{"id":38554,"date":"2019-10-31T22:24:30","date_gmt":"2019-10-31T19:24:30","guid":{"rendered":"https:\/\/prohoster.info\/blog\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra\/"},"modified":"2019-10-31T22:24:30","modified_gmt":"2019-10-31T19:24:30","slug":"v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra","title":{"rendered":"Im Linux-Kernel 5.4 wurden Patches zur Einschr\u00e4nkung des Root-Zugriffs auf interne Kernel-Komponenten angenommen.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Linus Torvalds <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=aefcf2f4b58155d27340ba5f9ddbe9513da8286d\">hat<\/a><\/noindex> Im kommenden Release des Linux-Kernels 5.4 wird ein Satz von Patches enthalten sein, der von Google entwickelt wurde, um den Zugriff des root-Benutzers auf den Kernel einzuschr\u00e4nken. Die mit \u201elockdown\u201c verbundene Funktionalit\u00e4t wurde in ein optional ladbares LSM-Modul ausgegliedert.<noindex><a rel=\"nofollow\" href=\"https:\/\/lkml.org\/lkml\/2019\/9\/10\/856\">lockdown<\/a><\/noindex>&#171; <noindex><a rel=\"nofollow\" href=\"https:\/\/mjg59.dreamwidth.org\/50577.html\">vorgeschlagen<\/a><\/noindex>\tentwickelt von David Howells (arbeitet bei Red Hat) und Matthew Garrett (<noindex><a rel=\"nofollow\" href=\"https:\/\/mjg59.dreamwidth.org\/\">Matthew Garrett<\/a><\/noindex>, \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 Google) \u0434\u043b\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root \u043a \u044f\u0434\u0440\u0443. \u0421\u0432\u044f\u0437\u0430\u043d\u043d\u0430\u044f \u0441 &#171;lockdown&#187; \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u044c \u0432\u044b\u043d\u0435\u0441\u0435\u043d\u0430 \u0432 \u043e\u043f\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c\u044b\u0439 LSM-\u043c\u043e\u0434\u0443\u043b\u044c (<noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Linux_Security_Modules\">Linux Security Module<\/a><\/noindex>) ausgelagert, das eine Barriere zwischen UID 0 und dem Kernel setzt und bestimmte Low-Level-Funktionen einschr\u00e4nkt.<\/p>\n<p>Wenn ein Angreifer durch einen Angriff die Ausf\u00fchrung von Code mit Root-Rechten erlangt, kann er seinen Code auch auf Kernel-Ebene ausf\u00fchren, zum Beispiel durch den Austausch des Kernels mit kexec oder durch das Lesen\/Schreiben von Speicher \u00fcber \/dev\/kmem. Die offensichtlichste Folge einer solchen Aktivit\u00e4t k\u00f6nnte sein, dass <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=41852\">Umgehung<\/a><\/noindex> des UEFI Secure Boot oder die Extraktion vertraulicher Daten, die auf Kernel-Ebene gespeichert sind.<\/p>\n<p>Urspr\u00fcnglich wurden die Funktionen zur Einschr\u00e4nkung von Root im Kontext der Verbesserung der Sicherheit der verifiziertem Boot entwickelt, und Distributionen verwenden seit langem externe Patches, um die Umgehung des UEFI Secure Boot zu blockieren. Diese Einschr\u00e4nkungen wurden jedoch nicht in den Hauptkern aufgenommen aufgrund von <noindex><a rel=\"nofollow\" href=\"https:\/\/lwn.net\/Articles\/751061\/\">Meinungsverschiedenheiten<\/a><\/noindex> Dies geschah aufgrund ihrer Implementierung und der Bedenken, bestehende Systeme zu destabilisieren. Das \u201elockdown\u201c-Modul beinhaltet bereits in Distributionen verwendete Patches, die in Form eines separaten Subsystems umgestaltet wurden, das nicht an UEFI Secure Boot gebunden ist. <\/p>\n<p>Im Lockdown-Modus wird der Zugriff auf \/dev\/mem, \/dev\/kmem, \/dev\/port, \/proc\/kcore, debugfs, den Debug-Modus von kprobes, mmiotrace, tracefs, BPF, PCMCIA CIS (Card Information Structure), einige ACPI-Schnittstellen und MSR-Register der CPU eingeschr\u00e4nkt, kexec_file und kexec_load-Aufrufe werden blockiert, der \u00dcbergang in den Schlafmodus ist verboten, die Verwendung von DMA f\u00fcr PCI-Ger\u00e4te wird limitiert, und das Importieren von ACPI-Code aus EFI-Variablen ist nicht zul\u00e4ssig.<br \/>\nManipulationen mit Ein-\/Ausgabe-Ports sind nicht erlaubt, einschlie\u00dflich der \u00c4nderung der Interruptnummer und des Ein-\/Ausgabe-Ports f\u00fcr den seriellen Port. <\/p>\n<p>Standardm\u00e4\u00dfig ist das lockdown-Modul nicht aktiv, wird jedoch durch Angabe der Option SECURITY_LOCKDOWN_LSM in kconfig kompiliert und wird \u00fcber den Kernel-Parameter \u201elockdown=\u201c, die Steuerdatei \u201e\/sys\/kernel\/security\/lockdown\u201c oder die Build-Optionen aktiviert. <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/torvalds\/linux\/blob\/master\/security\/lockdown\/Kconfig\">LOCK_DOWN_KERNEL_FORCE_*<\/a><\/noindex>, die die Werte \u201eintegrity\u201c und \u201econfidentiality\u201c annehmen k\u00f6nnen. Im ersten Fall werden die M\u00f6glichkeiten blockiert, die es erm\u00f6glichen, \u00c4nderungen am laufenden Kernel aus dem Benutzermodus vorzunehmen; im zweiten Fall wird zus\u00e4tzlich die Funktionalit\u00e4t deaktiviert, die genutzt werden kann, um vertrauliche Informationen aus dem Kernel zu extrahieren.