Adịghị ike na ọkwọ ụgbọala vhost-net sitere na Linux kernel

Na onye ọkwọ ụgbọ ala vhost-net, nke na-eme ka ọrụ nke virtio net na-arụ ọrụ n'akụkụ gburugburu ebe obibi, mara adịghị ike (CVE-2020-10942), na-ekwe ka onye ọrụ mpaghara bido njupụta kernel site na izipu ioctl (VHOST_NET_SET_BACKEND) ahaziri ahazi na /dev/vhost-net ngwaọrụ. Ihe kpatara nsogbu a bụ enweghị nkwado ziri ezi nke ọdịnaya nke ubi sk_family na koodu ọrụ get_raw_socket().

Dabere na data mbido, enwere ike iji adịghị ike ahụ mee mwakpo DoS mpaghara site na ịkpata okuku kernel (enweghị ozi gbasara iji oke njupụta nke nhụsianya na-ahazi nhazi koodu).
Mgbanwe kpochapuru na Linux kernel 5.5.8 update. Maka nkesa, ị nwere ike soro ntọhapụ nke mmelite ngwugwu na ibe Debian, Ubuntu, RHEL, SUSE/mepeeSUSE, Fedora, Arch.

isi: opennet.ru

Tinye a comment