¸ü¶à Ñ¡ÔñÓïÑÔ
< ·µ»ØÖ÷²Ëµ¥
Äþ¾²Ô¤¾¯-Linux Grub2 BootHole©¶´
Ô¤¾¯±àºÅ£ºINSPUR-SA-202008-001
³õʼÐû²¼Ê±¼ä£º2020-08-12 16:49:57
¸üÐÂÐû²¼Ê±¼ä£º2020-09-01 08:28:46
©¶´À´Ô´£º

Äþ¾²Ñо¿¹«Ë¾ EclypsiumÅû¶

©¶´Ó°Ï죺

¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´Ö´ÐÐÈÎÒâ´úÂ룬½øÒ»²½½Ù³ÖÅÌËã»úµÄÒýµ¼Àú³Ì²¢ÈƹýSecure Boot±£»¤, ¿ØÖÆÊÜÓ°ÏìµÄÉ豸¡£

©¶´ÃèÊö£º

Äþ¾²Ñо¿¹«Ë¾ EclypsiumÆعâÁËLinux Grub2Òýµ¼¼ÓÔسÌÐòÖÐÒ»¸öÃûΪ¡°BootHole¡±£¨CVE-2020-10713£©µÄ©¶´¡£´Ë©¶´ÔÊÐí¹¥»÷Õß½Ù³ÖÒýµ¼½ø³Ì²¢ÔÚϵͳÆô¶¯ÆÚ¼äÖ´ÐжñÒâ´úÂ룬×ÝȻʹÓÃUEFI Secure BootµÄϵͳҲ¿ÉÒÔʹÓôË©¶´Èƹý¡£
Grub2 boot loaderͨ¹ýgrub.cfgÎļþÅäÖ㬸ÃÎļþÖаüÀ¨¶à¸ötokens×Ö·û´®¡£ÔÚ³õʼÒýµ¼¼ÓÔسÌÐò£¨³ÆΪshim£©¼ÓÔØÖ®ºó£¬¿ªÊ¼¼ÓÔØÏ¢ÕùÎögrub.cfgÅäÖÃÎļþ¡£ÔÚ½âÎö½×¶Î£¬ÅäÖÃÎļþµÄÄÚÈݱ»¸´ÖƵ½ÄÚ´æµÄÄÚ²¿»º³åÇøÖд洢¡£µ±tokens³¤¶È´óÓÚÄÚ²¿»º³åÇø¾Þϸʱ»áµ¼Ö»º³åÇøÒç³öÎÊÌâ¡£¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´Ö´ÐÐÈÎÒâ´úÂ룬½øÒ»²½½Ù³ÖÅÌËã»úµÄÒýµ¼Àú³Ì²¢ÈƹýSecure Boot±£»¤¡£

CVSSÆÀ·Ö£º

CVE V3.1 Vector(Base) Base Score V3.1 Vector(Temporal Score) Temporal Score
CVE-2020-10713 AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H 8.2 E:U/RL:O/RC:C 7.1

ÊÜÓ°Ïì²úÆ·£º

²úÆ·Ãû³Æ ÊÜÓ°Ïì²úÆ·°æ±¾ ÐÞ¸´²¹¶¡°ü/Éý¼¶°ü°æ±¾
¡¡¡¡AS13000 AS13000 > 3.5.0.1  grub2-2.02-0.65-AS13000-update.tar.gz
ICS ICS<=5.8.1  V5.8.1°æ±¾Í¨¹ý²¹¶¡½øÐÐÐÞ¸´£¬²¹¶¡°üÃû³Æ£º
IncloudSphere-V5R08B017-b1-M001.hotfix.zip
IncloudSphere-V5R08B017-b1-S001.hotfix.zip£»
СÓÚV5.8.1°æ±¾²úÆ·£¬ÐèÒªÏÈÉý¼¶µ½v5.8.1°æ±¾£¬ÔÙͨ¹ý²¹¶¡½øÐÐÐÞ¸´¡£
ICOS ICOS>=5.2,ICOS<=5.8 ICOS-CVE-2020-10713.rar

¼¼Êõϸ½Ú£º

©¶´Ô­Òò£ºGRUB2 ÔÚ´¦ÀíÆä×ÔÉíµÄÅäÖÃÎļþ grub.cfg ʱ±£´æ»º³åÇøÒç³ö©¶´¡£¹¥»÷Õßͨ¹ý´´Á¢ÌØÖÆµÄ grub.cfg Îļþ£¬ÔÚÏÂÒ»´ÎÖØÆôºó¹¥»÷Õß¿ÉÒÔ²»ÊÜÏÞÖƵĿØÖÆÊÜÓ°ÏìµÄÉ豸¡£
ÀûÓÃÌõ¼þ£ºÔ¶³Ìroot»á¼û£¬¿ÉÐÞ¸Ägrub.cfgÎļþ¡£

