{"id":39040,"date":"2019-10-31T22:27:31","date_gmt":"2019-10-31T19:27:31","guid":{"rendered":"https:\/\/prohoster.info\/blog\/udalyonno-ekspluatiruemaya-uyazvimost-v-linux-drajvere-dlya-chipov-realtek\/"},"modified":"2019-10-31T22:27:31","modified_gmt":"2019-10-31T19:27:31","slug":"udalyonno-ekspluatiruemaya-uyazvimost-v-linux-drajvere-dlya-chipov-realtek","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-linux-drajvere-dlya-chipov-realtek","title":{"rendered":"Vuln\u00e9rabilit\u00e9 exploit\u00e9e \u00e0 distance dans le pilote Linux pour les puces Realtek","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Dans le pilote int\u00e9gr\u00e9 au noyau Linux <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/torvalds\/linux\/tree\/master\/drivers\/net\/wireless\/realtek\/rtlwifi\">rtlwifi<\/a><\/noindex> pour les adaptateurs sans fil bas\u00e9s sur des puces Realtek <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/nicowaisman\/status\/1184864519316758535\">une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 identifi\u00e9e<\/a><\/noindex> une vuln\u00e9rabilit\u00e9 (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-17666\">CVE-2019-17666<\/a><\/noindex>), qui peut potentiellement \u00eatre exploit\u00e9e pour ex\u00e9cuter du code dans le contexte du noyau lors de l'envoi de trames sp\u00e9cialement con\u00e7ues.<\/p>\n<p>La vuln\u00e9rabilit\u00e9 est caus\u00e9e par un d\u00e9passement de tampon dans le code impl\u00e9mentant le mode P2P (Wifi-Direct). Lors de l'analyse des trames <noindex><a rel=\"nofollow\" href=\"https:\/\/hsc.com\/DesktopModules\/DigArticle\/Print.aspx?PortalId=0&#038;ModuleId=1215&#038;Article=221\">NoA<\/a><\/noindex> (Notice of Absence) ne v\u00e9rifie pas la taille d'une des valeurs, ce qui permet d'\u00e9crire des donn\u00e9es au-del\u00e0 de la limite du tampon et d'\u00e9craser les informations dans les structures du noyau situ\u00e9es apr\u00e8s le tampon.<\/p>\n<p>Une attaque peut \u00eatre r\u00e9alis\u00e9e en envoyant des trames sp\u00e9cialement con\u00e7ues \u00e0 un syst\u00e8me disposant d'un adaptateur r\u00e9seau actif bas\u00e9 sur une puce Realtek supportant la technologie <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/Wi-Fi_Direct\">Wi-Fi Direct<\/a><\/noindex>, permettant \u00e0 deux adaptateurs sans fil d'\u00e9tablir une connexion directement sans point d'acc\u00e8s. Pour exploiter le probl\u00e8me, aucune connexion au r\u00e9seau sans fil de l'attaquant n'est requise, et aucune action de la part de l'utilisateur n'est n\u00e9cessaire, il suffit que l'attaquant soit dans la port\u00e9e du signal sans fil. <\/p>\n<p>Le prototype de l'exploit se limite pour l'instant \u00e0 un appel \u00e0 distance faisant planter le noyau, mais la vuln\u00e9rabilit\u00e9 ne exclut pas potentiellement la possibilit\u00e9 d'ex\u00e9cuter du code (pour l'instant cette hypoth\u00e8se n'est que th\u00e9orique, car il n'existe pas encore de prototype d'exploit permettant l'ex\u00e9cution de code, mais le chercheur ayant d\u00e9tect\u00e9 le probl\u00e8me travaille d\u00e9j\u00e0 <noindex><a rel=\"nofollow\" href=\"https:\/\/arstechnica.com\/information-technology\/2019\/10\/unpatched-linux-flaw-may-let-attackers-crash-or-compromise-nearby-devices\/\">sur<\/a><\/noindex> \u00e0 sa cr\u00e9ation).<\/p>\n<p>Le probl\u00e8me se manifeste \u00e0 partir du noyau <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=38331\">3.12<\/a><\/noindex> (selon d'autres sources, le probl\u00e8me se manifeste \u00e0 partir du noyau <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=37315\">3.10<\/a><\/noindex>), sorti en 2013. Le correctif n'est pour l'instant disponible que sous forme de <noindex><a rel=\"nofollow\" href=\"https:\/\/lkml.org\/lkml\/2019\/10\/16\/1226\">d'un correctif<\/a><\/noindex>. Dans les distributions, le probl\u00e8me reste non corrig\u00e9.<br \/>\nOn peut suivre la r\u00e9solution des vuln\u00e9rabilit\u00e9s dans les distributions sur ces pages : <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-17666\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.suse.com\/security\/cve\/CVE-2019-17666\/\">SUSE\/openSUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2019-17666\">RHEL<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-17666.