ืคื’ื™ืขื•ืช ืžืงื•ืžื™ืช ื‘-nftables ื”ืžืืคืฉืจืช ืœืš ืœื”ืกืœื™ื ืืช ื”ื”ืจืฉืื•ืช ืฉืœืš

ืœ-Netfilter, ืชืช-ืžืขืจื›ืช ืฉืœ ืœื™ื‘ืช ืœื™ื ื•ืงืก ื”ืžืฉืžืฉืช ืœืกื™ื ื•ืŸ ื•ืฉื™ื ื•ื™ ืžื ื•ืช ืจืฉืช, ื™ืฉื ื” ืคื’ื™ืขื•ืช (CVE ืœื ืžื•ืงืฆื™ืช) ื”ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœื‘ืฆืข ืงื•ื“ ื‘ืจืžืช ื”ืงืจื ืœ ื•ืœื”ืขืœื•ืช ืืช ื”ื”ืจืฉืื•ืช ืฉืœื• ื‘ืžืขืจื›ืช. ื—ื•ืงืจื™ื ื”ื•ื›ื™ื—ื• ื ื™ืฆื•ืœ ืฉืืคืฉืจ ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœื”ืฉื™ื’ ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ ื‘ืื•ื‘ื•ื ื˜ื• 22.04 ืขื ื”ืœื™ื‘ื” ื”ื’ื ืจื™ืช 5.15.0-39. ื‘ืชื—ื™ืœื” ืชื•ื›ื ืŸ ืœืคืจืกื•ื ืžื™ื“ืข ืขืœ ื”ืคื’ื™ืขื•ืช ื‘-15 ื‘ืื•ื’ื•ืกื˜, ืืš ืขืงื‘ ื”ืขืชืงืช ืžื›ืชื‘ ืขื ืื‘ ื˜ื™ืคื•ืก ืฉืœ ื”ื ื™ืฆื•ืœ ืœืจืฉื™ืžืช ืชืคื•ืฆื” ืฆื™ื‘ื•ืจื™ืช, ื”ื•ืกืจ ื”ืืžื‘ืจื’ื• ืขืœ ื—ืฉื™ืคืช ืžื™ื“ืข.

ื”ื‘ืขื™ื” ื ื™ื›ืจืช ืžืื– ืœื™ื‘ืช 5.8 ื•ื”ื™ื ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื’ืœื™ืฉืช ืžืื’ืจ ื‘ืงื•ื“ ืœื˜ื™ืคื•ืœ ื‘ืจืฉื™ืžื•ืช ืกื˜ื™ื ื‘ืžื•ื“ื•ืœ nf_tables, ืฉื”ืชืจื—ืฉื” ืขืงื‘ ื”ื™ืขื“ืจ ื‘ื“ื™ืงื•ืช ืžืชืื™ืžื•ืช ื‘ืคื•ื ืงืฆื™ื” nft_set_elem_init. ื”ื‘ืื’ ื”ื•ืฆื’ ื‘ืฉื™ื ื•ื™ ืฉื”ืจื—ื™ื‘ ืืช ืื–ื•ืจ ื”ืื—ืกื•ืŸ ืฉืœ ืคืจื™ื˜ื™ ืจืฉื™ืžื” ืœ-128 ื‘ืชื™ื.

ื›ื“ื™ ืœื‘ืฆืข ืืช ื”ืžืชืงืคื”, ื ื“ืจืฉืช ื’ื™ืฉื” ืœ-nftables, ืฉื ื™ืชืŸ ืœื”ืฉื™ื’ ื‘ืžืจื—ื‘ื™ ืฉืžื•ืช ื ืคืจื“ื™ื ืฉืœ ืจืฉืช ืื ื™ืฉ ืœืš ื–ื›ื•ื™ื•ืช CLONE_NEWUSER, CLONE_NEWNS ืื• CLONE_NEWNET (ืœื“ื•ื’ืžื”, ืื ืืชื” ื™ื›ื•ืœ ืœื”ืคืขื™ืœ ืงื•ื ื˜ื™ื™ื ืจ ืžื‘ื•ื“ื“). ืชื™ืงื•ืŸ ืขื“ื™ื™ืŸ ืœื ื–ืžื™ืŸ. ื›ื“ื™ ืœื—ืกื•ื ื ื™ืฆื•ืœ ืฉืœ ื”ืคื’ื™ืขื•ืช ื‘ืžืขืจื›ื•ืช ืจื’ื™ืœื•ืช, ืขืœื™ืš ืœื”ืงืคื™ื“ ืœื”ืฉื‘ื™ืช ืืช ื”ื™ื›ื•ืœืช ืœื™ืฆื•ืจ ืžืจื—ื‘ื™ ืฉืžื•ืช ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื ื—ืกืจื™ ื”ืจืฉืื•ืช ("sudo sysctl -w kernel.unprivileged_userns_clone=0").

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”