSaltStackÈÏÖ¤ÈƹýÎó²î,¹¥»÷Õßͨ¹ý½á¹¹¶ñÒâÇëÇ󣬿ÉÒÔÈƹýSalt MasterµÄÑéÖ¤Âß¼£¬Å²ÓÃÏà¹ØδÊÚȨº¯Êý¹¦Ð§£¬´Ó¶ø¿ÉÒÔÔì³ÉÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£
CVE-2020-11652£ºSalt MasterĿ¼±éÀúÎó²î£¬¹¥»÷Õßͨ¹ý½á¹¹¶ñÒâÇëÇ󣬶ÁÈ¡·þÎñÆ÷ÉÏí§ÒâÎļþ¡£
ÆäËûµÚÈý·½×é¼þÎó²î£º
CVE-2015-5589£ºPHPÔ¶³Ì¾Ü¾ø·þÎñÎó²î
CVE-2016-2554£ºPHP»ùÓÚÕ»µÄ»º³åÇøÒç³öÎó²î
CVE-2018-7584£ºPHPÕ»»º³åÇøÒç³öÎó²î
CVE-2016-7568£ºPHPÕûÊýÒç³öÎó²î
CVE-2019-9023£ºPHP»º³åÇø¹ýʧÎó²î
CVE-2017-12933£ºPHP¶Ñ»º³åÇøÒç³öÎó²î
2020Äê01ÔÂ27ÈÕ£¬Ó¢ÌضûÐû²¼Çå¾²¸üУ¬Åû¶2¸öintel´¦Öóͷ£Æ÷Çå¾²Îó²î£¬CVE±àºÅΪCVE-2020-0548ºÍCVE-2020-0549£¬¿Éµ¼ÖÂÐÅϢй¶µÈ¡£Îó²îÏêϸÐÅÏ¢ÈçÏ£º
CVE-2020-0549£ºL1D Eviction Sampling
ÔÚijЩ΢ϵͳ½á¹¹Ìõ¼þϵÄijЩ´¦Öóͷ£Æ÷ÉÏ£¬À´×Ô×î½ü³·»ØµÄÐ޸ĵÄL1Êý¾Ý¸ßËÙ»º´æ£¨L1D£©ÐеÄÊý¾Ý¿ÉÄܻᴫË͵½Î´Ê¹ÓõÄÎÞЧµÄL1DÌî³ä»º³åÇøÖС£ ÔÚÊÜ΢ϵͳ½á¹¹Êý¾Ý²ÉÑù£¨MDS£©»òÊÂÎñÐÔÒì²½ÖÐÖ¹£¨TAA£©Ó°ÏìµÄ´¦Öóͷ£Æ÷ÉÏ£¬¿ÉÒÔʹÓÃÕâÁ½ÖÖÊý¾Ý²ÉÑù±ßÐŵÀÒªÁìÖ®Ò»À´ÍƶÏÀ´×ÔL1DÌî³ä»º³åÇøµÄÊý¾Ý¡£ ͨ¹ý½«ÕâÁ½ÖÖÐÐΪ×éºÏÔÚÒ»Æ𣬹¥»÷Õß¾ÍÓпÉÄÜ´ÓÏÈÇ°´ÓL1Êý¾Ý¸ßËÙ»º´æÖÐÖð³öµÄÐ޸ĺóµÄ¸ßËÙ»º´æÐÐÖÐÍƶϳöÊý¾ÝÖµ¡£
CVE-2020-0548£º
ijЩӢÌضû´¦Öóͷ£Æ÷ÖеÄɨ³ý¹ýʧ£¬¿ÉÄܵ¼Ö¾ÓÉÉí·ÝÑéÖ¤µÄÓû§Í¨¹ýÍâµØ»á¼û»ñÊØÐÅÏ¢¡£¸ÃÎó²îintel¸ø³öµÄCVSSÆÀ·ÖΪ2.8£¬µÍΣÎó²î¡£
2019Äê12ÔÂ10ÈÕ£¬Ó¢ÌضûÐû²¼Çå¾²¸üУ¬Åû¶¶à¸öÇå¾²Îó²î£¬ÆäÖÐintel ProcessorsÎó²îCVE-2019-11157ºÍCVE-2019-14607¿Éµ¼ÖÂȨÏÞÌáÉý»òÐÅϢй¶µÈ¡£Îó²îÏêϸÐÅÏ¢ÈçÏ£º
INTEL-SA-00289£ºCVE-2019-11157
ijЩIntel£¨R£©´¦Öóͷ£Æ÷µÄµçѹÉèÖÃÄ£¿é£¨voltage settings£©Òò¼ì²éÌõ¼þ²»µ±¿ÉÄÜ»áʹ¾ÓÉÉí·ÝÑéÖ¤µÄÓû§Í¨¹ýͨ¹ýÍâµØ»á¼ûÌáÉýȨÏÞºÍ/»ò»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
INTEL-SA-00317£ºCVE-2019-14607
¶à¸öintel´¦Öóͷ£Æ÷Òò²»×¼È·µÄÌõ¼þ¼ì²â¿ÉÄÜ»áÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄÓû§Í¨¹ýͨ¹ýÍâµØ»á¼ûÌáÉýȨÏÞºÍ/»ò»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾ÊÜÓ°Ïì²úÆ·¼°¶ÔÓ¦ÐÞ¸´°æ±¾¼ûÏÂ±í¡£Ëæ×ÅÏà¹ØÊÂÇéµÄÒ»Á¬¾ÙÐУ¬K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾PSIRT»áËæʱ¸üиÃÇå¾²Ô¤¾¯£¬ÇëÒ»Á¬¹Ø×¢¡£
