ืคื’ื™ืขื•ืช ื ื•ืกืคืช ื‘ืชืช-ืžืขืจื›ืช ืœื™ื‘ืช Netfilter ืฉืœ Linux Netfilter

ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช (CVE-2022-1972) ื‘ืชืช-ืžืขืจื›ืช ืœื™ื‘ืช Netfilter, ื‘ื“ื•ืžื” ืœื‘ืขื™ื” ืฉื ื—ืฉืคื” ื‘ืกื•ืฃ ืžืื™. ื”ืคื’ื™ืขื•ืช ื”ื—ื“ืฉื” ื’ื ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœืงื‘ืœ ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ ื‘ืžืขืจื›ืช ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ื›ืœืœื™ื ื‘-nftables ื•ื“ื•ืจืฉืช ื’ื™ืฉื” ืœ-nftables ื›ื“ื™ ืœื‘ืฆืข ืืช ื”ืžืชืงืคื”, ืื•ืชื” ื ื™ืชืŸ ืœื”ืฉื™ื’ ื‘ืžืจื—ื‘ ืฉืžื•ืช ื ืคืจื“ (ืžืจื—ื‘ ืฉืžื•ืช ืจืฉืช ืื• ืžืจื—ื‘ ืฉืžื•ืช ืžืฉืชืžืฉ) ืขื CLONE_NEWUSER, ื–ื›ื•ื™ื•ืช CLONE_NEWNS ืื• CLONE_NEWNET (ืœื“ื•ื’ืžื”, ืื ืืคืฉืจ ืœื”ืคืขื™ืœ ืงื•ื ื˜ื™ื™ื ืจ ืžื‘ื•ื“ื“).

ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื‘ืื’ ื‘ืงื•ื“ ืœื˜ื™ืคื•ืœ ื‘ืจืฉื™ืžื•ืช ืกื˜ ืขื ืฉื“ื•ืช ื”ื›ื•ืœืœื™ื ื˜ื•ื•ื—ื™ื ืžืจื•ื‘ื™ื, ื•ื’ื•ืจืžืช ืœื›ืชื™ื‘ื” ืžื—ื•ืฅ ืœืชื—ื•ื ื‘ืขืช ืขื™ื‘ื•ื“ ืคืจืžื˜ืจื™ ืจืฉื™ืžื” ื‘ืคื•ืจืžื˜ ืžื™ื•ื—ื“. ื—ื•ืงืจื™ื ื”ืฆืœื™ื—ื• ืœื”ื›ื™ืŸ ื ื™ืฆื•ืœ ืขื‘ื•ื“ื” ื›ื“ื™ ืœื”ืฉื™ื’ ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ ื‘ืื•ื‘ื•ื ื˜ื• 21.10 ืขื ื”ืœื™ื‘ื” ื”ื’ื ืจื™ืช 5.13.0-39. ื”ืคื’ื™ืขื•ืช ืžื•ืคื™ืขื” ื”ื—ืœ ืžื’ืจืขื™ืŸ 5.6. ืชื™ืงื•ืŸ ืžืกื•ืคืง ื›ืชื™ืงื•ืŸ. ื›ื“ื™ ืœื—ืกื•ื ื ื™ืฆื•ืœ ืฉืœ ื”ืคื’ื™ืขื•ืช ื‘ืžืขืจื›ื•ืช ืจื’ื™ืœื•ืช, ืขืœื™ืš ืœื”ืงืคื™ื“ ืœื”ืฉื‘ื™ืช ืืช ื”ื™ื›ื•ืœืช ืœื™ืฆื•ืจ ืžืจื—ื‘ื™ ืฉืžื•ืช ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื ื—ืกืจื™ ื”ืจืฉืื•ืช ("sudo sysctl -w kernel.unprivileged_userns_clone=0").

ื‘ื ื•ืกืฃ, ืคื•ืจืกื ืžื™ื“ืข ืขืœ ืฉืœื•ืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉืœ ืœื™ื‘ื” ื”ืงืฉื•ืจื•ืช ืœืžืขืจื›ืช ื”ืžืฉื ื” NFC. ื”ืคื’ื™ืขื•ื™ื•ืช ืขืœื•ืœื•ืช ืœื’ืจื•ื ืœืงืจื™ืกื” ื‘ืืžืฆืขื•ืช ืคืขื•ืœื•ืช ืฉื‘ื•ืฆืขื• ืขืœ ื™ื“ื™ ืžืฉืชืžืฉ ื—ืกืจ ื”ืจืฉืื•ืช (ื˜ืจื ื”ื•ื›ื—ื• ื•ืงื˜ื•ืจื™ ืชืงื™ืคื” ืžืกื•ื›ื ื™ื ื™ื•ืชืจ):

  • CVE-2022-1734 ื”ื™ื ืฉื™ื—ืช ื–ื™ื›ืจื•ืŸ ืœืœื ืฉื™ืžื•ืฉ ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ ืฉืœ nfcmrvl (drivers/nfc/nfcmrvl), ื”ืžืชืจื—ืฉืช ื‘ืขืช ื”ื“ืžื™ื™ืช ื”ืชืงืŸ NFC ื‘ื—ืœืœ ื”ืžืฉืชืžืฉ.
  • CVE-2022-1974 - ืฉื™ื—ืช ื–ื™ื›ืจื•ืŸ ืฉื›ื‘ืจ ืฉื•ื—ืจืจื” ืžืชืจื—ืฉืช ื‘ืคื•ื ืงืฆื™ื•ืช netlink ืขื‘ื•ืจ ื”ืชืงื ื™ NFC (/net/nfc/core.c), ื”ืžืชืจื—ืฉืช ื‘ืขืช ืจื™ืฉื•ื ืžื›ืฉื™ืจ ื—ื“ืฉ. ื›ืžื• ื”ืคื’ื™ืขื•ืช ื”ืงื•ื“ืžืช, ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ื‘ืขื™ื” ืขืœ ื™ื“ื™ ื”ื“ืžื™ื™ืช ืžื›ืฉื™ืจ NFC ื‘ืžืจื—ื‘ ื”ืžืฉืชืžืฉ.
  • CVE-2022-1975 ื”ื•ื ื‘ืื’ ื‘ืงื•ื“ ื˜ืขื™ื ืช ื”ืงื•ืฉื—ื” ืขื‘ื•ืจ ื”ืชืงื ื™ NFC ืฉื ื™ืชืŸ ืœื ืฆืœื• ื›ื“ื™ ืœื’ืจื•ื ืœืžืฆื‘ ืฉืœ "ืคืื ื™ืงื”".

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”