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/security.archlinux.org\/CVE-2019-17666\">Arch Linux<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?releases=F30&#038;type=security\">Fedora<\/a><\/noindex>. Il est probable que la vuln\u00e9rabilit\u00e9 touche \u00e9galement <noindex><a rel=\"nofollow\" href=\"https:\/\/android.googlesource.com\/kernel\/tegra\/+\/refs\/tags\/android-8.1.0_r0.135\/drivers\/net\/wireless\/rtlwifi\/ps.c#750\">touche<\/a><\/noindex> la plateforme Android.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51700\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 rtlwifi \u0434\u043b\u044f \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0430\u0434\u0430\u043f\u0442\u0435\u0440\u043e\u0432 \u043d\u0430 \u0447\u0438\u043f\u0430\u0445 Realtek \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-17666), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u0432 \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442\u0435 \u044f\u0434\u0440\u0430 \u043f\u0440\u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u043a\u0430\u0434\u0440\u043e\u0432. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435\u043c \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 \u043a\u043e\u0434\u0435 \u0441 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0435\u0439 \u0440\u0435\u0436\u0438\u043c\u0430 P2P (Wifi-Direct). \u041f\u0440\u0438 \u0440\u0430\u0437\u0431\u043e\u0440\u0435 \u043a\u0430\u0434\u0440\u043e\u0432 NoA (Notice of Absence) \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u0440\u0430\u0437\u043c\u0435\u0440\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-39040","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 rtlwifi \u0434\u043b\u044f \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0430\u0434\u0430\u043f\u0442\u0435\u0440\u043e\u0432 \u043d\u0430 \u0447\u0438\u043f\u0430\u0445.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-linux-drajvere-dlya-chipov-realtek\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Linux-\u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 \u0434\u043b\u044f \u0447\u0438\u043f\u043e\u0432 Realtek | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 rtlwifi \u0434\u043b\u044f \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0430\u0434\u0430\u043f\u0442\u0435\u0440\u043e\u0432 \u043d\u0430 \u0447\u0438\u043f\u0430\u0445.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-linux-drajvere-dlya-chipov-realtek\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:27:31+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:27:31+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vuln\u00e9rabilit\u00e9 exploit\u00e9e \u00e0 distance dans le pilote Linux pour les puces Realtek | ProHoster","description":"Dans le pilote int\u00e9gr\u00e9 au noyau Linux rtlwifi pour les adaptateurs sans fil bas\u00e9s sur des puces.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-linux-drajvere-dlya-chipov-realtek","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Linux-\u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 \u0434\u043b\u044f \u0447\u0438\u043f\u043e\u0432 Realtek | ProHoster","og:description":"\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u044f\u0434\u0440\u0430 Linux \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 rtlwifi \u0434\u043b\u044f \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0430\u0434\u0430\u043f\u0442\u0435\u0440\u043e\u0432 \u043d\u0430 \u0447\u0438\u043f\u0430\u0445.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-linux-drajvere-dlya-chipov-realtek","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:27:31+00:00","article:modified_time":"2019-10-31T19:27:31+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"39040","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 00:30:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 00:58:37","updated":"2026-01-24 00:30:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/39040","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=39040"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/39040\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=39040"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=39040"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=39040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}