ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉืงืฉื” ืœืชืงืŸ ื‘-GRUB2 ื”ืžืืคืฉืจื•ืช ืœืš ืœืขืงื•ืฃ ืืช UEFI Secure Boot

ื ื—ืฉืฃ ืžื™ื“ืข ืขืœ 8 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืžื˜ืขืŸ ื”ืืชื—ื•ืœ GRUB2, ื”ืžืืคืฉืจื•ืช ืœืš ืœืขืงื•ืฃ ืืช ืžื ื’ื ื•ืŸ ื”ืืชื—ื•ืœ ื”ืžืื•ื‘ื˜ื— ืฉืœ UEFI ื•ืœื”ืจื™ืฅ ืงื•ื“ ืœื ืžืื•ืžืช, ืœืžืฉืœ, ืœื™ื™ืฉื ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ื”ืคื•ืขืœื•ืช ื‘ืจืžืช ื”ืืชื—ื•ืœ ืื• ืจืžืช ื”ืงืจื ืœ.

ื ื–ื›ื™ืจ ืฉื‘ืจื•ื‘ ื”ื”ืคืฆื•ืช ืฉืœ ืœื™ื ื•ืงืก, ืœืืชื—ื•ืœ ืžืื•ืžืช ื‘ืžืฆื‘ UEFI Secure Boot, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืฉื›ื‘ืช shim ืงื˜ื ื”, ื—ืชื•ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ืขืœ ื™ื“ื™ ืžื™ืงืจื•ืกื•ืคื˜. ืฉื›ื‘ื” ื–ื• ืžืืžืชืช ืืช GRUB2 ืขื ืชืขื•ื“ื” ืžืฉืœื”, ืžื” ืฉืžืืคืฉืจ ืœืžืคืชื—ื™ ื”ืคืฆื” ืœื ืœืงื‘ืœ ืื™ืฉื•ืจ ืœื›ืœ ืœื™ื‘ื” ื•ืขื“ื›ื•ืŸ GRUB ืขืœ ื™ื“ื™ ืžื™ืงืจื•ืกื•ืคื˜. ืคื’ื™ืขื•ื™ื•ืช ื‘-GRUB2 ืžืืคืฉืจื•ืช ืœืš ืœื”ืฉื™ื’ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœืš ื‘ืฉืœื‘ ืฉืœืื—ืจ ืื™ืžื•ืช shim ืžื•ืฆืœื—, ืืš ืœืคื ื™ ื˜ืขื™ื ืช ืžืขืจื›ืช ื”ื”ืคืขืœื”, ื”ื™ืฆืžื“ื•ืช ืœืฉืจืฉืจืช ื”ืืžื•ืŸ ื›ืืฉืจ ืžืฆื‘ Secure Boot ืคืขื™ืœ ื•ืงื‘ืœืช ืฉืœื™ื˜ื” ืžืœืื” ืขืœ ืชื”ืœื™ืš ื”ืืชื—ื•ืœ ื”ื ื•ืกืฃ, ื›ื•ืœืœ ื˜ืขื™ื ืช ืžืขืจื›ืช ื”ืคืขืœื” ืื—ืจืช, ืฉื™ื ื•ื™ ืžืขืจื›ืช ืจื›ื™ื‘ื™ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื•ืขืงื•ืฃ ื”ื’ื ืช ื ืขื™ืœื”.

