ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช ื‘ืžื˜ืขืŸ ื”ืืชื—ื•ืœ GRUB2 ื”ืžืืคืฉืจ ืœืš ืœืขืงื•ืฃ ืืช UEFI Secure Boot

ื‘ืžื˜ืขืŸ ื”ืืชื—ื•ืœ GRUB2 ื’ื™ืœื” 8 ื ืงื•ื“ื•ืช ืชื•ืจืคื”. ื”ืžืกื•ื›ืŸ ื‘ื™ื•ืชืจ ื‘ืขื™ื” (CVE-2020-10713), ืฉื”ื•ื ืฉื ื”ืงื•ื“ BootHole, ืชืŸ ื”ื–ื“ืžื ื•ืช ืœืขืงื•ืฃ ืืช ืžื ื’ื ื•ืŸ ื”ืืชื—ื•ืœ ื”ืžืื•ื‘ื˜ื— ืฉืœ UEFI ื•ืœื”ืชืงื™ืŸ ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ืœื ืžืื•ืžืชื•ืช. ื”ื™ื™ื—ื•ื“ื™ื•ืช ืฉืœ ืคื’ื™ืขื•ืช ื–ื• ื”ื™ื ืฉื›ื“ื™ ืœื—ืกืœ ืื•ืชื” ืœื ืžืกืคื™ืง ืœืขื“ื›ืŸ GRUB2, ืฉื›ืŸ ื”ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืžื“ื™ื” ื ื™ืชื ืช ืœืืชื—ื•ืœ ืขื ื’ืจืกื” ืคื’ื™ืขื” ื™ืฉื ื” ืฉืื•ืฉืจื” ืขืœ ื™ื“ื™ ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช. ืชื•ืงืฃ ื™ื›ื•ืœ ืœืกื›ืŸ ืืช ืชื”ืœื™ืš ื”ืื™ืžื•ืช ืœื ืจืง ืฉืœ ืœื™ื ื•ืงืก, ืืœื ื’ื ืฉืœ ืžืขืจื›ื•ืช ื”ืคืขืœื” ืื—ืจื•ืช, ื›ื•ืœืœ Windows.

ื ื™ืชืŸ ืœืคืชื•ืจ ืืช ื”ื‘ืขื™ื” ืจืง โ€‹โ€‹ืขืœ ื™ื“ื™ ืขื“ื›ื•ืŸ ื”ืžืขืจื›ืช ืจืฉื™ืžืช ื‘ื™ื˜ื•ืœื™ ื”ืื™ืฉื•ืจื™ื (dbx, UEFI Revocation List), ืืš ื‘ืžืงืจื” ื–ื” ืชืื‘ื“ ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืžื“ื™ื™ืช ื”ืชืงื ื” ื™ืฉื ื” ืขื ืœื™ื ื•ืงืก. ื—ืœืง ืžื™ืฆืจื ื™ ื”ืฆื™ื•ื“ ื›ื‘ืจ ื›ืœืœื• ืจืฉื™ืžื” ืžืขื•ื“ื›ื ืช ืฉืœ ืื™ืฉื•ืจื™ ื‘ื™ื˜ื•ืœ ื‘ืงื•ืฉื—ื” ืฉืœื”ื; ื‘ืžืขืจื›ื•ืช ื›ืืœื”, ื ื™ืชืŸ ืœื˜ืขื•ืŸ ืจืง ื’ื™ืจื•ืฉื™ื ืžืขื•ื“ื›ื ื™ื ืฉืœ ื”ืคืฆื•ืช ืœื™ื ื•ืงืก ื‘ืžืฆื‘ UEFI Secure Boot.

ื›ื“ื™ ืœื‘ื˜ืœ ืืช ื”ืคื’ื™ืขื•ืช ื‘ื”ืคืฆื•ืช, ืชืฆื˜ืจืš ื’ื ืœืขื“ื›ืŸ ืžืชืงื™ื ื™ื, ืžื˜ืขื ื™ ืืชื—ื•ืœ, ื—ื‘ื™ืœื•ืช ืœื™ื‘ื”, ืงื•ืฉื—ืช fwupd ื•ืฉื›ื‘ืช shim, ืœื™ื™ืฆืจ ืขื‘ื•ืจื ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ื—ื“ืฉื•ืช. ื”ืžืฉืชืžืฉื™ื ื™ื™ื“ืจืฉื• ืœืขื“ื›ืŸ ืชืžื•ื ื•ืช ื”ืชืงื ื” ื•ืžื“ื™ื” ื ื™ืชื ืช ืœืืชื—ื•ืœ, ื•ื›ืŸ ืœื˜ืขื•ืŸ ืจืฉื™ืžืช ื‘ื™ื˜ื•ืœื™ ืื™ืฉื•ืจื™ื (dbx) ืœืงื•ืฉื—ืช UEFI. ืœืคื ื™ ืขื“ื›ื•ืŸ dbx ืœ-UEFI, ื”ืžืขืจื›ืช ื ืฉืืจืช ืคื’ื™ืขื” ืœืœื ืงืฉืจ ืœื”ืชืงื ืช ืขื“ื›ื•ื ื™ื ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื”.

