{"id":53560,"date":"2019-12-04T00:00:00","date_gmt":"2019-12-03T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/15-uyazvimostej-v-usb-drajverah-postavlyaemyh-v-yadre-linux"},"modified":"2020-02-18T14:01:28","modified_gmt":"2020-02-18T11:01:28","slug":"15-uyazvimostej-v-usb-drajverah-postavlyaemyh-v-yadre-linux","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/15-uyazvimostej-v-usb-drajverah-postavlyaemyh-v-yadre-linux","title":{"rendered":"15 vuln\u00e9rabilit\u00e9s dans les pilotes USB fournis dans le noyau Linux","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/xairy\">Andrey Konovalov<\/a><\/noindex> de la soci\u00e9t\u00e9 Google  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/12\/03\/4\">a publi\u00e9<\/a><\/noindex> rapport sur la d\u00e9tection de 15 vuln\u00e9rabilit\u00e9s (CVE-2019-19523 \u2014 CVE-2019-19537) dans les pilotes USB propos\u00e9s dans le noyau Linux. Il s'agit du troisi\u00e8me lot de probl\u00e8mes d\u00e9tect\u00e9s lors des tests de fuzzing de la pile USB dans le paquet. <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/google\/syzkaller\/blob\/master\/docs\/linux\/external_fuzzing_usb.md\">syzkaller<\/a><\/noindex> \u2014 ce chercheur pr\u00e9c\u00e9demment nomm\u00e9 <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=47523\">d\u00e9j\u00e0<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51333\">rapportait<\/a><\/noindex> signal\u00e9 la pr\u00e9sence de 29 vuln\u00e9rabilit\u00e9s. <\/p>\n<p>Cette fois, la liste ne comprend que les vuln\u00e9rabilit\u00e9s provoqu\u00e9es par l'acc\u00e8s \u00e0 des zones de m\u00e9moire d\u00e9j\u00e0 lib\u00e9r\u00e9es (use-after-free) ou entra\u00eenant des fuites de donn\u00e9es de la m\u00e9moire du noyau. Les probl\u00e8mes pouvant \u00eatre exploit\u00e9s pour un d\u00e9ni de service ne sont pas inclus dans le rapport. Les vuln\u00e9rabilit\u00e9s peuvent potentiellement \u00eatre exploit\u00e9es lors de la connexion de p\u00e9riph\u00e9riques USB sp\u00e9cialement pr\u00e9par\u00e9s \u00e0 un ordinateur. Les correctifs pour tous les probl\u00e8mes mentionn\u00e9s dans le rapport ont d\u00e9j\u00e0 \u00e9t\u00e9 int\u00e9gr\u00e9s dans le noyau, mais certains qui ne figurent pas dans le rapport <noindex><a rel=\"nofollow\" href=\"https:\/\/syzkaller.appspot.com\/upstream?manager=ci2-upstream-usb\">l'erreur<\/a><\/noindex> restent non corrig\u00e9s.<\/p>\n<p>Les vuln\u00e9rabilit\u00e9s les plus critiques de type \u00ab use-after-free \u00bb, qui peuvent entra\u00eener l'ex\u00e9cution de code malveillant, ont \u00e9t\u00e9 corrig\u00e9es dans les pilotes adutux, ff-memless, ieee802154, pn533, hiddev, iowarrior, mcba_usb et yurex. Sous CVE-2019-19532, 14 vuln\u00e9rabilit\u00e9s suppl\u00e9mentaires ont \u00e9t\u00e9 recens\u00e9es dans les pilotes HID, caus\u00e9es par des erreurs permettant des \u00e9critures hors limites (out-of-bounds write). Des probl\u00e8mes permettant des fuites de donn\u00e9es de la m\u00e9moire du noyau ont \u00e9t\u00e9 identifi\u00e9s dans les pilotes ttusb_dec, pcan_usb_fd et pcan_usb_pro. Dans le code de la pile USB pour le travail avec des p\u00e9riph\u00e9riques de caract\u00e8res, un probl\u00e8me a \u00e9t\u00e9 d\u00e9tect\u00e9 (CVE-2019-19537), caus\u00e9 par une condition de course (race condition).<\/p>\n<p>On peut \u00e9galement noter<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/11\/22\/1\">d\u00e9tection<\/a><\/noindex> quatre vuln\u00e9rabilit\u00e9s (CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901) dans le pilote pour les puces sans fil Marvell, qui peuvent entra\u00eener un d\u00e9passement de tampon. Une attaque peut \u00eatre men\u00e9e \u00e0 distance par l'envoi de trames sp\u00e9cifiquement format\u00e9es lors de la connexion \u00e0 un point d'acc\u00e8s sans fil contr\u00f4l\u00e9 par un attaquant. La menace la plus probable est le d\u00e9ni de service \u00e0 distance (plantage du noyau), mais la possibilit\u00e9 d'ex\u00e9cution de code dans le syst\u00e8me ne peut pas \u00eatre exclue.