<\/p>\n<p>Es ist wichtig zu beachten, dass der Lockdown nur die standardm\u00e4\u00dfigen Zugriffsm\u00f6glichkeiten auf den Kernel einschr\u00e4nkt, jedoch nicht vor Modifikationen sch\u00fctzt, die durch die Ausnutzung von Schwachstellen entstehen. Um \u00c4nderungen am laufenden Kernel bei der Anwendung von Exploits zu verhindern, hat das Projekt Openwall <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=47989\">seit Sommer 2016). Bis Ende 2019 ist die Ver\u00f6ffentlichung einer weiteren experimentellen Version der GTK 3.9x-Reihe geplant, gefolgt von einem finalen Testrelease von GTK 3.99 im Fr\u00fchling 2020, das alle angestrebten Funktionen enthalten wird. Die Ver\u00f6ffentlichung von GTK 4 wird f\u00fcr Anfang Herbst 2020 erwartet, zeitgleich mit GNOME 3.38.<\/a><\/noindex> ein separates Modul <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lkrg\/\">LKRG<\/a><\/noindex> (Linux Kernel Runtime Guard) angenommen.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51591\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041b\u0438\u043d\u0443\u0441 \u0422\u043e\u0440\u0432\u0430\u043b\u044c\u0434\u0441 \u043f\u0440\u0438\u043d\u044f\u043b \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0431\u0443\u0434\u0443\u0449\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430 \u044f\u0434\u0440\u0430 Linux 5.4 \u043d\u0430\u0431\u043e\u0440 \u043f\u0430\u0442\u0447\u0435\u0439 &#171;lockdown&#171;, \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043d\u044b\u0439 \u0414\u044d\u0432\u0438\u0434\u043e\u043c \u0425\u043e\u0443\u044d\u043b\u043b\u0441\u043e\u043c (David Howells, \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 Red Hat) \u0438 \u041c\u044d\u0442\u044c\u044e \u0413\u0430\u0440\u0440\u0435\u0442\u043e\u043c (Matthew Garrett, \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 Google) \u0434\u043b\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root \u043a \u044f\u0434\u0440\u0443. \u0421\u0432\u044f\u0437\u0430\u043d\u043d\u0430\u044f \u0441 &#171;lockdown&#187; \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u044c \u0432\u044b\u043d\u0435\u0441\u0435\u043d\u0430 \u0432 \u043e\u043f\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c\u044b\u0439 LSM-\u043c\u043e\u0434\u0443\u043b\u044c (Linux Security Module), \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u044e\u0449\u0438\u0439 \u0431\u0430\u0440\u044c\u0435\u0440 \u043c\u0435\u0436\u0434\u0443 UID 0 \u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38554","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041b\u0438\u043d\u0443\u0441 \u0422\u043e\u0440\u0432\u0430\u043b\u044c\u0434\u0441 \u043f\u0440\u0438\u043d\u044f\u043b \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0431\u0443\u0434\u0443\u0449\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430 \u044f\u0434\u0440\u0430 Linux 5.4 \u043d\u0430\u0431\u043e\u0440 \u043f\u0430\u0442\u0447\u0435\u0439 &quot;lockdown&quot;, \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043d\u044b\u0439 \u0414\u044d\u0432\u0438\u0434\u043e\u043c \u0425\u043e\u0443\u044d\u043b\u043b\u0441\u043e\u043c (David Howells, \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 Red Hat) \u0438 \u041c\u044d\u0442\u044c\u044e \u0413\u0430\u0440\u0440\u0435\u0442\u043e\u043c (Matthew Garrett, \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 Google) \u0434\u043b\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root \u043a \u044f\u0434\u0440\u0443. \u0421\u0432\u044f\u0437\u0430\u043d\u043d\u0430\u044f \u0441 &quot;lockdown&quot; \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u044c \u0432\u044b\u043d\u0435\u0441\u0435\u043d\u0430 \u0432 \u043e\u043f\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c\u044b\u0439 LSM-\u043c\u043e\u0434\u0443\u043b\u044c (Linux Security Module), \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u044e\u0449\u0438\u0439 \u0431\u0430\u0440\u044c\u0435\u0440 \u043c\u0435\u0436\u0434\u0443 UID 0 \u0438\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 \u044f\u0434\u0440\u043e Linux 5.4 \u043f\u0440\u0438\u043d\u044f\u0442\u044b \u043f\u0430\u0442\u0447\u0438 \u0434\u043b\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 root \u043a \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c \u044f\u0434\u0440\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041b\u0438\u043d\u0443\u0441 \u0422\u043e\u0440\u0432\u0430\u043b\u044c\u0434\u0441 \u043f\u0440\u0438\u043d\u044f\u043b \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0431\u0443\u0434\u0443\u0449\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430 \u044f\u0434\u0440\u0430 Linux 5.4 \u043d\u0430\u0431\u043e\u0440 \u043f\u0430\u0442\u0447\u0435\u0439 &quot;lockdown&quot;, \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043d\u044b\u0439 \u0414\u044d\u0432\u0438\u0434\u043e\u043c \u0425\u043e\u0443\u044d\u043b\u043b\u0441\u043e\u043c (David Howells, \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 Red Hat) \u0438 \u041c\u044d\u0442\u044c\u044e \u0413\u0430\u0440\u0440\u0435\u0442\u043e\u043c (Matthew Garrett, \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 Google) \u0434\u043b\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root \u043a \u044f\u0434\u0440\u0443. \u0421\u0432\u044f\u0437\u0430\u043d\u043d\u0430\u044f \u0441 &quot;lockdown&quot; \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u044c \u0432\u044b\u043d\u0435\u0441\u0435\u043d\u0430 \u0432 \u043e\u043f\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c\u044b\u0439 LSM-\u043c\u043e\u0434\u0443\u043b\u044c (Linux Security Module), \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u044e\u0449\u0438\u0439 \u0431\u0430\u0440\u044c\u0435\u0440 \u043c\u0435\u0436\u0434\u0443 UID 0 \u0438\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:24:30+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:24:30+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Im Linux-Kernel 5.4 wurden Patches angenommen, um den Zugriff von Root auf die Inneren des Kernels zu beschr\u00e4nken | ProHoster","description":"Linus Torvalds hat im zuk\u00fcnftigen Release des Linux-Kernels 5.4 eine Reihe von \u201eLockdown\u201c-Patches akzeptiert, die von David Howells (Red Hat) und Matthew Garrett (Google) vorgeschlagen wurden, um den Zugriff von Root-Benutzern auf den Kernel einzuschr\u00e4nken. Die mit \u201eLockdown\u201c verbundene Funktionalit\u00e4t wurde in ein optional ladbares LSM-Modul (Linux Security Module) ausgelagert, das eine Barriere zwischen UID 0 und","canonical_url":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 \u044f\u0434\u0440\u043e Linux 5.4 \u043f\u0440\u0438\u043d\u044f\u0442\u044b \u043f\u0430\u0442\u0447\u0438 \u0434\u043b\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 root \u043a \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c \u044f\u0434\u0440\u0430 | ProHoster","og:description":"\u041b\u0438\u043d\u0443\u0441 \u0422\u043e\u0440\u0432\u0430\u043b\u044c\u0434\u0441 \u043f\u0440\u0438\u043d\u044f\u043b \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0431\u0443\u0434\u0443\u0449\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430 \u044f\u0434\u0440\u0430 Linux 5.4 \u043d\u0430\u0431\u043e\u0440 \u043f\u0430\u0442\u0447\u0435\u0439 &quot;lockdown&quot;, \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043d\u044b\u0439 \u0414\u044d\u0432\u0438\u0434\u043e\u043c \u0425\u043e\u0443\u044d\u043b\u043b\u0441\u043e\u043c (David Howells, \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 Red Hat) \u0438 \u041c\u044d\u0442\u044c\u044e \u0413\u0430\u0440\u0440\u0435\u0442\u043e\u043c (Matthew Garrett, \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 Google) \u0434\u043b\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root \u043a \u044f\u0434\u0440\u0443. \u0421\u0432\u044f\u0437\u0430\u043d\u043d\u0430\u044f \u0441 &quot;lockdown&quot; \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u044c \u0432\u044b\u043d\u0435\u0441\u0435\u043d\u0430 \u0432 \u043e\u043f\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c\u044b\u0439 LSM-\u043c\u043e\u0434\u0443\u043b\u044c (Linux Security Module), \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u044e\u0449\u0438\u0439 \u0431\u0430\u0440\u044c\u0435\u0440 \u043c\u0435\u0436\u0434\u0443 UID 0 \u0438","og:url":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:24:30+00:00","article:modified_time":"2019-10-31T19:24:30+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38554","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 22:31:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:07:39","updated":"2026-01-23 22:31:19"},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/38554","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=38554"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/38554\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=38554"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=38554"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=38554"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}