Intel Inosimbisa Alder Lake UEFI Code Leak

intel-alder-lake

BIOS hardware kodhi yeIntel Alder Lake processors yakatumirwa pa4chan

Mazuva mashoma apfuura pamambure iyo nhau nezve Alder Lake UFEI kodhi kodhi yakaburitswa kubva kuIntel pa4chan uye kopi yakazoburitswa paGitHub.

Nezvenyaya yacho Intel, haina kushanda ipapo ipapo, asi ikozvino yasimbisa huchokwadi kubva kuUEFI uye BIOS firmware source codes yakatumirwa nemunhu asingazivikanwe paGitHub. Pakazara, 5,8 GB yekodhi, zvishandiso, zvinyorwa, mabhurobhu, uye zvigadziriso zvine chekuita nekuumbwa kweiyo firmware zvakaburitswa masisitimu ane processors akavakirwa paAlder Lake microarchitecture, yakaburitswa muna Mbudzi 2021.

Intel inotaura kuti mafaera ane hukama anga achitenderera kwemazuva mashoma uye nekudaro nhau dziri kusimbiswa zvakananga kubva kuIntel, iyo inotaura kuti inoda kutaura kuti nyaya iyi hairevi njodzi nyowani dzekuchengetedza machipisi uye masisitimu ayo anoshandiswa, saka inoda kuti usavhunduke nezvenyaya yacho.

Sekureva kweIntel, kuvuza kwakaitika nekuda kwemunhu wechitatu uye kwete nekuda kwekukanganisa mune zvigadzirwa zvekambani.

"Kodhi yedu yeUEFI inoita kunge yakaburitswa nemunhu wechitatu. Isu hatitendi kuti izvi zvichafumura hutsva hutsva hwekuchengetedzeka, sezvo isu tisingavimbi neruzivo rwekubfuscation senzira yekuchengetedza. Iyi kodhi inofukidzwa nechirongwa chedu chebug bounty mukati meProjekti Circuit Breaker, uye tinokurudzira chero muongorori anogona kuona zvinogona kukanganisa kuti atiunze isu kuburikidza nechirongwa ichi. Tiri kutaura nevatengi uye nenharaunda yekutsvagisa yekuchengetedza kuti varambe vachiziva nezvemamiriro ezvinhu aya. " - Intel mutauriri.

Saka nekudaro hazvitaurwe kuti ndiani chaizvo akazove kwakabva kuvuza (sezvo semuenzaniso vagadziri vemidziyo yeOEM uye makambani ari kugadzira tsika firmware akawana maturusi ekuunganidza firmware).

Nezvenyaya yacho, inotaurwa kuti kuongororwa kwezviri mukati mefaira rakaburitswa kwakaratidza mamwe bvunzo nemasevhisi chaiyo yeLenovo zvigadzirwa ("Lenovo Feature Tag Test Information", "Lenovo String Service", "Lenovo Secure Suite", "Lenovo Cloud Service"), asi kupinda kwaLenovo mukudonha kwakaratidzawo mashandisirwo nemaraibhurari kubva kuInsyde Software, iyo inogadzira firmware yeOEMs, uye. iyo git log ine email kubva mumwe wevashandi ve L.C. Future Center, iyo inogadzira malaptops emhando dzakasiyana dzeOEM.

Sekureva kweIntel, iyo kodhi yakapinda mukuvhurika yekupinda haina data rakadzama kana zvikamu zvinogona kubatsira pakuburitswa kwekusagadzikana kutsva. Panguva imwecheteyo, Mark Yermolov, anonyanya kutsvagisa kuchengetedzwa kweIntel mapuratifomu, akafumura mune yakaburitswa faira ruzivo nezve isina kunyorwa MSR matanda (modhi-yakananga matanda, anoshandiswa ku microcode manejimendi, tracking, uye debugging), ruzivo pamusoro peiyo inowira pasi. chibvumirano chekusavimbika.

Uyewo, kiyi yepachivande yakawanikwa mufaira, iyo inoshandiswa kuisa digitally kusaina firmwareque inogona kushandiswa kudarika Intel Boot Guard kuchengetedza (Kiyi haina kusimbiswa kushanda, inogona kunge iri kiyi yekuyedza.)

Zvinonzi zvakare kodhi yakapinda mukuvhurika yekupinda inovhara chirongwa cheProjekti Circuit Breaker, icho chinosanganisira kubhadharwa kwemubairo kubva kumadhora mazana mashanu kusvika kumadhora zana nemakumi mashanu ekuona matambudziko ekuchengetedza mufirmware uye zvigadzirwa zveIntel (zvinonzwisisika kuti vaongorori vanogona kugamuchira mibairo yekutaura. kusakuvara kwakawanikwa nekushandisa zviri mukati mekudonha).

"Code iyi yakafukidzwa nechirongwa chedu chebug bounty mukati meProjekti Circuit Breaker mushandirapamwe, uye tinokurudzira chero muongorori anogona kuona zvingaite kuti atiudze kuburikidza nechirongwa ichi," Intel akawedzera.

Chekupedzisira, zvakakosha kuti titaure kuti maererano nekudonha kwedata, shanduko ichangoburwa mukodhi yakaburitswa yakaitwa munaGunyana 30, 2022, saka ruzivo rwakaburitswa runovandudzwa.


Iva wekutanga kutaura

Siya yako yekutaura

Your kero e havazobvumirwi ichibudiswa. Raida minda anozivikanwa ne *

*

*

  1. Inotarisira data: AB Internet Networks 2008 SL
  2. Chinangwa cheiyo data: Kudzora SPAM, manejimendi manejimendi.
  3. Legitimation: Kubvuma kwako
  4. Kutaurirana kwedata
  5. Dhata yekuchengetedza: Dhatabhesi inobatwa neOccentus Networks (EU)
  6. Kodzero: Panguva ipi neipi iwe unogona kudzora, kupora uye kudzima ruzivo rwako