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51974\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0410\u043d\u0434\u0440\u0435\u0439 \u041a\u043e\u043d\u043e\u0432\u0430\u043b\u043e\u0432 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Google \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b \u043e\u0442\u0447\u0451\u0442 \u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0438 \u043e\u0447\u0435\u0440\u0435\u0434\u043d\u044b\u0445 15 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 (CVE-2019-19523 &#8212; CVE-2019-19537) \u0432 USB-\u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430\u0445, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u0435\u043c\u044b\u0445 \u0432 \u044f\u0434\u0440\u0435 Linux. \u042d\u0442\u043e \u0442\u0440\u0435\u0442\u044c\u044f \u043f\u043e\u0440\u0446\u0438\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c, \u043d\u0430\u0439\u0434\u0435\u043d\u043d\u044b\u0445 \u043f\u0440\u0438 \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0438 fuzzing-\u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f USB-\u0441\u0442\u0435\u043a\u0430 \u0432 \u043f\u0430\u043a\u0435\u0442\u0435 syzkaller &#8212; \u0440\u0430\u043d\u0435\u0435 \u0434\u0430\u043d\u043d\u044b\u0439 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0443\u0436\u0435 \u0441\u043e\u043e\u0431\u0449\u0430\u043b \u043e \u043d\u0430\u043b\u0438\u0447\u0438\u0438 29 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439. \u041d\u0430 \u044d\u0442\u043e\u0442 \u0440\u0430\u0437 \u0432 \u0441\u043f\u0438\u0441\u043a\u0435 \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u044b \u0442\u043e\u043b\u044c\u043a\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0432\u044b\u0437\u0432\u0430\u043d\u043d\u044b\u0435 \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0435\u043c \u043a \u0443\u0436\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-53560","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0410\u043d\u0434\u0440\u0435\u0439 \u041a\u043e\u043d\u043e\u0432\u0430\u043b\u043e\u0432 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Google\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/15-uyazvimostej-v-usb-drajverah-postavlyaemyh-v-yadre-linux\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd4715 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 USB-\u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430\u0445, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u044b\u0445 \u0432 \u044f\u0434\u0440\u0435 Linux | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0410\u043d\u0434\u0440\u0435\u0439 \u041a\u043e\u043d\u043e\u0432\u0430\u043b\u043e\u0432 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Google\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/15-uyazvimostej-v-usb-drajverah-postavlyaemyh-v-yadre-linux\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-12-03T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:01:28+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 15 vuln\u00e9rabilit\u00e9s dans les pilotes USB fournis dans le noyau Linux | ProHoster","description":"Andrey Konovalov de la soci\u00e9t\u00e9 Google","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/15-uyazvimostej-v-usb-drajverah-postavlyaemyh-v-yadre-linux","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd4715 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 USB-\u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430\u0445, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u044b\u0445 \u0432 \u044f\u0434\u0440\u0435 Linux | ProHoster","og:description":"\u0410\u043d\u0434\u0440\u0435\u0439 \u041a\u043e\u043d\u043e\u0432\u0430\u043b\u043e\u0432 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Google","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/15-uyazvimostej-v-usb-drajverah-postavlyaemyh-v-yadre-linux","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-12-03T21:00:00+00:00","article:modified_time":"2020-02-18T11:01:28+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"53560","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 07:52:14","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 15:20:02","updated":"2026-01-24 07:52:14","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/53560","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=53560"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/53560\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=53560"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=53560"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=53560"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}