¸ü¶à Ñ¡ÔñÓïÑÔ
< ·µ»ØÖ÷²Ëµ¥
Çå¾²Ô¤¾¯-Linux Grub2 BootHoleÎó²î
Ô¤¾¯±àºÅ£ºINSPUR-SA-202008-001
³õʼÐû²¼Ê±¼ä£º2020-08-12 16:49:57
¸üÐÂÐû²¼Ê±¼ä£º2020-09-01 08:28:46
Îó²îȪԴ£º

Çå¾²Ñо¿¹«Ë¾ EclypsiumÅû¶

Îó²îÓ°Ï죺

¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬½øÒ»²½Ð®ÖÆÅÌËã»úµÄÖ¸µ¼Àú³Ì²¢ÈƹýSecure Boot±£»£»£»¤, ¿ØÖÆÊÜÓ°ÏìµÄ×°±¸¡£¡£¡£

Îó²îÐÎò£º

Çå¾²Ñо¿¹«Ë¾ EclypsiumÆØ¹âÁËLinux Grub2Ö¸µ¼¼ÓÔØ³ÌÐòÖÐÒ»¸öÃûΪ¡°BootHole¡±£¨CVE-2020-10713£©µÄÎó²î¡£¡£¡£´ËÎó²îÔÊÐí¹¥»÷ÕßÐ®ÖÆÖ¸µ¼Àú³Ì²¢ÔÚϵͳÆô¶¯Ê±´úÖ´ÐжñÒâ´úÂ룬£¬£¬£¬×ÝȻʹÓÃUEFI Secure BootµÄϵͳҲ¿ÉÒÔʹÓôËÎó²îÈÆ¹ý¡£¡£¡£
Grub2 boot loaderͨ¹ýgrub.cfgÎļþÉèÖ㬣¬£¬£¬¸ÃÎļþÖаüÀ¨¶à¸ötokens×Ö·û´®¡£¡£¡£ÔÚ³õʼָµ¼¼ÓÔØ³ÌÐò£¨³ÆÎªshim£©¼ÓÔØÖ®ºó£¬£¬£¬£¬×îÏȼÓÔØÏ¢ÕùÎögrub.cfgÉèÖÃÎļþ¡£¡£¡£ÔÚÆÊÎö½×¶Î£¬£¬£¬£¬ÉèÖÃÎļþµÄÄÚÈݱ»¸´ÖƵ½ÄÚ´æµÄÄÚ²¿»º³åÇøÖд洢¡£¡£¡£µ±tokens³¤¶È´óÓÚÄÚ²¿»º³åÇø¾Þϸʱ»áµ¼Ö»º³åÇøÒç³öÎÊÌâ¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬½øÒ»²½Ð®ÖÆÅÌËã»úµÄÖ¸µ¼Àú³Ì²¢ÈƹýSecure Boot±£»£»£»¤¡£¡£¡£

CVSSÆÀ·Ö£º

CVE V3.1 Vector(Base) Base Score V3.1 Vector(Temporal Score) Temporal Score
CVE-2020-10713 AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H 8.2 E:U/RL:O/RC:C 7.1

ÊÜÓ°Ïì²úÆ·£º

²úÆ·Ãû³Æ ÊÜÓ°Ïì²úÆ·°æ±¾ ÐÞ¸´²¹¶¡°ü/Éý¼¶°ü°æ±¾
¡¡¡¡AS13000 AS13000 > 3.5.0.1  grub2-2.02-0.65-AS13000-update.tar.gz
ICS ICS<=5.8.1  V5.8.1°æ±¾Í¨¹ý²¹¶¡¾ÙÐÐÐÞ¸´£¬£¬£¬£¬²¹¶¡°üÃû³Æ£º
IncloudSphere-V5R08B017-b1-M001.hotfix.zip
IncloudSphere-V5R08B017-b1-S001.hotfix.zip£»£»£»
СÓÚV5.8.1°æ±¾²úÆ·£¬£¬£¬£¬ÐèÒªÏÈÉý¼¶µ½v5.8.1°æ±¾£¬£¬£¬£¬ÔÙͨ¹ý²¹¶¡¾ÙÐÐÐÞ¸´¡£¡£¡£
ICOS ICOS>=5.2,ICOS<=5.8 ICOS-CVE-2020-10713.rar

ÊÖÒÕϸ½Ú£º

Îó²îÔµ¹ÊÔ­ÓÉ£ºGRUB2 ÔÚ´¦Öóͷ£Æä×ÔÉíµÄÉèÖÃÎļþ grub.cfg ʱ±£´æ»º³åÇøÒç³öÎó²î¡£¡£¡£¹¥»÷Õßͨ¹ý½¨ÉèÌØÖÆµÄ grub.cfg Îļþ£¬£¬£¬£¬ÔÚÏÂÒ»´ÎÖØÆôºó¹¥»÷Õß¿ÉÒÔ²»ÊÜÏÞÖÆµÄ¿ØÖÆÊÜÓ°ÏìµÄ×°±¸¡£¡£¡£
ʹÓÃÌõ¼þ£ºÔ¶³Ìroot»á¼û£¬£¬£¬£¬¿ÉÐÞ¸Ägrub.cfgÎļþ¡£¡£¡£

