ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-GRUB2 ื”ืžืืคืฉืจื•ืช ืœืš ืœืขืงื•ืฃ ืืช ื”ื’ื ืช UEFI Secure Boot

ื ื—ืฉืฃ ืžื™ื“ืข ืขืœ ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืžื˜ืขืŸ ื”ืืชื—ื•ืœ ืฉืœ GRUB2, ืฉืขืœื•ืœื•ืช ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ื’ื•ืคื ื™ื ืฉืขื•ืฆื‘ื• ื‘ืžื™ื•ื—ื“ ื•ืขื™ื‘ื•ื“ ืจืฆืคื™ Unicode ืžืกื•ื™ืžื™ื. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืคื’ื™ืขื•ื™ื•ืช ื›ื“ื™ ืœืขืงื•ืฃ ืืช ืžื ื’ื ื•ืŸ ื”ืืชื—ื•ืœ ืžืื•ืžืช ืฉืœ UEFI Secure Boot.

ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉื–ื•ื”ื•:

  • CVE-2022-2601 - ื’ืœื™ืฉืช ื—ื•ืฆืฅ ื‘ืคื•ื ืงืฆื™ื” grub_font_construct_glyph() ื‘ืขืช ืขื™ื‘ื•ื“ ื’ื•ืคื ื™ื ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“ ื‘ืคื•ืจืžื˜ pf2, ื”ืžืชืจื—ืฉืช ืขืงื‘ ื—ื™ืฉื•ื‘ ืฉื’ื•ื™ ืฉืœ ื”ืคืจืžื˜ืจ max_glyph_size ื•ื”ืงืฆืืช ืื–ื•ืจ ื–ื™ื›ืจื•ืŸ ืฉื›ืžื•ื‘ืŸ ืงื˜ืŸ ืžื”ื ื“ืจืฉ ื›ื“ื™ ืœื”ื›ื™ืœ ืืช ื”ื’ืœื™ืคื™ื.
  • CVE-2022-3775 ื›ืชื™ื‘ื” ืžื—ื•ืฅ ืœืชื—ื•ื ืžืชืจื—ืฉืช ื‘ืขืช ืจื™ื ื“ื•ืจ ื—ืœืง ืžืจืฆืคื™ Unicode ื‘ื’ื•ืคืŸ ื‘ืขืœ ืกื’ื ื•ืŸ ืžื™ื•ื—ื“. ื”ื‘ืขื™ื” ื”ื™ื ื‘ืงื•ื“ ืขื™ื‘ื•ื“ ื”ืคื•ื ื˜ื™ื ื•ื ื’ืจืžืช ืžื”ื™ืขื“ืจ ื‘ื“ื™ืงื•ืช ืžืชืื™ืžื•ืช ื›ื“ื™ ืœื•ื•ื“ื ืฉื”ืจื•ื—ื‘ ื•ื”ื’ื•ื‘ื” ืฉืœ ื”ื’ืœื™ืฃ ืชื•ืืžื™ื ืœื’ื•ื“ืœ ืžืคืช ื”ืกื™ื‘ื™ื•ืช ื”ื–ืžื™ื ื”. ืชื•ืงืฃ ื™ื›ื•ืœ ืœื™ืฆื•ืจ ืืช ื”ืงืœื˜ ื‘ืฆื•ืจื” ื›ื–ื• ืฉืชื’ืจื•ื ืœื›ืš ืฉื–ื ื‘ ื”ื ืชื•ื ื™ื ื™ื™ื›ืชื‘ ืืœ ืžื—ื•ืฅ ืœืžืื’ืจ ื”ืžื•ืงืฆื”. ื™ืฆื•ื™ืŸ ืฉืœืžืจื•ืช ื”ืžื•ืจื›ื‘ื•ืช ืฉืœ ื ื™ืฆื•ืœ ื”ืคื’ื™ืขื•ืช, ื”ื‘ืืช ื”ื‘ืขื™ื” ืœื‘ื™ืฆื•ืข ืงื•ื“ ืื™ื ื” ื ื›ืœืœืช.