ื‘ื“ื•ืžื” ืœืคื’ื™ืขื•ืช ืฉืœ BootHole ื‘ืฉื ื” ืฉืขื‘ืจื”, ืขื“ื›ื•ืŸ ืฉืœ ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ ืื™ื ื• ืžืกืคื™ืง ื›ื“ื™ ืœื—ืกื•ื ืืช ื”ื‘ืขื™ื”, ืฉื›ืŸ ืชื•ืงืฃ, ืœืœื ืงืฉืจ ืœืžืขืจื›ืช ื”ื”ืคืขืœื” ืฉื‘ื” ื ืขืฉื” ืฉื™ืžื•ืฉ, ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืžื“ื™ื” ื ื™ืชื ืช ืœืืชื—ื•ืœ ืขื ื’ืจืกื” ื™ืฉื ื”, โ€‹โ€‹ื—ืชื•ืžื” ื“ื™ื’ื™ื˜ืœื™ืช, ืคื’ื™ืขื” ืฉืœ GRUB2 ื›ื“ื™ ืœืกื›ืŸ ืืช UEFI Secure Boot. ื ื™ืชืŸ ืœืคืชื•ืจ ืืช ื”ื‘ืขื™ื” ืจืง โ€‹โ€‹ืขืœ ื™ื“ื™ ืขื“ื›ื•ืŸ ืจืฉื™ืžืช ื‘ื™ื˜ื•ืœื™ ื”ืื™ืฉื•ืจื™ื (dbx, UEFI Revocation List), ืืš ื‘ืžืงืจื” ื–ื” ืชืื‘ื“ ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืžื“ื™ื™ืช ื”ืชืงื ื” ื™ืฉื ื” ืขื ืœื™ื ื•ืงืก.

ื‘ืžืขืจื›ื•ืช ืขื ืงื•ืฉื—ื” ืฉื™ืฉ ืœื” ืจืฉื™ืžืช ื‘ื™ื˜ื•ืœื™ ืื™ืฉื•ืจื™ื ืžืขื•ื“ื›ื ืช, ื ื™ืชืŸ ืœื˜ืขื•ืŸ ืจืง ื’ื™ืจื•ืฉื™ื ืžืขื•ื“ื›ื ื™ื ืฉืœ ื”ืคืฆื•ืช ืœื™ื ื•ืงืก ื‘ืžืฆื‘ UEFI Secure Boot. ื”ื”ืคืฆื•ืช ื™ืฆื˜ืจื›ื• ืœืขื“ื›ืŸ ืžืชืงื™ื ื™ื, ืžื˜ืขื ื™ ืืชื—ื•ืœ, ื—ื‘ื™ืœื•ืช ืœื™ื‘ื”, ืงื•ืฉื—ื” fwupd ื•ืฉื›ื‘ืช shim, ืœื™ื™ืฆืจ ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ื—ื“ืฉื•ืช ืขื‘ื•ืจื. ื”ืžืฉืชืžืฉื™ื ื™ื™ื“ืจืฉื• ืœืขื“ื›ืŸ ืชืžื•ื ื•ืช ื”ืชืงื ื” ื•ืžื“ื™ื” ื ื™ืชื ืช ืœืืชื—ื•ืœ, ื•ื›ืŸ ืœื˜ืขื•ืŸ ืจืฉื™ืžืช ื‘ื™ื˜ื•ืœื™ ืื™ืฉื•ืจื™ื (dbx) ืœืงื•ืฉื—ื” ืฉืœ UEFI. ืœืคื ื™ ืขื“ื›ื•ืŸ dbx ืœ-UEFI, ื”ืžืขืจื›ืช ื ืฉืืจืช ืคื’ื™ืขื” ืœืœื ืงืฉืจ ืœื”ืชืงื ืช ืขื“ื›ื•ื ื™ื ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื”. ื ื™ืชืŸ ืœื”ืขืจื™ืš ืืช ืžืฆื‘ ื”ืคื’ื™ืขื•ืช ื‘ื“ืคื™ื ื”ื‘ืื™ื: ืื•ื‘ื•ื ื˜ื•, SUSE, RHEL, Debian.

