Rashin lahani a cikin OpenZFS wanda ke karya ikon samun dama a cikin FreeBSD

В kara da cewa в OpenZFS An gano lambar don tallafawa FreeBSD OS mai mahimmanci rauni (CVE-2020-24717), yana haifar da cin zarafi na sarrafa haƙƙin samun dama. Babban matsalar ita ce haƙƙoƙin da aka ɗora wa ƙungiyar an ɗauke su a matsayin haƙƙin mai fayil ɗin. Matsala shafe a cikin sabuntawa Buɗe ZFS 2.0.0-rc1. Gyara gabatar to fassarar FreeBSD HEAD codebase akan OpenZFS.

Matsalar ta samo asali ne daga duk abubuwan da aka saita na masu mallakar rukuni (rukuni @) da kuma ƙungiyoyi na yau da kullun (rukuni:<name>) ana wakilta ga mai amfani na yanzu.
Misali, yanayin samun damar 0770 (rubuta izini ga membobin rukuni kawai) ana ɗaukarsa azaman 0777 (rubuta izini ga duk masu amfani). An lura da irin wannan yanayin tare da ACLs, alal misali, ACL da ke ƙasa ya zama daidai da haƙƙoƙin 0777, tun lokacin da memba na ƙungiyar ya sake dawowa da gaske.

# mai: tushe
# group: dabaran
group:builtin_administrators:rwxpDdaARWcCos:——-: yarda

Hakanan a cikin tashar tashar OpenZFS don FreeBSD, an gano wata matsala tare da ba da haƙƙoƙin adireshi (cd), ba tare da la'akari da yanayin tutar haƙƙin haƙƙin kundayen adireshi ba. Shigar da kundin adireshi yana yiwuwa, gami da haramtacciyar hanya ta hanyar ACL ("ƙi - aiwatarwa")

source: budenet.ru

Add a comment