ื”ืชื™ืงื•ืŸ ืคื•ืจืกื ื›ืชื™ืงื•ืŸ. ื ื™ืชืŸ ืœื”ืขืจื™ืš ืืช ืžืฆื‘ ื‘ื™ื˜ื•ืœ ื”ืคื’ื™ืขื•ื™ื•ืช ื‘ื”ืคืฆื•ืช ื‘ื“ืคื™ื ื”ื‘ืื™ื: ืื•ื‘ื•ื ื˜ื•, SUSE, RHEL, Fedora, Debian. ื›ื“ื™ ืœืชืงืŸ ื‘ืขื™ื•ืช ื‘-GRUB2, ื–ื” ืœื ืžืกืคื™ืง ืจืง ืœืขื“ื›ืŸ ืืช ื”ื—ื‘ื™ืœื”; ืชืฆื˜ืจืš ื’ื ืœื™ืฆื•ืจ ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ืคื ื™ืžื™ื•ืช ื—ื“ืฉื•ืช ื•ืœืขื“ื›ืŸ ืžืชืงื™ื ื™ื, ืžืื’ืจื™ ืืชื—ื•ืœ, ื—ื‘ื™ืœื•ืช ืœื™ื‘ื”, ืงื•ืฉื—ื” fwupd ื•ืฉื›ื‘ืช shim.

ืจื•ื‘ ื”ื”ืคืฆื•ืช ืฉืœ ืœื™ื ื•ืงืก ืžืฉืชืžืฉื•ืช ื‘ืฉื›ื‘ืช shim ืงื˜ื ื” ื”ื—ืชื•ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ืขืœ ื™ื“ื™ ืžื™ืงืจื•ืกื•ืคื˜ ืœืืชื—ื•ืœ ืžืื•ืžืช ื‘ืžืฆื‘ UEFI Secure Boot. ืฉื›ื‘ื” ื–ื• ืžืืžืชืช ืืช GRUB2 ืขื ืชืขื•ื“ื” ืžืฉืœื”, ืžื” ืฉืžืืคืฉืจ ืœืžืคืชื—ื™ ื”ืคืฆื” ืœื ืœืงื‘ืœ ืื™ืฉื•ืจ ืœื›ืœ ืœื™ื‘ื” ื•ืขื“ื›ื•ืŸ GRUB ืขืœ ื™ื“ื™ ืžื™ืงืจื•ืกื•ืคื˜. ืคื’ื™ืขื•ื™ื•ืช ื‘-GRUB2 ืžืืคืฉืจื•ืช ืœืš ืœื”ืฉื™ื’ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœืš ื‘ืฉืœื‘ ืฉืœืื—ืจ ืื™ืžื•ืช shim ืžื•ืฆืœื—, ืืš ืœืคื ื™ ื˜ืขื™ื ืช ืžืขืจื›ืช ื”ื”ืคืขืœื”, ื”ื™ืฆืžื“ื•ืช ืœืฉืจืฉืจืช ื”ืืžื•ืŸ ื›ืืฉืจ ืžืฆื‘ Secure Boot ืคืขื™ืœ ื•ืงื‘ืœืช ืฉืœื™ื˜ื” ืžืœืื” ืขืœ ืชื”ืœื™ืš ื”ืืชื—ื•ืœ ื”ื ื•ืกืฃ, ื›ื•ืœืœ ื˜ืขื™ื ืช ืžืขืจื›ืช ื”ืคืขืœื” ืื—ืจืช, ืฉื™ื ื•ื™ ืžืขืจื›ืช ืจื›ื™ื‘ื™ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื•ืขืงื•ืฃ ื”ื’ื ืช ื ืขื™ืœื”.