©¶´½â¾ö¼Æ»®£º

AS13000Óû§Ö±½ÓÁªÏµ¿Í»§Ð§ÀÍÈËÔ±»ò·¢ËÍÓʼþÖÁsun.meng@inspur.com£¬»ñÈ¡²¹¶¡£¬ÒÔ¼°Ïà¹ØµÄ¼¼ÊõЭÖú¡£
ICOS¡¢ICSÓû§Ö±½ÓÁªÏµÖ§³ÖÈËÔ±»ñÈ¡²¹¶¡ÒÔ¼°Ïà¹ØµÄ¼¼ÊõЭÖú¡£
ISPIM:ÏÂÔØ
ISIB:ÏÂÔØ

FAQ£º

ÎÞ

¸üмͼ£º

20200812-V1.0-Initial Release
20200831-V1.1-Update Ôö¼ÓÊÜÓ°Ïì²úÆ·Çåµ¥
20200901-V1.2-Update Ôö¼ÓÊÜÓ°Ïì²úÆ·Çåµ¥

pgµç×Ó¹ÙÍøÄþ¾²Ó¦¼±ÏìÓ¦¶ÔÍâЧÀÍ£º
pgµç×Ó¹ÙÍøÒ»¹áÖ÷Õž¡È«Á¦°ü¹Ü²úÆ·Óû§µÄ×îÖÕÀûÒ棬×ñÑ­ÂôÁ¦ÈεÄÄþ¾²Ê¼þÅû¶ԭÔò£¬²¢Í¨¹ý²úÆ·Äþ¾²ÎÊÌâ´¦Àí»úÖÆ´¦Àí²úÆ·Äþ¾²ÎÊÌâ¡£
·´Ïìpgµç×Ó¹ÙÍø²úÆ·Äþ¾²ÎÊÌ⣺ /lcjtww/psirt/vulnerability-management/index.html#report_ldbg

»ñÈ¡¼¼ÊõÖ§³Ö£º/lcjtww/2317452/2317456/2317460/index.html

ÉùÃ÷

±¾ÎĵµÌṩµÄËùÓÐÊý¾ÝºÍÐÅÏ¢½ö¹©²Î¿¼£¬ÇÒ"°´Ô­Ñù"Ìṩ£¬²»ÔÊÐíÈκÎÃ÷ʾ¡¢Ä¬Ê¾ºÍ·¨¶¨µÄµ£±££¬°üÀ¨(µ«²»ÏÞÓÚ)¶ÔÊÊÏúÐÔ¡¢ÊÊÓÃÐÔ¼°²»ÇÖȨµÄµ£±£¡£ÔÚÈκÎÇé¿öÏ£¬pgµç×Ó¹ÙÍø»òÆäÖ±½Ó»ò¼ä½Ó¿ØÖƵÄ×Ó¹«Ë¾£¬»òÆ乩ӦÉÌ£¬¾ù²î³ØÈκÎÒ»·½ÒòÒÀÀµ»òʹÓñ¾ÐÅÏ¢¶øÔâÊܵÄÈκÎËðʧµ£ÂôÁ¦ÈΣ¬°üÀ¨Ö±½Ó£¬¼ä½Ó£¬Å¼È»£¬Ò»¶¨µÄÉÌÒµÀûÈóËðʧ»òÌØÊâËðʧ¡£pgµç×Ó¹ÙÍø±£´æËæʱ¸ü¸Ä»ò¸üдËÎĵµµÄȨÀû¡£

ÔÚ
Ïß
¿Í
·þ
?
Áª
ϵ
ÎÒ
ÃÇ
¡Á
PGµç×Ó¡¤(Öйú)¹Ù·½ÍøÕ¾ ÁªÏµpgµç×Ó¹ÙÍø
ERP¡¢ÆóÒµÈí¼þ¹ºÖÃÈÈÏß
400-018-7700
ÔÆЧÀͲúÆ·ÏúÊÛÈÈÏß
400-607-6657
¼¯ÍÅ¿Í»§Í¶ËßÈÈÏß
400-691-8711
ÖÇÄÜÖն˲úÆ·¿Í·þÈÈÏß
400-658-6111
ÍøÕ¾µØͼ