Vulnerability nyob rau hauv vhost-net uas tso cai rau kev rho tawm bypass hauv systems raws li QEMU-KVM

Qhia tawm cov ntaub ntawv hais txog yooj yim (CVE-2019-14835), uas tso cai rau koj mus dhau lub kaw lus qhua hauv KVM (qemu-kvm) thiab khiav koj cov cai nyob rau sab ntawm tus tswv tsev ib puag ncig hauv cov ntsiab lus ntawm Linux kernel. Qhov tsis zoo tau raug codenamed V-gHost. Qhov teeb meem tso cai rau cov qhua tuaj yeem tsim cov xwm txheej rau qhov tsis sib xws hauv vhost-net kernel module (network backend for virtio), raug tua nyob rau sab ntawm tus tswv tsev ib puag ncig. Qhov kev tawm tsam tuaj yeem ua los ntawm tus neeg tawm tsam uas muaj cai nkag mus rau cov qhua tuaj noj mov thaum lub sijhawm ua haujlwm virtual tshuab tsiv teb tsaws.

Kho qhov teeb meem suav nrog suav nrog hauv Linux 5.3 kernel. Raws li kev daws teeb meem rau kev thaiv qhov tsis zoo, koj tuaj yeem lov tes taw nyob hauv kev tsiv teb tsaws chaw ntawm cov qhua lossis lov tes taw vhost-net module (ntxiv "blacklist vhost-net" rau /etc/modprobe.d/blacklist.conf). Qhov teeb meem tshwm sim pib los ntawm Linux ntsiav 2.6.34. Lub vulnerability tau kho nyob rau hauv Ubuntu ΠΈ Fedora, tab sis tseem tseem uncorrected nyob rau hauv Debian, Arch Linux, SUSE ΠΈ RHEL.

Tau qhov twg los: opennet.ru

Ntxiv ib saib