adịghị ike nke na-enye gị ohere ịpụ na gburugburu QEMU dịpụrụ adịpụ

Ekpughere nkọwa adịghị ike dị oke egwu (CVE-2019-14378) na ndabara SLIRP njikwa eji na QEMU iji guzobe ọwa nkwurịta okwu n'etiti ihe nkwụnye netwọk mebere na usoro ndị ọbịa na netwọk azụ azụ n'akụkụ QEMU. Ihe iseokwu a na-emetụtakwa sistemu ike nke dabeere na KVM (na Ụdị njirimara) na Virtualbox, nke na-eji slirp backend sitere na QEMU, yana ngwa ndị na-eji nchịkọta netwọk ohere ọrụ. libSLIRP (TCP/IP emulator).

Ọdịmma ahụ na-enye ohere ka e gbuo koodu n'akụkụ sistemụ nnabata yana ikike nke usoro onye na-ahụ maka QEMU mgbe ezigara ngwugwu netwọk buru ibu nke emebere nke ọma site na sistemụ ndị ọbịa, nke chọrọ nkewa. N'ihi njehie dị na ọrụ ip_reass (), nke a na-akpọ mgbe ị na-achịkọta ngwugwu na-abata, nke mbụ nwere ike ọ gaghị adaba na ebe nchekwa ekenyela na a ga-ede ọdụ ya na ebe nchekwa n'akụkụ ihe nchekwa ahụ.

Maka ule ugbua dị ụdị arụ ọrụ nke nrigbu, nke na-enye maka ịgafe ASLR na ime koodu site na ịdegharịa ebe nchekwa nke main_loop_tlg array, gụnyere QEMUTimerList nke nwere ndị njikwa na-akpọ site na ngụ oge.
Edobelarị adịghị ike na Fedora и SUSE/mepeeSUSE, mana ọ ka na-edozighị ya Debian, Arch Linux и FreeBSD. The Ubuntu и RHEL Nsogbu a apụtaghị n'ihi na ejighi slirp. Ọdịmma ahụ ka edobeghị ya na mwepụta kacha ọhụrụ libslirp 4.0 (Ndozi ahụ dị ugbu a dị ka kwachie).

isi: opennet.ru

Tinye a comment