ื ื—ืฉืคื” ื˜ื›ื ื™ืงื” ืœื ื™ืฆื•ืœ ืคื’ื™ืขื•ืช ื‘ืชืช-ืžืขืจื›ืช tty ืฉืœ ืœื™ื‘ืช ืœื™ื ื•ืงืก

ื—ื•ืงืจื™ื ืžืฆื•ื•ืช Google Project Zero ืคืจืกืžื• ืฉื™ื˜ื” ืœื ื™ืฆื•ืœ ืคื’ื™ืขื•ืช (CVE-2020-29661) ื‘ื”ื˜ืžืขืช ื”ืžื˜ืคืœ TIOCSPGRP ioctl ืžืชืช-ื”ืžืขืจื›ืช tty ืฉืœ ืœื™ื‘ืช ืœื™ื ื•ืงืก, ื•ื›ืŸ ื‘ื“ืงื• ื‘ืคื™ืจื•ื˜ ืืช ืžื ื’ื ื•ื ื™ ื”ื”ื’ื ื” ืฉืขืœื•ืœื™ื ืœื—ืกื•ื ื›ืืœื” ืคื’ื™ืขื•ืช.

ื”ื‘ืื’ ืฉื’ืจื ืœื‘ืขื™ื” ืชื•ืงืŸ ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก ื‘-3 ื‘ื“ืฆืžื‘ืจ ื‘ืฉื ื” ืฉืขื‘ืจื”. ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ื‘ืงืจื ืœื™ื ืขื“ ื’ืจืกื” 5.9.13, ืืš ืจื•ื‘ ื”ื”ืคืฆื•ืช ืชื™ืงื ื• ืืช ื”ื‘ืขื™ื” ื‘ืขื“ื›ื•ื ื™ื ืœื—ื‘ื™ืœื•ืช ืœื™ื‘ื” ืฉื”ื•ืฆืขื• ื‘ืฉื ื” ืฉืขื‘ืจื” (Debian, RHEL, SUSE, Ubuntu, Fedora, Arch). ืคื’ื™ืขื•ืช ื“ื•ืžื” (CVE-2020-29660) ื ืžืฆืื” ื‘ื•-ื–ืžื ื™ืช ื‘ื”ื˜ืžืขืช ืงืจื™ืืช TIOCGSID ioctl, ืืš ื”ื™ื ื’ื ืชื•ืงื ื” ื‘ื›ืœ ืžืงื•ื.

ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ืฉื’ื™ืื” ื‘ืขืช ื”ื’ื“ืจืช ื ืขื™ืœื•ืช, ืžื” ืฉืžื•ื‘ื™ืœ ืœืžืฆื‘ ืžืจื•ืฅ ื‘ืงื•ื“ drivers/tty/tty_jobctrl.c, ืืฉืจ ืฉื™ืžืฉ ืœื™ืฆื™ืจืช ืชื ืื™ ืฉื™ืžื•ืฉ-ืื—ืจื™-ื—ื•ืคืฉื™ ืžื ื•ืฆืœื™ื ืžืžืจื—ื‘ ื”ืžืฉืชืžืฉ ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื•ืช ืฉืœ ioct. ืงื•ืจืื™ื TIOCSPGRP. ื”ื•ื›ื— ื ื™ืฆื•ืœ ืขื•ื‘ื“ ืœื”ืกืœืžื” ืฉืœ ื”ืจืฉืื•ืช ื‘ื“ื‘ื™ืืŸ 10 ืขื ืœื™ื‘ื” 4.19.0-13-amd64.

ื™ื—ื“ ืขื ื–ืืช, ื”ืžืืžืจ ืฉืคื•ืจืกื ืœื ืžืชืžืงื“ ื›ืœ ื›ืš ื‘ื˜ื›ื ื™ืงื” ืฉืœ ื™ืฆื™ืจืช ื ื™ืฆื•ืœ ืขื•ื‘ื“, ืืœื ื‘ืื™ืœื• ื›ืœื™ื ืงื™ื™ืžื™ื ื‘ืงืจื ืœ ื›ื“ื™ ืœื”ื’ืŸ ืžืคื ื™ ืคื’ื™ืขื•ื™ื•ืช ื›ืืœื”. ื”ืžืกืงื ื” ืื™ื ื” ืžื ื—ืžืช; ืฉื™ื˜ื•ืช ื›ืžื• ืคื™ืœื•ื— ื–ื™ื›ืจื•ืŸ ื‘ืขืจื™ืžื” ื•ืฉืœื™ื˜ื” ื‘ื’ื™ืฉื” ืœื–ื™ื›ืจื•ืŸ ืœืื—ืจ ืฉื—ืจื•ืจื• ืื™ื ืŸ ื‘ืฉื™ืžื•ืฉ ื‘ืคื•ืขืœ, ืžื›ื™ื•ื•ืŸ ืฉื”ืŸ ืžื•ื‘ื™ืœื•ืช ืœื™ืจื™ื“ื” ื‘ื‘ื™ืฆื•ืขื™ื, ื•ื”ื’ื ื” ืžื‘ื•ืกืกืช CFI (Control Flow Integrity), ืืฉืจ ื—ื•ืกื ื ื™ืฆื•ืœื™ื ื‘ืฉืœื‘ื™ื ืžืื•ื—ืจื™ื ื™ื•ืชืจ ืฉืœ ื”ืชืงืคื”, ื˜ืขื•ืŸ ืฉื™ืคื•ืจ.

ื›ืืฉืจ ื‘ื•ื—ื ื™ื ืžื” ื™ืขืฉื” ื”ื‘ื“ืœ ื‘ื˜ื•ื•ื— ื”ืืจื•ืš, ืื—ื“ ื”ื‘ื•ืœื˜ ื”ื•ื ื”ืฉื™ืžื•ืฉ ื‘ืžื ืชื—ื™ื ืกื˜ื˜ื™ื™ื ืžืชืงื“ืžื™ื ืื• ืฉื™ืžื•ืฉ ื‘ืฉืคื•ืช ื‘ื˜ื•ื—ื•ืช ื‘ื–ื™ื›ืจื•ืŸ ื›ื’ื•ืŸ ื ื™ื‘ื™ื ื—ืœื•ื“ื” ื•-C ืขื ื”ืขืจื•ืช ืขืฉื™ืจื•ืช (ื›ื’ื•ืŸ ืžืกื•ืžืŸ C) ื›ื“ื™ ืœื‘ื“ื•ืง ืžืฆื‘ ื‘ืžื”ืœืš ืฉืœื‘ ื”ื‘ื ื™ื™ื” ืžื ืขื•ืœื™ื, ื—ืคืฆื™ื ื•ืžืฆื‘ื™ืขื™ื. ืฉื™ื˜ื•ืช ื”ื”ื’ื ื” ื›ื•ืœืœื•ืช ื’ื ื”ืคืขืœืช ืžืฆื‘ panic_on_oops, ื”ื—ืœืคืช ืžื‘ื ื™ ืœื™ื‘ื” ืœืžืฆื‘ ืงืจื™ืื” ื‘ืœื‘ื“ ื•ื”ื’ื‘ืœืช ื’ื™ืฉื” ืœืฉื™ื—ื•ืช ืžืขืจื›ืช ื‘ืืžืฆืขื•ืช ืžื ื’ื ื•ื ื™ื ื›ื’ื•ืŸ seccomp.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”