ืคื’ื™ืขื•ืช ืฉืœ 0 ื™ืžื™ื ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ ืฉืœ n_gsm, ื”ืžืืคืฉืจืช ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืจืžืช ืœื™ื‘ืช ืœื™ื ื•ืงืก

ืฉื ื™ ื ื™ืฆื•ืœื™ื ื”ืชื’ืœื• ื‘ืจืฉื•ืช ื”ืฆื™ื‘ื•ืจ ื”ื›ื•ืœืœื™ื ืคื’ื™ืขื•ืช ืฉืœื ื”ื™ื™ืชื” ื™ื“ื•ืขื” ื‘ืขื‘ืจ ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ ืฉืœ n_gsm, ืฉื”ื•ื ื—ืœืง ืžืœื™ื‘ืช ืœื™ื ื•ืงืก. ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœืœื ื”ืจืฉืื•ืช ืœื‘ืฆืข ืงื•ื“ ื‘ืจืžืช ื”ืงืจื ืœ ื•ืœื”ืกืœื™ื ืืช ื”ื”ืจืฉืื•ืช ืฉืœื• ื‘ืžืขืจื›ืช. ืœื ื”ื•ืงืฆื” ืžื–ื”ื” CVE. ื”ื‘ืขื™ื” ื ื•ืชืจื” ืœื ืžืชื•ืงื ืช ืœืขืช ืขืชื”.

ืžื ื”ืœ ื”ื”ืชืงืŸ n_gsm ืžืกืคืง ื™ื™ืฉื•ื ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ GSM 07.10, ื”ืžืฉืžืฉ ื‘ืžื•ื“ืžื™ GSM ืœืจื™ื‘ื•ื™ ื—ื™ื‘ื•ืจื™ื ืœื™ืฆื™ืื” ื”ื˜ื•ืจื™ืช. ื”ืคื’ื™ืขื•ืช ื ื•ื‘ืขืช ืžืžืฆื‘ ืžื™ืจื•ืฅ ื‘ืžื˜ืคืœ GSMIOC_SETCONF_DLCI ื‘-ioctl ื”ืžืฉืžืฉ ืœืขื“ื›ื•ืŸ ืชืฆื•ืจืช ื”-Data Link Connection Identifier (DLCI). ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื•ืช ืขื ioctl, ืืชื” ื™ื›ื•ืœ ืœื”ืฉื™ื’ ื’ื™ืฉื” ืœื–ื™ื›ืจื•ืŸ ืœืื—ืจ ืฉื”ื•ื ืžืฉื•ื—ืจืจ (ืฉื™ืžื•ืฉ-ืื—ืจ-ื—ื•ืคืฉื™).

ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘-exploit ื‘ืžืขืจื›ื•ืช ืขื ืœื™ื‘ื•ืช ืœื™ื ื•ืงืก ืž-5.15 ืขื“ 6.5. ืœื“ื•ื’ืžื”, ื’ื™ืฉืช ืฉื•ืจืฉ ืžื•ืฆืœื—ืช ื”ื•ื›ื—ื” ื‘-Fedora, ืื•ื‘ื•ื ื˜ื• 22.04 ืขื ืœื™ื‘ืช 6.5, ื•ื“ื‘ื™ืืŸ 12 ืขื ืœื™ื‘ืช 6.1. ื”ื—ืœ ืžื’ืจืขื™ืŸ 6.6, ื ื“ืจืฉื•ืช ื”ืจืฉืื•ืช CAP_NET_ADMIN ืœืคืขื•ืœื”. ื›ืคืชืจื•ืŸ ืขื•ืงืฃ ืœื—ืกื™ืžืช ื”ืคื’ื™ืขื•ืช, ืืชื” ื™ื›ื•ืœ ืœืžื ื•ืข ื˜ืขื™ื ื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ืžื•ื“ื•ืœ ืœื™ื‘ืช n_gsm ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ื”ืฉื•ืจื” "blacklist n_gsm" ืœืงื•ื‘ืฅ /etc/modprobe.d/blacklist.conf.

ืจืื•ื™ ืœืฆื™ื™ืŸ ื›ื™ ื‘ื™ื ื•ืืจ ื ื—ืฉืฃ ืžื™ื“ืข ืขืœ ื ืงื•ื“ืช ืชื•ืจืคื” ื ื•ืกืคืช (CVE-2023-6546) ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ ืฉืœ n_gsm, ืฉืขื‘ื•ืจื” ื’ื ื ื™ืฆื•ืœ ื–ืžื™ืŸ ืœืฆื™ื‘ื•ืจ. ืคื’ื™ืขื•ืช ื–ื• ืื™ื ื” ื—ื•ืคืคืช ืœื‘ืขื™ื” ื”ืจืืฉื•ื ื”, ืื ื›ื™ ื”ื™ื ื ื’ืจืžืช ื’ื ืขืœ ื™ื“ื™ ื’ื™ืฉื” ืœื–ื™ื›ืจื•ืŸ ืœืื—ืจ ื—ื•ืคืฉ ื‘ืขื‘ื•ื“ื” ืขื ืžื‘ื ื” gsm_dlci, ืืœื ื‘ืžื˜ืคืœ GSMIOC_SETCONF ioctl. ื”ื‘ืขื™ื” ืชื•ืงื ื” ื‘ืื•ื’ื•ืกื˜ ื‘ืฉื ื” ืฉืขื‘ืจื” (ื”ืชื™ืงื•ืŸ ื ื›ืœืœ ื‘ืงืจื ืœ 6.5).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”