Îó²î½â¾ö¼Æ»®£º

AS13000Óû§Ö±½ÓÁªÏµ¿Í»§Ð§ÀÍÖ°Ô±»ò·¢ËÍÓʼþÖÁsun.meng@inspur.com£¬£¬£¬£¬»ñÈ¡²¹¶¡£¬£¬£¬£¬ÒÔ¼°Ïà¹ØµÄÊÖÒÕЭÖú¡£¡£¡£
ICOS¡¢ICSÓû§Ö±½ÓÁªÏµÖ§³ÖÖ°Ô±»ñÈ¡²¹¶¡ÒÔ¼°Ïà¹ØµÄÊÖÒÕЭÖú¡£¡£¡£
ISPIM:ÏÂÔØ
ISIB:ÏÂÔØ

FAQ£º

ÎÞ

¸üмͼ£º

20200812-V1.0-Initial Release
20200831-V1.1-Update ÔöÌíÊÜÓ°Ïì²úÆ·Çåµ¥
20200901-V1.2-Update ÔöÌíÊÜÓ°Ïì²úÆ·Çåµ¥

yl6776ÓÀÀû¼¯ÍÅÇå¾²Ó¦¼±ÏìÓ¦¶ÔÍâЧÀÍ£º
yl6776ÓÀÀû¼¯ÍÅÒ»Ö±Ö÷Õž¡È«Á¦°ü¹Ü²úÆ·Óû§µÄ×îÖÕÀûÒæ£¬£¬£¬£¬×ñÕÕÈÏÕæÈεÄÇå¾²ÊÂÎñÅû¶ԭÔò£¬£¬£¬£¬²¢Í¨¹ý²úÆ·Çå¾²ÎÊÌâ´¦Öóͷ£»úÖÆ´¦Öóͷ£²úÆ·Çå¾²ÎÊÌâ¡£¡£¡£
·´Ïìyl6776ÓÀÀû¼¯ÍŲúÆ·Çå¾²ÎÊÌ⣺ /lcjtww/psirt/vulnerability-management/index.html#report_ldbg

»ñÈ¡ÊÖÒÕÖ§³Ö£º/lcjtww/2317452/2317456/2317460/index.html

ÉùÃ÷

±¾ÎĵµÌṩµÄËùÓÐÊý¾ÝºÍÐÅÏ¢½ö¹©²Î¿¼£¬£¬£¬£¬ÇÒ"°´Ô­Ñù"Ìṩ£¬£¬£¬£¬²»ÔÊÐíÈκÎÕÑʾ¡¢Ä¬Ê¾ºÍ·¨¶¨µÄµ£±££¬£¬£¬£¬°üÀ¨(µ«²»ÏÞÓÚ)¶ÔÊÊÏúÐÔ¡¢ÊÊÓÃÐÔ¼°²»ÇÖȨµÄµ£±£¡£¡£¡£ÔÚÈκÎÇéÐÎÏ£¬£¬£¬£¬yl6776ÓÀÀû¼¯ÍÅ»òÆäÖ±½Ó»ò¼ä½Ó¿ØÖƵÄ×Ó¹«Ë¾£¬£¬£¬£¬»òÆä¹©Ó¦ÉÌ£¬£¬£¬£¬¾ù²î³ØÈκÎÒ»·½ÒòÒÀÀµ»òʹÓñ¾ÐÅÏ¢¶øÔâÊܵÄÈκÎËðʧ¼ç¸ºÔðÈΣ¬£¬£¬£¬°üÀ¨Ö±½Ó£¬£¬£¬£¬¼ä½Ó£¬£¬£¬£¬ÎÞÒ⣬£¬£¬£¬Ò»¶¨µÄÉÌÒµÀûÈóËðʧ»òÌØÊâËðʧ¡£¡£¡£yl6776ÓÀÀû¼¯Íű£´æËæÊ±¸ü¸Ä»ò¸üдËÎĵµµÄȨÁ¦¡£¡£¡£

ÔÚ
Ïß
¿Í
·þ
?
Áª
ϵ
ÎÒ
ÃÇ
¡Á
yl6776ÓÀÀû¼¯ÍÅ(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾¹ÙÍø ÁªÏµyl6776ÓÀÀû¼¯ÍÅ
ERP¡¢ÆóÒµÈí¼þ¹ºÖÃÈÈÏß
400-018-7700
ÕþÎñÔÆ²úÆ·ÏúÊÛÈÈÏß
400-607-6657
ÆóÒµÔÆ²úÆ·ÏúÊÛÈÈÏß
400-699-1556 ת 5
¼¯Íſͻ§Í¶ËßÈÈÏß
400-691-8711
ÖÇÄÜÖն˲úÆ·¿Í·þÈÈÏß
400-658-6111
¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