ืฉื—ืจื•ืจ ืฉืœ hostapd ื•-wpa_supplicant 2.10

ืœืื—ืจ ืฉื ื” ื•ื—ืฆื™ ืฉืœ ืคื™ืชื•ื—, ื”ื•ื›ื ื” ื”ื”ืคืฆื” ืฉืœ hostapd/wpa_supplicant 2.10, ืขืจื›ื” ืœืชืžื™ื›ื” ื‘ืคืจื•ื˜ื•ืงื•ืœื™ื ื”ืืœื—ื•ื˜ื™ื™ื IEEE 802.1X, WPA, WPA2, WPA3 ื•-EAP, ื”ืžื•ืจื›ื‘ืช ืžืืคืœื™ืงืฆื™ื™ืช wpa_supplicant ืœื—ื™ื‘ื•ืจ ืœืจืฉืช ืืœื—ื•ื˜ื™ืช ื›ืœืงื•ื— ื•ืชื”ืœื™ืš ื”ืจืงืข ืฉืœ hostapd ืœืกืคืง ืชืคืขื•ืœ ืฉืœ ื ืงื•ื“ืช ื”ื’ื™ืฉื” ื•ืฉืจืช ืื™ืžื•ืช, ื›ื•ืœืœ ืจื›ื™ื‘ื™ื ื›ื’ื•ืŸ WPA Authenticator, ืœืงื•ื—/ืฉืจืช ืื™ืžื•ืช RADIUS, ืฉืจืช EAP. ืงื•ื“ ื”ืžืงื•ืจ ืฉืœ ื”ืคืจื•ื™ืงื˜ ืžื•ืคืฅ ืชื—ืช ืจื™ืฉื™ื•ืŸ BSD.

ื‘ื ื•ืกืฃ ืœืฉื™ื ื•ื™ื™ื ืคื•ื ืงืฆื™ื•ื ืœื™ื™ื, ื”ื’ืจืกื” ื”ื—ื“ืฉื” ื—ื•ืกืžืช ื•ืงื˜ื•ืจ ื”ืชืงืคื” ืฆื“ื“ื™ ื—ื“ืฉ ื”ืžืฉืคื™ืข ืขืœ ืฉื™ื˜ืช ื”ืžืฉื ื•ืžืชืŸ ืฉืœ ื—ื™ื‘ื•ืจ SAE (Simultaneous Authentication of Equals) ื•ืขืœ ืคืจื•ื˜ื•ืงื•ืœ EAP-pwd. ืชื•ืงืฃ ืฉื™ืฉ ืœื• ืืช ื”ื™ื›ื•ืœืช ืœื”ืคืขื™ืœ ืงื•ื“ ืœื ืžื•ื’ืŸ ื‘ืžืขืจื›ืช ืฉืœ ืžืฉืชืžืฉ ื”ืžืชื—ื‘ืจ ืœืจืฉืช ืืœื—ื•ื˜ื™ืช ื™ื›ื•ืœ, ื‘ืืžืฆืขื•ืช ื ื™ื˜ื•ืจ ืคืขื™ืœื•ืช ื‘ืžืขืจื›ืช, ืœืงื‘ืœ ืžื™ื“ืข ืขืœ ืžืืคื™ื™ื ื™ ื”ืกื™ืกืžื” ื•ืœื”ืฉืชืžืฉ ื‘ื”ื ื›ื“ื™ ืœืคืฉื˜ ืืช ื ื™ื—ื•ืฉ ื”ืกื™ืกืžื” ื‘ืžืฆื‘ ืœื ืžืงื•ื•ืŸ. ื”ื‘ืขื™ื” ื ื’ืจืžืช ื›ืชื•ืฆืื” ืžื“ืœื™ืคืช ืžื™ื“ืข ื“ืจืš ืขืจื•ืฆื™ ืฆื“ ืฉืœื™ืฉื™ ืขืœ ืžืืคื™ื™ื ื™ ื”ืกื™ืกืžื”, ื”ืžืืคืฉืจืช, ืขืœ ืกืžืš ื ืชื•ื ื™ื ืขืงื™ืคื™ื, ื›ื’ื•ืŸ ืฉื™ื ื•ื™ื™ื ื‘ืขื™ื›ื•ื‘ื™ื ื‘ืžื”ืœืš ื”ืคืขื•ืœื•ืช, ืœื”ื‘ื”ื™ืจ ืืช ื ื›ื•ื ื•ืช ื‘ื—ื™ืจืช ื—ืœืงื™ ื”ืกื™ืกืžื” ื‘. ืชื”ืœื™ืš ื”ื‘ื—ื™ืจื” ื‘ื•.

