10 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-Xen hypervisor

ื™ืฆื ืœืื•ืจ ืžื™ื“ืข ืขืœ 10 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-Xen hypervisor, ืžืชื•ื›ืŸ ื—ืžืฉ (CVE-2019-17341, CVE-2019-17342, CVE-2019-17340, CVE-2019-17346, CVE-2019-17343) ืขืฉื•ื™ ืœืืคืฉืจ ืœืš ืœืฆืืช ืžืกื‘ื™ื‘ืช ื”ืื•ืจื—ื™ื ื”ื ื•ื›ื—ื™ืช ื•ืœื”ืขืœื•ืช ืืช ื”ื”ืจืฉืื•ืช ืฉืœืš, ืคื’ื™ืขื•ืช ืื—ืช (CVE-2019-17347) ืžืืคืฉืจืช ืœืชื”ืœื™ืš ื—ืกืจ ื”ืจืฉืื•ืช ืœื”ืฉื™ื’ ืฉืœื™ื˜ื” ืขืœ ืชื”ืœื™ื›ื™ื ืฉืœ ืžืฉืชืžืฉื™ื ืื—ืจื™ื ื‘ืื•ืชื” ืžืขืจื›ืช ืื•ืจื—ืช, ืืจื‘ืข ื”ื ื•ืชืจื•ืช (CVE-2019 -17344, CVE- 2019-17345, CVE-2019-17348, CVE-2019-17351) ืคื’ื™ืขื•ื™ื•ืช ืขืœื•ืœื•ืช ืœื’ืจื•ื ืœืžื ื™ืขืช ืฉื™ืจื•ืช (ืงืจื™ืกืช ืกื‘ื™ื‘ืช ืžืืจื—). ื‘ืขื™ื•ืช ืฉืชื•ืงื ื• ื‘ืžื”ื“ื•ืจื•ืช Xen 4.12.1, 4.11.2 ื•-4.10.4.

  • CVE-2019-17341 - ื”ื™ื›ื•ืœืช ืœืงื‘ืœ ื’ื™ืฉื” ื‘ืจืžืช ื”ื”ื™ืคืจื•ื•ื™ื–ืจ ืžืžืขืจื›ืช ืื•ืจื— ื”ื ืฉืœื˜ืช ืขืœ ื™ื“ื™ ื”ืชื•ืงืฃ. ื”ื‘ืขื™ื” ืžืชืจื—ืฉืช ืจืง ื‘ืžืขืจื›ื•ืช x86 ื•ื”ื™ื ื™ื›ื•ืœื” ืœื”ื™ื•ืช ืžื—ื•ื™ื‘ืช ืžืื•ืจื—ื™ื ื”ืคื•ืขืœื™ื ื‘ืžืฆื‘ paravirtualization (PV) ืขืœ ื™ื“ื™ ื“ื—ื™ืคื” ืฉืœ ื”ืชืงืŸ PCI ื—ื“ืฉ ืœืื•ืจื— ืคื•ืขืœ. ืื•ืจื—ื™ื ื”ืคื•ืขืœื™ื ื‘ืžืฆื‘ื™ HVM ื•-PVH ืื™ื ื ืžื•ืฉืคืขื™ื;
  • CVE-2019-17340 - ื“ืœื™ืคืช ื–ื™ื›ืจื•ืŸ, ืขืœื•ืœื” ืœืืคืฉืจ ืœืš ืœื”ืขืœื•ืช ืืช ื”ื”ืจืฉืื•ืช ืฉืœืš ืื• ืœื’ืฉืช ืœื ืชื•ื ื™ื ืžืžืขืจื›ื•ืช ืื•ืจื—ื•ืช ืื—ืจื•ืช.
    ื”ื‘ืขื™ื” ืžืชืจื—ืฉืช ืจืง ื‘ืžืืจื—ื™ื ืขื ื™ื•ืชืจ ืž-16TB ืฉืœ ื–ื™ื›ืจื•ืŸ RAM ื‘ืžืขืจื›ื•ืช 64-bit ื•-168GB ื‘ืžืขืจื›ื•ืช 32-bit.
    ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ืจืง ืžืžืขืจื›ื•ืช ืื•ืจื—ื•ืช ื‘ืžืฆื‘ PV (ื‘ืžืฆื‘ื™ HVM ื•-PVH, ื›ืืฉืจ ืขื•ื‘ื“ื™ื ื“ืจืš libxl, ื”ืคื’ื™ืขื•ืช ืื™ื ื” ื‘ืื” ืœื™ื“ื™ ื‘ื™ื˜ื•ื™);

