Ọdịmma DoS dịpụrụ adịpụ na ngwugwu FreeBSD IPV6

Na FreeBSD kpochapuru adịghị ike (CVE-2019-5611) nke na-enye gị ohere ịkpata mkpọka kernel (ngwugwu-ọnwụ) site na izipu ngwugwu ICMPv6 MLD ekewapụrụ ekewasị (Nchọpụta Multicast Listener). Nsogbu kpatara enweghị nlele nlele dị mkpa na oku m_pulldown(), nke nwere ike ibute mbufs na-abụghị nke na-aga n'ihu na-eweghachite, megidere atụmanya onye ọkpụkpọ ahụ.

Mgbanwe kpochapuru na mmelite 12.0-RELEASE-p10, 11.3-RELEASE-p3 na 11.2-RELEASE-p14. Dịka nchekwa nchekwa, ị nwere ike gbanyụọ nkwado nkewa maka IPv6 ma ọ bụ nzacha nhọrọ nkụnye eji isi mee na firewall. HBH (Hop-by-Hop). N'ụzọ na-akpali mmasị, achọpụtara ahụhụ ahụ na-eduga na adịghị ike ahụ na 2006 wee dozie ya na OpenBSD, NetBSD na macOS, mana ọ nọgidere na-edozighị na FreeBSD, n'agbanyeghị na a gwara ndị mmepe FreeBSD maka nsogbu ahụ.

Ị nwekwara ike ịhụ na mkpochapụ abụọ ọzọ adịghị ike na FreeBSD:

  • CVE-2019-5603 - njupụta nke counter ntụaka maka ihe owuwu data na mqueuefs mgbe ị na-eji ọba akwụkwọ 32-bit na gburugburu 64-bit (32-bit compat). Nsogbu a na-egosipụta onwe ya mgbe ọ na-enyere mqueuefs aka, nke na-adịghị arụ ọrụ na ndabara, ma nwee ike iduga ịnweta faịlụ, akwụkwọ ndekọ aha na oghere meghere site na usoro nke ndị ọrụ ndị ọzọ, ma ọ bụ ịnweta faịlụ mpụga site na gburugburu ụlọ mkpọrọ. Ọ bụrụ na onye ọrụ ahụ nwere mgbọrọgwụ ịbanye n'ụlọ mkpọrọ, adịghị ike na-enye ohere ịnweta mgbọrọgwụ n'akụkụ ebe obibi ndị ọbịa.
  • CVE-2019-5612 - nsogbu na ịnweta multi-threaded na ngwaọrụ / dev / midistat mgbe ọnọdụ agbụrụ na-eme nwere ike iduga na-agụ ebe nchekwa kernel n'èzí ókèala nke ihe nchekwa ekenyela maka midistat. Na sistemu 32-bit, mbọ iji mee ihe adịghị ike na-eduga na mkpọka kernel, na sistemụ 64-bit ọ na-enye mmadụ ohere ịchọpụta ọdịnaya nke ebe nchekwa kernel aka ike.

isi: opennet.ru

Tinye a comment