ื‘ื ื™ื’ื•ื“ ืœื‘ืขื™ื•ืช ื“ื•ืžื•ืช ืฉืชื•ืงื ื• ื‘-2019, ื”ืคื’ื™ืขื•ืช ื”ื—ื“ืฉื” ื ื’ืจืžืช ืžื”ืขื•ื‘ื“ื” ืฉื”ืคืจื™ืžื™ื˜ื™ื‘ื™ื ื”ื”ืฆืคื ื” ื”ื—ื™ืฆื•ื ื™ื™ื ื”ืžืฉืžืฉื™ื ื‘ืคื•ื ืงืฆื™ื” crypto_ec_point_solve_y_coord() ืœื ืกื™ืคืงื• ื–ืžืŸ ื‘ื™ืฆื•ืข ืงื‘ื•ืข, ืœืœื ืงืฉืจ ืœืื•ืคื™ ื”ื ืชื•ื ื™ื ื”ืžืขื•ื‘ื“ื™ื. ื‘ื”ืชื‘ืกืก ืขืœ ื ื™ืชื•ื— ื”ื”ืชื ื”ื’ื•ืช ืฉืœ ืžื˜ืžื•ืŸ ื”ืžืขื‘ื“, ืชื•ืงืฃ ืฉื”ื™ื™ืชื” ืœื• ื™ื›ื•ืœืช ืœื”ืจื™ืฅ ืงื•ื“ ืœื ืžื•ื’ืŸ ืขืœ ืื•ืชื” ืœื™ื‘ืช ืžืขื‘ื“ ื™ื›ื•ืœ ืœืงื‘ืœ ืžื™ื“ืข ืขืœ ื”ืชืงื“ืžื•ืช ืคืขื•ืœื•ืช ื”ืกื™ืกืžื” ื‘-SAE/EAP-pwd. ื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ืขืœ ื›ืœ ื”ื’ื™ืจืกืื•ืช ืฉืœ wpa_supplicant ื•-hostapd ื”ืžื•ืจื›ื‘ื•ืช ืขื ืชืžื™ื›ื” ื‘-SAE (CONFIG_SAE=y) ื•-EAP-pwd (CONFIG_EAP_PWD=y).

ืฉื™ื ื•ื™ื™ื ื ื•ืกืคื™ื ื‘ืžื”ื“ื•ืจื•ืช ื”ื—ื“ืฉื•ืช ืฉืœ hostapd ื•-wpa_supplicant:

  • ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœื‘ื ื•ืช ืขื ืกืคืจื™ื™ืช ื”ื”ืฆืคื ื” OpenSSL 3.0.
