{"id":38554,"date":"2019-10-31T22:24:30","date_gmt":"2019-10-31T19:24:30","guid":{"rendered":"https:\/\/prohoster.info\/blog\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra\/"},"modified":"2019-10-31T22:24:30","modified_gmt":"2019-10-31T19:24:30","slug":"v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra","title":{"rendered":"Des correctifs ont \u00e9t\u00e9 accept\u00e9s dans le noyau Linux 5.4 pour restreindre l'acc\u00e8s root aux entrailles du noyau","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Linus Torvalds <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=aefcf2f4b58155d27340ba5f9ddbe9513da8286d\">a accept\u00e9<\/a><\/noindex> Le prochain noyau Linux 5.4 comprendra un ensemble de correctifs \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/lkml.org\/lkml\/2019\/9\/10\/856\">lockdown<\/a><\/noindex>\u00ab <noindex><a rel=\"nofollow\" href=\"https:\/\/mjg59.dreamwidth.org\/50577.html\">propos\u00e9<\/a><\/noindex>\tDavid Howells (travaille chez Red Hat) et Matthew Garrett (<noindex><a rel=\"nofollow\" href=\"https:\/\/mjg59.dreamwidth.org\/\">Matthew Garrett<\/a><\/noindex>, qui travaille chez Google) pour restreindre l'acc\u00e8s de l'utilisateur root au noyau. La fonctionnalit\u00e9 associ\u00e9e au \u00ab lockdown \u00bb est int\u00e9gr\u00e9e dans un module LSM optionnel (<noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Linux_Security_Modules\">Linux Security Module<\/a><\/noindex>), qui \u00e9tablit une barri\u00e8re entre l'UID 0 et le noyau, limitant certaines fonctionnalit\u00e9s de bas niveau.<\/p>\n<p>Si un attaquant r\u00e9ussit, \u00e0 la suite d'une attaque, \u00e0 ex\u00e9cuter du code avec des privil\u00e8ges root, il peut ex\u00e9cuter son code au niveau du noyau, par exemple en rempla\u00e7ant le noyau via kexec ou en lisant\/\u00e9crivant la m\u00e9moire \u00e0 travers \/dev\/kmem. La cons\u00e9quence la plus \u00e9vidente de telles activit\u00e9s pourrait \u00eatre <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=41852\">le contournement<\/a><\/noindex> de l'UEFI Secure Boot ou l'extraction de donn\u00e9es sensibles stock\u00e9es au niveau du noyau.<\/p>\n<p>Au d\u00e9part, les fonctions de restriction de root ont \u00e9t\u00e9 d\u00e9velopp\u00e9es dans le contexte du renforcement de la protection de la cha\u00eene de d\u00e9marrage v\u00e9rifi\u00e9e, et les distributions utilisent d\u00e9j\u00e0 depuis longtemps des patches tiers pour bloquer le contournement de l'UEFI Secure Boot. Cependant, ces restrictions n'ont pas \u00e9t\u00e9 incluses dans la version principale du noyau en raison de <noindex><a rel=\"nofollow\" href=\"https:\/\/lwn.net\/Articles\/751061\/\">d\u00e9saccords<\/a><\/noindex> dans leur mise en \u0153uvre et les craintes d'impact sur les syst\u00e8mes existants. Le module \u00ab lockdown \u00bb regroupe d\u00e9j\u00e0 des correctifs utilis\u00e9s dans les distributions, qui ont \u00e9t\u00e9 retravaill\u00e9s sous la forme d'un sous-syst\u00e8me distinct, non li\u00e9 \u00e0 UEFI Secure Boot. <\/p>\n<p>En mode lockdown, l'acc\u00e8s \u00e0 \/dev\/mem, \/dev\/kmem, \/dev\/port, \/proc\/kcore, debugfs, au mode de d\u00e9bogage kprobes, mmiotrace, tracefs, BPF, PCMCIA CIS (Card Information Structure), certains interfaces ACPI et registres MSR du CPU est limit\u00e9. Les appels kexec_file et kexec_load sont bloqu\u00e9s, le passage en mode veille est interdit, l'utilisation de DMA pour les dispositifs PCI est limit\u00e9e, l'importation de code ACPI \u00e0 partir de variables EFI est interdite,<br \/>\nles man\u0153uvres avec les ports d'entr\u00e9e\/sortie sont proscrites, y compris la modification du num\u00e9ro d'interruption et du port d'entr\u00e9e\/sortie pour le port s\u00e9rie. <\/p>\n<p>Par d\u00e9faut, le module lockdown n'est pas actif, il est construit en sp\u00e9cifiant l'option SECURITY_LOCKDOWN_LSM dans kconfig et est activ\u00e9 via le param\u00e8tre du noyau \u00ab lockdown= \u00bb, un fichier de contr\u00f4le \u00ab \/sys\/kernel\/security\/lockdown \u00bb ou des options de construction <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/torvalds\/linux\/blob\/master\/security\/lockdown\/Kconfig\">LOCK_DOWN_KERNEL_FORCE_*<\/a><\/noindex>, qui peuvent prendre les valeurs \u00ab integrity \u00bb et \u00ab confidentiality \u00bb. Dans le premier cas, il bloque les capacit\u00e9s permettant de modifier le noyau en cours d'ex\u00e9cution depuis l'espace utilisateur, et dans le second, il d\u00e9sactive en plus les fonctionnalit\u00e9s pouvant \u00eatre utilis\u00e9es pour extraire des informations confidentielles du noyau.