Glibci haavatavus, mis võimaldab teise protsessi krahhi tekitada

Glibc's vulnerability (CVE-2021-38604) allows for the initiation of process crashes in the system by sending a specially crafted message through the POSIX message queues API. The issue had not yet manifested in distributions, as it only exists in version 2.34, released two weeks ago.

The problem is caused by improper handling of NOTIFY_REMOVED data in the mq_notify.c code, leading to dereferencing a NULL pointer and crashing the process. Interestingly, this issue is a result of an oversight when fixing another vulnerability (CVE-2021-33574) that was resolved in Glibc 2.34. While the first vulnerability was quite challenging to exploit and required a specific set of circumstances, an attack leveraging the second issue is significantly easier to execute.

Allikas: opennet.ru

Osta usaldusväärne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid 🔥 Osta usaldusväärne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid | ProHoster