{"id":39040,"date":"2019-10-31T22:27:31","date_gmt":"2019-10-31T19:27:31","guid":{"rendered":"https:\/\/prohoster.info\/blog\/udalyonno-ekspluatiruemaya-uyazvimost-v-linux-drajvere-dlya-chipov-realtek\/"},"modified":"2019-10-31T22:27:31","modified_gmt":"2019-10-31T19:27:31","slug":"udalyonno-ekspluatiruemaya-uyazvimost-v-linux-drajvere-dlya-chipov-realtek","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-linux-drajvere-dlya-chipov-realtek","title":{"rendered":"Fernzugreifbare Schwachstelle im Linux-Treiber f\u00fcr Realtek-Chips","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Im Linux-Kernel enthaltenen Treiber <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/torvalds\/linux\/tree\/master\/drivers\/net\/wireless\/realtek\/rtlwifi\">rtlwifi<\/a><\/noindex> f\u00fcr drahtlose Adapter mit Realtek-Chips <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/nicowaisman\/status\/1184864519316758535\">entdeckt<\/a><\/noindex> Schwachstelle (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-17666\">CVE-2019-17666<\/a><\/noindex>), die potenziell ausgenutzt werden kann, um die Ausf\u00fchrung von Code im Kontext des Kernels durch das Senden speziell gestalteter Pakete zu erm\u00f6glichen.<\/p>\n<p>Die Schwachstelle wird durch einen Puffer\u00fcberlauf im Code des P2P-Modus (Wifi-Direct) verursacht. Bei der Analyse der Pakete <noindex><a rel=\"nofollow\" href=\"https:\/\/hsc.com\/DesktopModules\/DigArticle\/Print.aspx?PortalId=0&#038;ModuleId=1215&#038;Article=221\">NoA<\/a><\/noindex> (Notice of Absence) gibt es keine \u00dcberpr\u00fcfung der Gr\u00f6\u00dfe eines der Werte, was es erm\u00f6glicht, Daten \u00fcber das Ende des Puffers hinaus zu schreiben und Informationen in den nach dem Puffer folgenden Kernelstrukturen zu \u00fcberschreiben.<\/p>\n<p>Ein Angriff kann durch das Senden speziell gestalteter Pakete an ein System mit einem aktiven drahtlosen Adapter auf Basis eines Realtek-Chips erfolgen, das die Technologie unterst\u00fctzt <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/Wi-Fi_Direct\">Wi-Fi Direct<\/a><\/noindex>, die es zwei drahtlosen Adaptern erm\u00f6glicht, eine Verbindung direkt ohne Zugangspunkt herzustellen. F\u00fcr die Ausnutzung des Problems ist keine Verbindung zum drahtlosen Netzwerk des Angreifers erforderlich, ebenso sind keine Aktionen des Benutzers erforderlich, solange der Angreifer sich im Bereich des drahtlosen Signals befindet. <\/p>\n<p>Ein funktionierender Exploit-Prototyp beschr\u00e4nkt sich bisher auf den remote Aufruf eines Kernel-Crashes, aber die Schwachstelle schlie\u00dft potenziell die M\u00f6glichkeit der Ausf\u00fchrung von Code nicht aus (dies ist bisher nur eine theoretische Annahme, da es noch keinen Exploit-Prototyp f\u00fcr die Codeausf\u00fchrung gibt, aber der Forscher, der das Problem entdeckt hat, arbeitet bereits <noindex><a rel=\"nofollow\" href=\"https:\/\/arstechnica.com\/information-technology\/2019\/10\/unpatched-linux-flaw-may-let-attackers-crash-or-compromise-nearby-devices\/\">an uarch-bench<\/a><\/noindex> an dessen Erstellung).<\/p>\n<p>Das Problem tritt ab Kernel <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=38331\">3.12<\/a><\/noindex> (laut anderen Berichten tritt das Problem ab Kernel <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=37315\">3.10<\/a><\/noindex>) auf, der 2013 ver\u00f6ffentlicht wurde. Ein Fix ist bisher nur in Form von <noindex><a rel=\"nofollow\" href=\"https:\/\/lkml.org\/lkml\/2019\/10\/16\/1226\">Patches<\/a><\/noindex>. In den Distributionen bleibt das Problem unbehoben.<br \/>\nDie Beseitigung von Schwachstellen in den Distributionen kann auf den folgenden Seiten verfolgt werden: <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-17666\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.suse.com\/security\/cve\/CVE-2019-17666\/\">SUSE\\\/openSUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2019-17666\">RHEL<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-17666.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/security.archlinux.org\/CVE-2019-17666\">Arch Linux<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?releases=F30&#038;type=security\">Fedora<\/a><\/noindex>. Wahrscheinlich betrifft die Schwachstelle auch <noindex><a rel=\"nofollow\" href=\"https:\/\/android.googlesource.com\/kernel\/tegra\/+\/refs\/tags\/android-8.1.0_r0.135\/drivers\/net\/wireless\/rtlwifi\/ps.c#750\">betroffen<\/a><\/noindex> und die Android-Plattform.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51700\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 rtlwifi \u0434\u043b\u044f \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0430\u0434\u0430\u043f\u0442\u0435\u0440\u043e\u0432 \u043d\u0430 \u0447\u0438\u043f\u0430\u0445 Realtek \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-17666), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u0432 \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442\u0435 \u044f\u0434\u0440\u0430 \u043f\u0440\u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u043a\u0430\u0434\u0440\u043e\u0432. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435\u043c \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 \u043a\u043e\u0434\u0435 \u0441 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0435\u0439 \u0440\u0435\u0436\u0438\u043c\u0430 P2P (Wifi-Direct). \u041f\u0440\u0438 \u0440\u0430\u0437\u0431\u043e\u0440\u0435 \u043a\u0430\u0434\u0440\u043e\u0432 NoA (Notice of Absence) \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u0440\u0430\u0437\u043c\u0435\u0440\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-39040","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 rtlwifi \u0434\u043b\u044f \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0430\u0434\u0430\u043f\u0442\u0435\u0440\u043e\u0432 \u043d\u0430 \u0447\u0438\u043f\u0430\u0445.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-linux-drajvere-dlya-chipov-realtek\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Linux-\u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 \u0434\u043b\u044f \u0447\u0438\u043f\u043e\u0432 Realtek | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 rtlwifi \u0434\u043b\u044f \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0430\u0434\u0430\u043f\u0442\u0435\u0440\u043e\u0432 \u043d\u0430 \u0447\u0438\u043f\u0430\u0445.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-linux-drajvere-dlya-chipov-realtek\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:27:31+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:27:31+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Remote ausnutzbare Schwachstelle im Linux-Treiber f\u00fcr Realtek-Chips | ProHoster","description":"Im Linux-Kernel enthaltenen Treiber rtlwifi f\u00fcr drahtlose Adapter mit Chips.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-linux-drajvere-dlya-chipov-realtek","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Linux-\u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 \u0434\u043b\u044f \u0447\u0438\u043f\u043e\u0432 Realtek | ProHoster","og:description":"\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 rtlwifi \u0434\u043b\u044f \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0430\u0434\u0430\u043f\u0442\u0435\u0440\u043e\u0432 \u043d\u0430 \u0447\u0438\u043f\u0430\u0445.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-linux-drajvere-dlya-chipov-realtek","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:27:31+00:00","article:modified_time":"2019-10-31T19:27:31+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"39040","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 00:30:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 00:58:37","updated":"2026-01-24 00:30:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/39040","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=39040"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/39040\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=39040"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=39040"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=39040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}