<\/p>\n<p>Il est important de noter que le lockdown limite seulement les capacit\u00e9s d'acc\u00e8s standard au noyau, mais ne prot\u00e8ge pas contre les modifications r\u00e9sultant de l'exploitation de vuln\u00e9rabilit\u00e9s. Pour emp\u00eacher les modifications du noyau en fonctionnement lors de l'utilisation d'exploits, le projet Openwall <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=47989\">\u00e9volue<\/a><\/noindex> un module s\u00e9par\u00e9 <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lkrg\/\">LKRG<\/a><\/noindex> (Linux Kernel Runtime Guard).<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51591\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041b\u0438\u043d\u0443\u0441 \u0422\u043e\u0440\u0432\u0430\u043b\u044c\u0434\u0441 \u043f\u0440\u0438\u043d\u044f\u043b \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0431\u0443\u0434\u0443\u0449\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430 \u044f\u0434\u0440\u0430 Linux 5.4 \u043d\u0430\u0431\u043e\u0440 \u043f\u0430\u0442\u0447\u0435\u0439 &#171;lockdown&#171;, \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043d\u044b\u0439 \u0414\u044d\u0432\u0438\u0434\u043e\u043c \u0425\u043e\u0443\u044d\u043b\u043b\u0441\u043e\u043c (David Howells, \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 Red Hat) \u0438 \u041c\u044d\u0442\u044c\u044e \u0413\u0430\u0440\u0440\u0435\u0442\u043e\u043c (Matthew Garrett, \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 Google) \u0434\u043b\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root \u043a \u044f\u0434\u0440\u0443. \u0421\u0432\u044f\u0437\u0430\u043d\u043d\u0430\u044f \u0441 &#171;lockdown&#187; \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u044c \u0432\u044b\u043d\u0435\u0441\u0435\u043d\u0430 \u0432 \u043e\u043f\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c\u044b\u0439 LSM-\u043c\u043e\u0434\u0443\u043b\u044c (Linux Security Module), \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u044e\u0449\u0438\u0439 \u0431\u0430\u0440\u044c\u0435\u0440 \u043c\u0435\u0436\u0434\u0443 UID 0 \u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38554","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041b\u0438\u043d\u0443\u0441 \u0422\u043e\u0440\u0432\u0430\u043b\u044c\u0434\u0441 \u043f\u0440\u0438\u043d\u044f\u043b \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0431\u0443\u0434\u0443\u0449\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 \u044f\u0434\u0440\u043e Linux 5.4 \u043f\u0440\u0438\u043d\u044f\u0442\u044b \u043f\u0430\u0442\u0447\u0438 \u0434\u043b\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 root \u043a \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c \u044f\u0434\u0440\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041b\u0438\u043d\u0443\u0441 \u0422\u043e\u0440\u0432\u0430\u043b\u044c\u0434\u0441 \u043f\u0440\u0438\u043d\u044f\u043b \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0431\u0443\u0434\u0443\u0449\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:24:30+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:24:30+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Dans le noyau Linux 5.4, des correctifs ont \u00e9t\u00e9 accept\u00e9s pour limiter l'acc\u00e8s root aux entrailles du noyau | ProHoster","description":"Linus Torvalds a int\u00e9gr\u00e9 dans la future version.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 \u044f\u0434\u0440\u043e Linux 5.4 \u043f\u0440\u0438\u043d\u044f\u0442\u044b \u043f\u0430\u0442\u0447\u0438 \u0434\u043b\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 root \u043a \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c \u044f\u0434\u0440\u0430 | ProHoster","og:description":"\u041b\u0438\u043d\u0443\u0441 \u0422\u043e\u0440\u0432\u0430\u043b\u044c\u0434\u0441 \u043f\u0440\u0438\u043d\u044f\u043b \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0431\u0443\u0434\u0443\u0449\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:24:30+00:00","article:modified_time":"2019-10-31T19:24:30+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38554","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 22:31:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:07:39","updated":"2026-01-23 22:31:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/38554","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=38554"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/38554\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=38554"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=38554"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=38554"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}