ืคื’ื™ืขื•ืช ื’ืจื ืœ ื”ืฆืคืช ืžืื’ืจ ืฉื ื™ืชืŸ ืœื ืฆืœ ืœื‘ื™ืฆื•ืข ืงื•ื“ ืฉืจื™ืจื•ืชื™ ื‘ืžื”ืœืš ืชื”ืœื™ืš ื”ืืชื—ื•ืœ.
ื”ืคื’ื™ืขื•ืช ืžืชืจื—ืฉืช ื‘ืขืช ื ื™ืชื•ื— ื”ืชื•ื›ืŸ ืฉืœ ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” grub.cfg, ืืฉืจ ื ืžืฆื ื‘ื“ืจืš ื›ืœืœ ื‘-ESP (ืžื—ื™ืฆืช ืžืขืจื›ืช EFI) ื•ื ื™ืชืŸ ืœืขืจื•ืš ืื•ืชื• ืขืœ ื™ื“ื™ ืชื•ืงืฃ ืขื ื–ื›ื•ื™ื•ืช ืžื ื”ืœ ืžื‘ืœื™ ืœื”ืคืจ ืืช ืฉืœืžื•ืช ื”-shim ื•ืงื•ื‘ืฆื™ ื”ื”ืคืขืœื” ื”ื—ืชื•ืžื™ื ืฉืœ GRUB2. ื‘ื’ืœืœ ืฉื’ื™ืื•ืช ื‘ืงื•ื“ ืžื ืชื— ื”ืชืฆื•ืจื”, ื”ืžื˜ืคืœ ืœืฉื’ื™ืื•ืช ื ื™ืชื•ื— ืงื˜ืœื ื™ื•ืช YY_FATAL_ERROR ื”ืฆื™ื’ ืจืง ืื–ื”ืจื”, ืืš ืœื ืกื™ื™ื ืืช ื”ืชื•ื›ื ื™ืช. ื”ืกื™ื›ื•ืŸ ืœืคื’ื™ืขื•ืช ืžื•ืคื—ืช ืขืœ ื™ื“ื™ ื”ืฆื•ืจืš ื‘ื’ื™ืฉื” ืžื•ืกืžื›ืช ืœืžืขืจื›ืช; ืขื ื–ืืช, ื™ื™ืชื›ืŸ ืฉื”ื‘ืขื™ื” ืชื™ื“ืจืฉ ื›ื“ื™ ืœื”ืฆื™ื’ rootkits ื ืกืชืจื™ื ืื ื™ืฉ ืœืš ื’ื™ืฉื” ืคื™ื–ื™ืช ืœืฆื™ื•ื“ (ืื ื–ื” ืืคืฉืจื™ ืœืืชื—ืœ ืžื”ืžื“ื™ื” ืฉืœืš).

ืจื•ื‘ ื”ื”ืคืฆื•ืช ืฉืœ ืœื™ื ื•ืงืก ืžืฉืชืžืฉื•ืช ื‘-small ืฉื›ื‘ืช shim, ื—ืชื•ื ื“ื™ื’ื™ื˜ืœื™ ืขืœ ื™ื“ื™ Microsoft. ืฉื›ื‘ื” ื–ื• ืžืืžืชืช ืืช GRUB2 ืขื ืชืขื•ื“ื” ืžืฉืœื”, ืžื” ืฉืžืืคืฉืจ ืœืžืคืชื—ื™ ื”ืคืฆื” ืœื ืœืงื‘ืœ ืื™ืฉื•ืจ ืœื›ืœ ืœื™ื‘ื” ื•ืขื“ื›ื•ืŸ GRUB ืขืœ ื™ื“ื™ ืžื™ืงืจื•ืกื•ืคื˜. ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช, ืขืœ ื™ื“ื™ ืฉื™ื ื•ื™ ื”ืชื•ื›ืŸ ืฉืœ grub.cfg, ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืฉืœ ื”ืงื•ื“ ืฉืœืš ื‘ืฉืœื‘ ืฉืœืื—ืจ ืื™ืžื•ืช shim ืžื•ืฆืœื—, ืืš ืœืคื ื™ ื˜ืขื™ื ืช ืžืขืจื›ืช ื”ื”ืคืขืœื”, ืœื”ื™ืฆืžื“ ืœืฉืจืฉืจืช ื”ืืžื•ืŸ ื›ืืฉืจ ืžืฆื‘ ืืชื—ื•ืœ ืžืื•ื‘ื˜ื— ืคืขื™ืœ ื•ืœืงื‘ืœ ืฉืœื™ื˜ื” ืžืœืื” ืขืœ ืชื”ืœื™ืš ื”ืืชื—ื•ืœ ื”ื ื•ืกืฃ, ื›ื•ืœืœ ื˜ืขื™ื ืช ืžืขืจื›ืช ื”ืคืขืœื” ืื—ืจืช, ืฉื™ื ื•ื™ ืจื›ื™ื‘ื™ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื•ื”ื’ื ื” ืขืงื™ืคืช ื ืขื™ืœื”.

ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช ื‘ืžื˜ืขืŸ ื”ืืชื—ื•ืœ GRUB2 ื”ืžืืคืฉืจ ืœืš ืœืขืงื•ืฃ ืืช UEFI Secure Boot

ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืื—ืจื•ืช ื‘-GRUB2:

  • CVE-2020-14308 - ื’ืœื™ืฉืช ืžืื’ืจ ืขืงื‘ ื—ื•ืกืจ ื‘ื“ื™ืงืช ื’ื•ื“ืœ ืื–ื•ืจ ื”ื–ื™ื›ืจื•ืŸ ื”ืžื•ืงืฆื” ื‘-grub_malloc;
  • CVE-2020-14309 - ื”ืฆืคืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘-grub_squash_read_symlink, ืฉื™ื›ื•ืœื” ืœื”ื•ื‘ื™ืœ ืœื›ืชื™ื‘ืช ื ืชื•ื ื™ื ืžืขื‘ืจ ืœืžืื’ืจ ืฉื”ื•ืงืฆื”;
  • CVE-2020-14310 - ื’ืœื™ืฉืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘-read_section_from_string, ืžื” ืฉื™ื›ื•ืœ ืœื”ื•ื‘ื™ืœ ืœื›ืชื™ื‘ืช ื ืชื•ื ื™ื ืžืขื‘ืจ ืœืžืื’ืจ ื”ืžื•ืงืฆื”;
  • CVE-2020-14311 - ื”ืฆืคืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘-grub_ext2_read_link, ืืฉืจ ื™ื›ื•ืœื” ืœื”ื•ื‘ื™ืœ ืœื›ืชื™ื‘ืช ื ืชื•ื ื™ื ืžืขื‘ืจ ืœืžืื’ืจ ื”ืžื•ืงืฆื”;
  • CVE-2020-15705 - ืžืืคืฉืจ ืœืš ืœื˜ืขื•ืŸ ื’ืจืขื™ื ื™ื ืœื ื—ืชื•ืžื™ื ื‘ืžื”ืœืš ืืชื—ื•ืœ ื™ืฉื™ืจ ื‘ืžืฆื‘ ืืชื—ื•ืœ ืžืื•ื‘ื˜ื— ืœืœื ืฉื›ื‘ืช shim;
  • CVE-2020-15706 - ื’ื™ืฉื” ืœืื–ื•ืจ ื–ื™ื›ืจื•ืŸ ืžืฉื•ื—ืจืจ ื›ื‘ืจ (ืฉื™ืžื•ืฉ ืœืื—ืจ-ื—ื•ืคืฉื™) ื‘ืขืช ื”ื’ื“ืจื” ืžื—ื“ืฉ ืฉืœ ืคื•ื ืงืฆื™ื” ื‘ื–ืžืŸ ืจื™ืฆื”;
  • CVE-2020-15707 - ื’ืœื™ืฉืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘ืžื˜ืคืœ ื”ื’ื•ื“ืœ initrd.

ืขื“ื›ื•ื ื™ ืขืจื›ืช ืชื™ืงื•ื ื™ื ื—ืžื™ื ืฉื•ื—ืจืจื• ืขื‘ื•ืจ ื“ื‘ื™ืืŸ, ืื•ื‘ื•ื ื˜ื•, ืจื”ืœ ะธ SUSE. ืขื‘ื•ืจ GRUB2 ืžื•ึผืฆึธืข ืกื˜ ืฉืœ ืชื™ืงื•ื ื™ื.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”