2019Äê11ÔÂ12ºÅ£¬Intel¹ûÕæÁ˶à¸öÇå¾²Îó²î£¬¿ÉÄܵ¼ÖÂÌØȨÌáÉý£¬·þÎñ¾Ü¾ø»òÐÅϢй¶¡£Ó¢ÌضûÒÑÐû²¼¹Ì¼þºÍÈí¼þ¸üУ¬ÒÔ»º½âÕâЩDZÔÚÎó²î¡£Îó²îÏêϸÐÅÏ¢ÈçÏ£º
Intel-SA-00240: CVE-2019-0151
Intel(R) Core Processors ºÍ Intel(R) Xeon(R) ProcessorsÓÉÓÚIntel(R) TXT¶ÔÄÚ´æ±£»¤È±·¦£¬¿ÉÄÜ»áʹÒÑÊÚȨÓû§Í¨¹ýÍâµØ»á¼ûÌáÉýȨÏÞ¡£
Intel-SA-00241: CVE-2019-11090£¨fTPMÎó²î£©, CVE-2019-11109
Intel£¨R£©SPS×ÓϵͳÇå¾²ÎÊÌ⣨Improper directory permissions¡¢Cryptographic timing conditions£©
Intel-SA-00270: CVE-2019-11135
ʹÓÃÍƲâÖ´ÐеÄijЩCPUÉϵÄTSXÒì²½ÖÐÖ¹Ìõ¼þ£¨TAA£©¿ÉÄÜÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄÓû§Í¨¹ý±ßÐŵÀ¹¥»÷»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
Intel-SA-00271: CVE-2019-11139
ijЩIntel(R) Xeon(R) ¿ÉÀ©Õ¹´¦Öóͷ£Æ÷ÔÚVoltage Setting Modulation£¨µçѹÉèÖõ÷ÖÆ£©Öв»µ±µÄÌõ¼þ¼ì²â£¬¿ÉÄÜ»áʹÒÑÊÚȨÓû§Í¨¹ýÍâµØ»á¼ûÔì³É¾Ü¾ø·þÎñ¡£
Intel-SA-00280: CVE-2019-11136, CVE-2019-11137
ijЩIntel(R) Xeon(R) ¿ÉÀ©Õ¹´¦Öóͷ£Æ÷ÓÉÓÚÊäÈëÑé֤ȱ·¦/»á¼û¿ØÖÆȱ·¦£¬¿ÉÄÜ»áʹÒÑÊÚȨÓû§Í¨¹ýÍâµØ»á¼ûÔì³ÉÌØȨÉý¼¶£¬¾Ü¾ø·þÎñºÍ/»òÐÅϢй¶¡£
ÓÉÓÚÔÚReids 4.x¼°ÒÔÉÏ°æ±¾ÖÐÐÂÔöÁËÄ£¿é¹¦Ð§£¬¹¥»÷Õß¿Éͨ¹ýÍⲿÍØÕ¹£¬ÔÚRedisÖÐʵÏÖÒ»¸öеÄRedisÏÂÁî¡£¹¥»÷Õß¿ÉÒÔʹÓøù¦Ð§ÒýÈëÄ£¿é£¬ÔÚδÊÚȨ»á¼ûµÄÇéÐÎÏÂʹ±»¹¥»÷·þÎñÆ÷¼ÓÔضñÒâ.so Îļþ£¬´Ó¶øʵÏÖÔ¶³Ì´úÂëÖ´ÐС£
ÓÉÓÚVHOST/VHOST_NETȱÉÙ¶ÔÄں˻º³åÇøµÄÑÏ¿á»á¼û½çÏßУÑ飬¹¥»÷Õß¿Éͨ¹ýÔÚÐéÄâ»úÖиü¸ÄVIRTIO networkÇ°¶ËÇý¶¯£¬ÔÚ¸ÃÐéÄâ»ú±»ÈÈǨáãʱ£¬´¥·¢Äں˻º³åÇøÒç³öʵÏÖÐéÄâ»úÌÓÒÝ£¬»ñµÃÔÚËÞÖ÷»úÄÚºËÖÐí§ÒâÖ´ÐдúÂëµÄȨÏÞ£¬¹¥»÷ÕßÒ²¿É´¥·¢ËÞÖ÷»úÄÚºËÍß½âʵÏ־ܾø·þÎñ¹¥»÷¡£
·þÎñÆ÷¡¢´æ´¢¡¢ÍøÂç²úÆ·¹ºÖÃÈÈÏߣº
ERP¡¢¹ÜÀíÈí¼þ¹ºÖÃÈÈÏߣº
ÔÆ·þÎñ²úÆ·ÏúÊÛÈÈÏߣº
K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾ÍøÂçÊÛºóÈÈÏߣº