ืคื’ื™ืขื•ืช ื ื•ืกืคืช ื‘ืชืช ื”ืžืขืจื›ืช eBPF ื”ืžืืคืฉืจืช ืœืš ืœื”ื’ื“ื™ืœ ืืช ื”ื”ืจืฉืื•ืช ืฉืœืš

ืคื’ื™ืขื•ืช ื ื•ืกืคืช ื–ื•ื”ืชื” ื‘ืชืช ื”ืžืขืจื›ืช eBPF (ืื™ืŸ CVE), ื›ืžื• ื”ื‘ืขื™ื” ืฉืœ ืืชืžื•ืœ ื”ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœืœื ื”ืจืฉืื•ืช ืœื‘ืฆืข ืงื•ื“ ื‘ืจืžืช ืœื™ื‘ืช ืœื™ื ื•ืงืก. ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืžืื– ืœื™ื‘ืช ืœื™ื ื•ืงืก 5.8 ื•ื ืฉืืจื” ืœื ืžืชื•ืงื ืช. ื ื™ืฆื•ืœ ืขื•ื‘ื“ ืžื•ื‘ื˜ื— ืœื”ืชืคืจืกื ื‘-18 ื‘ื™ื ื•ืืจ.

ื”ืคื’ื™ืขื•ืช ื”ื—ื“ืฉื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ืื™ืžื•ืช ืฉื’ื•ื™ ืฉืœ ืชื•ื›ื ื™ื•ืช eBPF ื”ืžื•ืขื‘ืจื•ืช ืœื‘ื™ืฆื•ืข. ื‘ืžื™ื•ื—ื“, ืžืืžืช ื”-eBPF ืœื ื”ื’ื‘ื™ืœ ื›ืจืื•ื™ ื›ืžื” ืกื•ื’ื™ื ืฉืœ ืžืฆื‘ื™ืขื™ *_OR_NULL, ืžื” ืฉืื™ืคืฉืจ ืœืชืžืจืŸ ืžืฆื‘ื™ืขื™ื ืžืชื•ื›ื ื•ืช eBPF ื•ืœื”ืฉื™ื’ ื”ื’ื“ืœืช ื”ื”ืจืฉืื•ืช ืฉืœื”ื. ื›ื“ื™ ืœื—ืกื•ื ืืช ื”ื ื™ืฆื•ืœ ืฉืœ ื”ืคื’ื™ืขื•ืช, ืžื•ืฆืข ืœืืกื•ืจ ื‘ื™ืฆื•ืข ืฉืœ ืชื•ื›ื ื™ื•ืช BPF ืขืœ ื™ื“ื™ ืžืฉืชืžืฉื™ื ืœื ืžื•ืจืฉื™ื ืขื ื”ืคืงื•ื“ื” "sysctl -w kernel.unprivileged_bpf_disabled=1".

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”