ืคืจื•ื™ืงื˜ FreeBSD ื”ืคืš ืืช ื™ืฆื™ืืช ARM64 ืœื™ืฆื™ืื” ืจืืฉื™ืช ื•ืชื™ืงืŸ ืฉืœื•ืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื”

ืžืคืชื—ื™ FreeBSD ื”ื—ืœื™ื˜ื• ื‘ืกื ื™ืฃ ื”ื—ื“ืฉ ืฉืœ FreeBSD 13, ืฉืฆืคื•ื™ ืœืฆืืช ื‘-13 ื‘ืืคืจื™ืœ, ืœื”ืงืฆื•ืช ืœืคื•ืจื˜ ืœืืจื›ื™ื˜ืงื˜ื•ืจืช ARM64 (AArch64) ืืช ื”ืกื˜ื˜ื•ืก ืฉืœ ื”ืคืœื˜ืคื•ืจืžื” ื”ืจืืฉื™ืช (Tier 1). ื‘ืขื‘ืจ ื ื™ืชื ื” ืจืžื” ื“ื•ืžื” ืฉืœ ืชืžื™ื›ื” ืขื‘ื•ืจ ืžืขืจื›ื•ืช x64 ืฉืœ 86 ืกื™ื‘ื™ื•ืช (ืขื“ ืœืื—ืจื•ื ื”, ืืจื›ื™ื˜ืงื˜ื•ืจืช i386 ื”ื™ื™ืชื” ื”ืืจื›ื™ื˜ืงื˜ื•ืจื” ื”ืขื™ืงืจื™ืช, ืืš ื‘ื™ื ื•ืืจ ื”ื™ื ื”ื•ืขื‘ืจื” ืœืจืžืช ื”ืชืžื™ื›ื” ื”ืฉื ื™ื™ื”).

ืจืžืช ื”ืชืžื™ื›ื” ื”ืจืืฉื•ื ื” ื›ื•ืœืœืช ื™ืฆื™ืจืช ืžื›ืœื•ืœื™ ื”ืชืงื ื”, ืขื“ื›ื•ื ื™ื ื‘ื™ื ืืจื™ื™ื ื•ื—ื‘ื™ืœื•ืช ืžื•ื›ื ื•ืช, ื›ืžื• ื’ื ืžืชืŸ ืขืจื‘ื•ื™ื•ืช ืœืคืชืจื•ืŸ ื‘ืขื™ื•ืช ืกืคืฆื™ืคื™ื•ืช ื•ืฉืžื™ืจื” ืขืœ ื”-ABI ืœืœื ืฉื™ื ื•ื™ ืขื‘ื•ืจ ืกื‘ื™ื‘ืช ื”ืžืฉืชืžืฉ ื•ื”ืงืจื ืœ (ืœืžืขื˜ ื—ืœืง ืžืชืชื™-ืžืขืจื›ื•ืช). ื”ืจืžื” ื”ืจืืฉื•ื ื” ื ื•ืคืœืช ืชื—ืช ืชืžื™ื›ื” ืฉืœ ืฆื•ื•ืชื™ื ื”ืื—ืจืื™ื ืขืœ ื‘ื™ื˜ื•ืœ ืคื’ื™ืขื•ื™ื•ืช, ื”ื›ื ืช ืžื”ื“ื•ืจื•ืช ื•ืชื—ื–ื•ืงืช ื™ืฆื™ืื•ืช.

ื‘ื ื•ืกืฃ, ืื ื• ื™ื›ื•ืœื™ื ืœืฆื™ื™ืŸ ืืช ื‘ื™ื˜ื•ืœืŸ ืฉืœ ืฉืœื•ืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘- FreeBSD:

  • CVE-2021-29626 ืชื”ืœื™ืš ืžืงื•ืžื™ ืœืœื ืคืจื™ื‘ื™ืœื’ื™ื” ื™ื›ื•ืœ ืœืงืจื•ื ืืช ื”ืชื•ื›ืŸ ืฉืœ ื–ื™ื›ืจื•ืŸ ื”ืœื™ื‘ื” ืื• ืชื”ืœื™ื›ื™ื ืื—ืจื™ื ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ืžื™ืคื•ื™ ื“ืคื™ ื–ื™ื›ืจื•ืŸ. ื”ืคื’ื™ืขื•ืช ื ื•ื‘ืขืช ืžื‘ืื’ ื‘ืชืช-ืžืขืจื›ืช ื”ื–ื™ื›ืจื•ืŸ ื”ื•ื•ื™ืจื˜ื•ืืœื™ ื”ืžืืคืฉืจ ืฉื™ืชื•ืฃ ื–ื™ื›ืจื•ืŸ ื‘ื™ืŸ ืชื”ืœื™ื›ื™ื, ืžื” ืฉืขืœื•ืœ ืœื’ืจื•ื ืœื–ื™ื›ืจื•ืŸ ืœื”ืžืฉื™ืš ืœื”ื™ื•ืช ืงืฉื•ืจ ืœืชื”ืœื™ืš ืœืื—ืจ ืฉื—ืจื•ืจ ื“ืฃ ื”ื–ื™ื›ืจื•ืŸ ื”ืžืฉื•ื™ืš.
  • CVE-2021-29627 ืžืฉืชืžืฉ ืžืงื•ืžื™ ืœืœื ื”ืจืฉืื•ืช ื™ื›ื•ืœ ืœื”ืกืœื™ื ืืช ื”ื”ืจืฉืื•ืช ืฉืœื• ื‘ืžืขืจื›ืช ืื• ืœืงืจื•ื ืืช ื”ืชื•ื›ืŸ ืฉืœ ื–ื™ื›ืจื•ืŸ ื”ืœื™ื‘ื”. ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื’ื™ืฉื” ืœื–ื™ื›ืจื•ืŸ ืœืื—ืจ ืฉื—ืจื•ืจื• (use-after-free) ื‘ื™ื™ืฉื•ื ืžื ื’ื ื•ืŸ ื”-accept filter.
  • CVE-2020-25584 - ืืคืฉืจื•ืช ืœืขืงื•ืฃ ืืช ืžื ื’ื ื•ืŸ ื‘ื™ื“ื•ื“ ื”ื›ืœื. ืžืฉืชืžืฉ ื‘ืชื•ืš ืืจื’ื– ื—ื•ืœ ืขื ื”ืจืฉืื” ืœื˜ืขื•ืŸ ืžื—ื™ืฆื•ืช (allow.mount) ื™ื›ื•ืœ ืœืฉื ื•ืช ืืช ืกืคืจื™ื™ืช ื”ืฉื•ืจืฉ ืœืžื™ืงื•ื ืžื—ื•ืฅ ืœื”ื™ืจืจื›ื™ื™ืช ื”ื›ืœื ื•ืœืงื‘ืœ ื’ื™ืฉืช ืงืจื™ืื” ื•ื›ืชื™ื‘ื” ืžืœืื” ืœื›ืœ ืงื‘ืฆื™ ื”ืžืขืจื›ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”