  • CVE-2019-17346 - ืคื’ื™ืขื•ืช ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-PCID (ืžื–ื”ื™ ื”ืงืฉืจ ืชื”ืœื™ื›ื™ื) ืœืฉื™ืคื•ืจ ื‘ื™ืฆื•ืขื™ ื”ื”ื’ื ื” ืžืคื ื™ ื”ืชืงืคื•ืช
    Meltdown ืžืืคืฉืจ ืœืš ืœื’ืฉืช ืœื ืชื•ื ื™ื ืžืžืขืจื›ื•ืช ืื•ืจื—ื•ืช ืื—ืจื•ืช ื•ืขืœื•ืœื” ืœื”ืขืœื•ืช ืืช ื”ื”ืจืฉืื•ืช ืฉืœืš. ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ืจืง ืžืื•ืจื—ื™ื ื‘ืžืฆื‘ PV ื‘ืžืขืจื›ื•ืช x86 (ื”ื‘ืขื™ื” ืœื ืžื•ืคื™ืขื” ื‘ืžืฆื‘ื™ HVM ื•-PVH, ื›ืžื• ื’ื ื‘ืชืฆื•ืจื•ืช ืฉื‘ื”ืŸ ืื™ืŸ ืื•ืจื—ื™ื ืขื PCID ืžื•ืคืขืœ (PCID ืžื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ));

  • CVE-2019-17342 - ื‘ืขื™ื” ื‘ื™ื™ืฉื•ื ื”ื”ื™ืคืจ-ืงืจื™ืื” XENMEM_exchange ืžืืคืฉืจืช ืœืš ืœื”ืขืœื•ืช ืืช ื”ื”ืจืฉืื•ืช ืฉืœืš ื‘ืกื‘ื™ื‘ื•ืช ืขื ืžืขืจื›ืช ืื•ืจื— ืื—ืช ื‘ืœื‘ื“. ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ืจืง ืžืžืขืจื›ื•ืช ืื•ืจื—ื•ืช ื‘ืžืฆื‘ PV (ื”ืคื’ื™ืขื•ืช ืื™ื ื” ืžื•ืคื™ืขื” ื‘ืžืฆื‘ื™ HVM ื•-PVH);
  • CVE-2019-17343 - ืžื™ืคื•ื™ ืฉื’ื•ื™ ื‘-IOMMU ืžืืคืฉืจ, ืื ื™ืฉ ื’ื™ืฉื” ืžืžืขืจื›ืช ื”ืื•ืจื— ืœืžื›ืฉื™ืจ ื”ืคื™ื–ื™, ืœื”ืฉืชืžืฉ ื‘-DMA ื›ื“ื™ ืœืฉื ื•ืช ืืช ื˜ื‘ืœืช ื“ืคื™ ื”ื–ื™ื›ืจื•ืŸ ืฉืœื• ื•ืœื”ืฉื™ื’ ื’ื™ืฉื” ื‘ืจืžืช ื”ืžืืจื—. ื”ืคื’ื™ืขื•ืช ืžืชื‘ื˜ืืช ืจืง ื‘ืžืขืจื›ื•ืช ืื•ืจื—ื•ืช ื‘ืžืฆื‘ PV ืขื ื–ื›ื•ื™ื•ืช ื”ืขื‘ืจื” ืฉืœ ื”ืชืงื ื™ PCI.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”