ื›ื“ื™ ืœื—ืกื•ื ืืช ื”ืคื’ื™ืขื•ืช ืžื‘ืœื™ ืœื‘ื˜ืœ ืืช ื”ื—ืชื™ืžื” ื”ื“ื™ื’ื™ื˜ืœื™ืช, ื”ืคืฆื•ืช ื™ื›ื•ืœื•ืช ืœื”ืฉืชืžืฉ ื‘ืžื ื’ื ื•ืŸ SBAT (UEFI Secure Boot Advanced Targeting), ืืฉืจ ื ืชืžืš ืขื‘ื•ืจ GRUB2, shim ื•-fwupd ื‘ืจื•ื‘ ื”ื”ืคืฆื•ืช ื”ืคื•ืคื•ืœืจื™ื•ืช ืฉืœ ืœื™ื ื•ืงืก. SBAT ืคื•ืชื—ื” ื‘ืžืฉื•ืชืฃ ืขื ืžื™ืงืจื•ืกื•ืคื˜ ื•ื›ื•ืœืœืช ื”ื•ืกืคืช ืžื˜ื ื ืชื•ื ื™ื ื ื•ืกืคื™ื ืœืงื‘ืฆื™ ื”ื”ืคืขืœื” ืฉืœ ืจื›ื™ื‘ื™ UEFI, ื”ื›ื•ืœืœื™ื ืžื™ื“ืข ืขืœ ื”ื™ืฆืจืŸ, ื”ืžื•ืฆืจ, ื”ืจื›ื™ื‘ ื•ื”ื’ืจืกื”. ื”ืžื˜ื ื ืชื•ื ื™ื ืฉืฆื•ื™ื ื• ืžืื•ืฉืจื™ื ื‘ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ื•ื ื™ืชืŸ ืœื›ืœื•ืœ ืื•ืชื ื‘ื ืคืจื“ ื‘ืจืฉื™ืžื•ืช ืฉืœ ืจื›ื™ื‘ื™ื ืžื•ืชืจื™ื ืื• ืืกื•ืจื™ื ืขื‘ื•ืจ UEFI Secure Boot.

SBAT ืžืืคืฉืจ ืœืš ืœื—ืกื•ื ืืช ื”ืฉื™ืžื•ืฉ ื‘ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ืขื‘ื•ืจ ืžืกืคืจื™ ื’ืจืกืื•ืช ืฉืœ ืจื›ื™ื‘ื™ื ื‘ื•ื“ื“ื™ื ืžื‘ืœื™ ืฉืชืฆื˜ืจืš ืœื‘ื˜ืœ ืžืคืชื—ื•ืช ืขื‘ื•ืจ ืืชื—ื•ืœ ืžืื•ื‘ื˜ื—. ื—ืกื™ืžืช ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืืžืฆืขื•ืช SBAT ืื™ื ื” ืžืฆืจื™ื›ื” ืฉื™ืžื•ืฉ ื‘ืจืฉื™ืžืช ื‘ื™ื˜ื•ืœื™ ืื™ืฉื•ืจื™ UEFI (dbx), ืืœื ืžื‘ื•ืฆืขืช ื‘ืจืžืช ื”ื—ืœืคืช ื”ืžืคืชื— ื”ืคื ื™ืžื™ ืœื™ืฆื™ืจืช ื—ืชื™ืžื•ืช ื•ืขื“ื›ื•ืŸ GRUB2, shim ื•ื—ืคืฆื™ ืืชื—ื•ืœ ืื—ืจื™ื ื”ืžืกื•ืคืงื™ื ืขืœ ื™ื“ื™ ื”ืคืฆื•ืช. ืœืคื ื™ ื”ืฆื’ืช SBAT, ืขื“ื›ื•ืŸ ืจืฉื™ืžืช ื‘ื™ื˜ื•ืœื™ ื”ืื™ืฉื•ืจื™ื (dbx, UEFI Revocation List) ื”ื™ื” ืชื ืื™ ืžื•ืงื“ื ืœื—ืกื™ืžืช ื”ืคื’ื™ืขื•ืช ืœื—ืœื•ื˜ื™ืŸ, ืฉื›ืŸ ืชื•ืงืฃ, ืœืœื ืงืฉืจ ืœืžืขืจื›ืช ื”ื”ืคืขืœื” ืฉื‘ื” ื ืขืฉื” ืฉื™ืžื•ืฉ, ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืžื“ื™ื” ื ื™ืชื ืช ืœืืชื—ื•ืœ ืขื ื’ืจืกื” ื™ืฉื ื” ื•ืคื’ื™ืขื” ืฉืœ GRUB2, ืžืื•ืฉืจ ืขืœ ื™ื“ื™ ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช, ื›ื“ื™ ืœืกื›ืŸ ืืช UEFI Secure Boot .

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”