  • ืžื ื’ื ื•ืŸ Beacon Protection ื”ืžื•ืฆืข ื‘ืขื“ื›ื•ืŸ ืžืคืจื˜ WPA3 ื™ื•ืฉื, ืฉื ื•ืขื“ ืœื”ื’ืŸ ืžืคื ื™ ื”ืชืงืคื•ืช ืืงื˜ื™ื‘ื™ื•ืช ืขืœ ื”ืจืฉืช ื”ืืœื—ื•ื˜ื™ืช ื”ืžื‘ืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื•ืช ื‘ืฉื™ื ื•ื™ื™ื ื‘ืžืกื’ืจื•ืช Beacon.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘-DPP 2 (ืคืจื•ื˜ื•ืงื•ืœ Wi-Fi Device Provisioning), ื”ืžื’ื“ื™ืจ ืืช ืฉื™ื˜ืช ืื™ืžื•ืช ื”ืžืคืชื— ื”ืฆื™ื‘ื•ืจื™ ื”ืžืฉืžืฉืช ื‘ืชืงืŸ WPA3 ืœืชืฆื•ืจื” ืคืฉื•ื˜ื” ืฉืœ โ€‹โ€‹ืžื›ืฉื™ืจื™ื ืœืœื ืžืžืฉืง ืขืœ ื”ืžืกืš. ื”ื”ื’ื“ืจื” ืžืชื‘ืฆืขืช ื‘ืืžืฆืขื•ืช ืžื›ืฉื™ืจ ืื—ืจ ืžืชืงื“ื ื™ื•ืชืจ ืฉื›ื‘ืจ ืžื—ื•ื‘ืจ ืœืจืฉืช ื”ืืœื—ื•ื˜ื™ืช. ืœื“ื•ื’ืžื”, ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ืคืจืžื˜ืจื™ื ืœืžื›ืฉื™ืจ IoT ืœืœื ืžืกืš ืžืกืžืืจื˜ืคื•ืŸ ืขืœ ืกืžืš ืชืžื•ื ืช ืžืฆื‘ ืฉืœ ืงื•ื“ QR ื”ืžื•ื“ืคืก ืขืœ ื”ืžืืจื–;
  • ื ื•ืกืคื” ืชืžื™ื›ื” ืขื‘ื•ืจ ืžื–ื”ื” ืžืคืชื— ืžื•ืจื—ื‘ (IEEE 802.11-2016).
  • ืชืžื™ื›ื” ื‘ืžื ื’ื ื•ืŸ ื”ืื‘ื˜ื—ื” SAE-PK (SAE Public Key) ื ื•ืกืคื” ืœื™ื™ืฉื•ื ืฉื™ื˜ืช ื”ืžืฉื ื•ืžืชืŸ ืขืœ ื—ื™ื‘ื•ืจ SAE. ืžื™ื•ืฉื ืžืฆื‘ ืœืฉืœื™ื—ืช ืื™ืฉื•ืจ ืžื™ื™ื“ื™, ื”ืžื•ืคืขืœ ืขืœ ื™ื“ื™ ื”ืืคืฉืจื•ืช "sae_config_immediate=1", ื›ืžื• ื’ื ืžื ื’ื ื•ืŸ hash-to-element, ื”ืžื•ืคืขืœ ื›ืืฉืจ ื”ืคืจืžื˜ืจ sae_pwe ืžื•ื’ื“ืจ ืœ-1 ืื• 2.
  • ื”ื˜ืžืขืช EAP-TLS ื”ื•ืกื™ืคื” ืชืžื™ื›ื” ืขื‘ื•ืจ TLS 1.3 (ืžื•ืฉื‘ืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ).
  • ื ื•ืกืคื• ื”ื’ื“ืจื•ืช ื—ื“ืฉื•ืช (max_auth_rounds, max_auth_rounds_short) ื›ื“ื™ ืœืฉื ื•ืช ืืช ื”ืžื’ื‘ืœื•ืช ืขืœ ืžืกืคืจ ื”ื•ื“ืขื•ืช EAP ื‘ืžื”ืœืš ืชื”ืœื™ืš ื”ืื™ืžื•ืช (ื™ื™ืชื›ืŸ ืฉื™ื™ื“ืจืฉื• ืฉื™ื ื•ื™ื™ื ื‘ืžื’ื‘ืœื•ืช ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืชืขื•ื“ื•ืช ื’ื“ื•ืœื•ืช ืžืื•ื“).
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืžื ื’ื ื•ืŸ PASN (Pre Association Security Negotiation) ืœื™ืฆื™ืจืช ื—ื™ื‘ื•ืจ ืžืื•ื‘ื˜ื— ื•ื”ื’ื ื” ืขืœ ื—ื™ืœื•ืคื™ ืžืกื’ืจื•ืช ื‘ืงืจื” ื‘ืฉืœื‘ ื—ื™ื‘ื•ืจ ืžื•ืงื“ื ื™ื•ืชืจ.
  • ื”ื•ื˜ืžืข ืžื ื’ื ื•ืŸ Transition Disable, ื”ืžืืคืฉืจ ืœืš ืœื‘ื˜ืœ ืื•ื˜ื•ืžื˜ื™ืช ืืช ืžืฆื‘ ื”ื ื“ื™ื“ื”, ื”ืžืืคืฉืจ ืœืš ืœืขื‘ื•ืจ ื‘ื™ืŸ ื ืงื•ื“ื•ืช ื’ื™ืฉื” ืชื•ืš ื›ื“ื™ ืชื ื•ืขื”, ื›ื“ื™ ืœืฉืคืจ ืืช ื”ืื‘ื˜ื—ื”.
  • ืชืžื™ื›ื” ื‘ืคืจื•ื˜ื•ืงื•ืœ WEP ืื™ื ื” ื ื›ืœืœืช ื‘ื‘ื ื™ื™ืช ื‘ืจื™ืจืช ืžื—ื“ืœ (ื‘ื ื™ื™ื” ืžื—ื“ืฉ ืขื ื”ืืคืฉืจื•ืช CONFIG_WEP=y ื ื“ืจืฉืช ื›ื“ื™ ืœื”ื—ื–ื™ืจ ืชืžื™ื›ื” ื‘-WEP). ื”ื•ืกืจื” ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืžื“ื•ืจ ืงื•ื“ื ื”ืงืฉื•ืจื” ืœ-Inter-Access Point Protocol (IAPP). ื”ืชืžื™ื›ื” ื‘-libnl 1.1 ื”ื•ืคืกืงื”. ื ื•ืกืคื” ืืคืฉืจื•ืช ื‘ื ื™ื™ื” CONFIG_NO_TKIP=y ืขื‘ื•ืจ ื‘ื ื™ื™ื” ืœืœื ืชืžื™ื›ื” ื‘-TKIP.
  • ืชื™ืงื•ืŸ ืคื’ื™ืขื•ื™ื•ืช ื‘ื™ื™ืฉื•ื UPnP (CVE-2020-12695), ื‘ืžื˜ืคืœ P2P/Wi-Fi Direct (CVE-2021-27803) ื•ื‘ืžื ื’ื ื•ืŸ ื”ื”ื’ื ื” ืฉืœ PMF (CVE-2019-16275).
  • ืฉื™ื ื•ื™ื™ื ืกืคืฆื™ืคื™ื™ื ืœ-Hostapd ื›ื•ืœืœื™ื ืชืžื™ื›ื” ืžื•ืจื—ื‘ืช ืขื‘ื•ืจ ืจืฉืชื•ืช ืืœื—ื•ื˜ื™ื•ืช ืฉืœ HEW (High-Efficiency Wireless, IEEE 802.11ax), ื›ื•ืœืœ ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ื˜ื•ื•ื— ื”ืชื“ืจื™ื ืฉืœ 6 GHz.
  • ืฉื™ื ื•ื™ื™ื ืกืคืฆื™ืคื™ื™ื ืœ-wpa_supplicant:
    • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ื”ื’ื“ืจื•ืช ืžืฆื‘ ื ืงื•ื“ืช ื’ื™ืฉื” ืขื‘ื•ืจ SAE (WPA3-Personal).
    • ืชืžื™ื›ื” ื‘ืžืฆื‘ P802.11P ืžื™ื•ืฉืžืช ืขื‘ื•ืจ ืขืจื•ืฆื™ EDMG (IEEE 2ay).
    • ื—ื™ื–ื•ื™ ืชืคื•ืงื” ืžืฉื•ืคืจื™ื ื•ื‘ื—ื™ืจืช BSS.
    • ืžืžืฉืง ื”ื‘ืงืจื” ื‘ืืžืฆืขื•ืช D-Bus ื”ื•ืจื—ื‘.
    • ืงืฆื” ืื—ื•ืจื™ ื—ื“ืฉ ื ื•ืกืฃ ืœืื—ืกื•ืŸ ืกื™ืกืžืื•ืช ื‘ืงื•ื‘ืฅ ื ืคืจื“, ื”ืžืืคืฉืจ ืœืš ืœื”ืกื™ืจ ืžื™ื“ืข ืจื’ื™ืฉ ืžืงื•ื‘ืฅ ื”ืชืฆื•ืจื” ื”ืจืืฉื™.
    • ื ื•ืกืคื• ืžื“ื™ื ื™ื•ืช ื—ื“ืฉื” ืขื‘ื•ืจ SCS, MSCS ื•-DSCP.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”