ื›ื“ื™ ืœืคืชื•ืจ ื‘ืขื™ื•ืช ื”ืžืชืขื•ืจืจื•ืช ื‘ืขืช ื”ืคืฆืช ืื™ืฉื•ืจื™ื ืฉื ืฉืœืœื•, ื‘ืขืชื™ื“ ืžืชื•ื›ื ืŸ ืœื”ืฉืชืžืฉ ื‘ืžื ื’ื ื•ืŸ SBAT (UEFI Secure Boot Advanced Targeting), ืฉื”ืชืžื™ื›ื” ื‘ื• ื”ื•ื˜ืžืขื” ืขื‘ื•ืจ GRUB2, shim ื•-fwupd, ื•ื”ื—ืœ ืžื”ืขื“ื›ื•ื ื™ื ื”ื‘ืื™ื ืชื”ื™ื” ื‘ืฉื™ืžื•ืฉ ื‘ืžืงื•ื ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืžืกืคืงืช ื—ื‘ื™ืœืช dbxtool. SBAT ืคื•ืชื—ื” ื‘ืžืฉื•ืชืฃ ืขื ืžื™ืงืจื•ืกื•ืคื˜ ื•ื›ื•ืœืœืช ื”ื•ืกืคืช ืžื˜ื ื ืชื•ื ื™ื ื—ื“ืฉื™ื ืœืงื‘ืฆื™ ื”ื”ืคืขืœื” ืฉืœ ืจื›ื™ื‘ื™ UEFI, ื”ื›ื•ืœืœื™ื ืžื™ื“ืข ืขืœ ื”ื™ืฆืจืŸ, ื”ืžื•ืฆืจ, ื”ืจื›ื™ื‘ ื•ื”ื’ืจืกื”. ื”ืžื˜ื ื ืชื•ื ื™ื ืฉืฆื•ื™ื ื• ืžืื•ืฉืจื™ื ื‘ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ื•ื ื™ืชืŸ ื‘ื ื•ืกืฃ ืœื”ื™ื›ืœืœ ื‘ืจืฉื™ืžื•ืช ืฉืœ ืจื›ื™ื‘ื™ื ืžื•ืชืจื™ื ืื• ืืกื•ืจื™ื ืขื‘ื•ืจ UEFI Secure Boot. ืœืคื™ื›ืš, SBAT ื™ืืคืฉืจ ืœืš ืœืชืคืขืœ ืžืกืคืจื™ ื’ืจืกืื•ืช ืฉืœ ืจื›ื™ื‘ื™ื ื‘ืžื”ืœืš ื‘ื™ื˜ื•ืœ ืœืœื ืฆื•ืจืš ืœื™ืฆื•ืจ ืžื—ื“ืฉ ืžืคืชื—ื•ืช ืขื‘ื•ืจ ืืชื—ื•ืœ ืžืื•ื‘ื˜ื— ื•ืžื‘ืœื™ ืœื™ืฆื•ืจ ื—ืชื™ืžื•ืช ื—ื“ืฉื•ืช ืขื‘ื•ืจ ื”ืงืจื ืœ, shim, grub2 ื•-fwupd.

ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉื–ื•ื”ื•:

  • CVE-2020-14372 โ€“ ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” acpi ื‘-GRUB2, ืžืฉืชืžืฉ ืžื™ื•ื—ืก ื‘ืžืขืจื›ืช ื”ืžืงื•ืžื™ืช ื™ื›ื•ืœ ืœื˜ืขื•ืŸ ื˜ื‘ืœืื•ืช ACPI ืฉืฉื•ื ื• ืขืœ ื™ื“ื™ ื”ืฆื‘ืช SSDT (ื˜ื‘ืœืช ืชื™ืื•ืจ ืžืขืจื›ืช ืžืฉื ื™ืช) ื‘ืกืคืจื™ื™ืช /boot/efi ื•ืฉื™ื ื•ื™ ื”ื’ื“ืจื•ืช ื‘-grub.cfg. ืœืžืจื•ืช ืฉืžืฆื‘ ืืชื—ื•ืœ ืžืื•ื‘ื˜ื— ืคืขื™ืœ, ื”-SSDT ื”ืžื•ืฆืข ื™ื‘ื•ืฆืข ืขืœ ื™ื“ื™ ื”ืœื™ื‘ื” ื•ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื›ื“ื™ ืœื”ืฉื‘ื™ืช ืืช ื”ื’ื ืช LockDown ืฉื—ื•ืกืžืช ื ืชื™ื‘ื™ ืขืงื™ืคืช UEFI Secure Boot. ื›ืชื•ืฆืื” ืžื›ืš, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืฉื™ื’ ื˜ืขื™ื ื” ืฉืœ ืžื•ื“ื•ืœ ื”ืœื™ื‘ื” ืฉืœื• ืื• ืงื•ื“ ืจื™ืฆื” ื“ืจืš ืžื ื’ื ื•ืŸ kexec, ืžื‘ืœื™ ืœื‘ื“ื•ืง ืืช ื”ื—ืชื™ืžื” ื”ื“ื™ื’ื™ื˜ืœื™ืช.
  • CVE-2020-25632 ื”ื•ื ื’ื™ืฉื” ืœื–ื™ื›ืจื•ืŸ ืœืœื ืฉื™ืžื•ืฉ ืœืื—ืจ ืฉื™ืžื•ืฉ ื‘ื™ื™ืฉื•ื ื”ืคืงื•ื“ื” rmmod, ื”ืžืชืจื—ืฉืช ื›ืืฉืจ ื ืขืฉื” ื ื™ืกื™ื•ืŸ ืœืคืจื•ืง ืžื•ื“ื•ืœ ื›ืœืฉื”ื• ืžื‘ืœื™ ืœืงื—ืช ื‘ื—ืฉื‘ื•ืŸ ืืช ื”ืชืœื•ืช ื”ืงืฉื•ืจื•ืช ืืœื™ื•. ื”ืคื’ื™ืขื•ืช ืื™ื ื” ืฉื•ืœืœ ื™ืฆื™ืจืช ื ื™ืฆื•ืœ ืฉืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ืงื•ื“ ืขื•ืงืฃ ืื™ืžื•ืช ืืชื—ื•ืœ ืžืื•ื‘ื˜ื—.
  • CVE-2020-25647 ื›ืชื™ื‘ื” ืžื—ื•ืฅ ืœืชื—ื•ื ื‘ืคื•ื ืงืฆื™ื” grub_usb_device_initialize() ื”ื ืงืจืืช ื‘ืขืช ืืชื—ื•ืœ ื”ืชืงื ื™ USB. ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ื‘ืขื™ื” ืขืœ ื™ื“ื™ ื—ื™ื‘ื•ืจ ื”ืชืงืŸ USB ืฉื”ื•ื›ืŸ ื‘ืžื™ื•ื—ื“ ื”ืžื™ื™ืฆืจ ืคืจืžื˜ืจื™ื ืฉื’ื•ื“ืœื ืื™ื ื• ืžืชืื™ื ืœื’ื•ื“ืœ ื”ืžืื’ืจ ื”ืžื•ืงืฆื” ืœืžื‘ื ื™ USB. ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืฉืœ ืงื•ื“ ืฉืื™ื ื• ืžืื•ืžืช ื‘ืืชื—ื•ืœ ืžืื•ื‘ื˜ื— ืขืœ ื™ื“ื™ ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ื”ืชืงื ื™ USB.
  • CVE-2020-27749 ื”ื•ื ื’ืœื™ืฉืช ืžืื’ืจ ื‘ืคื•ื ืงืฆื™ื” grub_parser_split_cmdline() ืืฉืจ ื™ื›ื•ืœื” ืœื”ื™ื’ืจื ืขืœ ื™ื“ื™ ืฆื™ื•ืŸ ืžืฉืชื ื™ื ื’ื“ื•ืœื™ื ืž-2 KB ื‘ืฉื•ืจืช ื”ืคืงื•ื“ื” GRUB1. ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœื‘ื™ืฆื•ืข ืงื•ื“ ืœืขืงื•ืฃ ืืช ืืชื—ื•ืœ ืžืื•ื‘ื˜ื—.
  • CVE-2020-27779 โ€“ ื”ืคืงื•ื“ื” cutmem ืžืืคืฉืจืช ืœืชื•ืงืฃ ืœื”ืกื™ืจ ืžื’ื•ื•ืŸ ื›ืชื•ื‘ื•ืช ืžื”ื–ื™ื›ืจื•ืŸ ื›ื“ื™ ืœืขืงื•ืฃ ืืช ื”ืืชื—ื•ืœ ื”ืžืื•ื‘ื˜ื—.
  • CVE-2021-3418 - ืฉื™ื ื•ื™ื™ื ื‘-shim_lock ื™ืฆืจื• ื•ืงื˜ื•ืจ ื ื•ืกืฃ ื›ื“ื™ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ืฉืœ ื”ืฉื ื” ืฉืขื‘ืจื” CVE-2020-15705. ืขืœ ื™ื“ื™ ื”ืชืงื ืช ื”ืื™ืฉื•ืจ ื”ืžืฉืžืฉ ืœื—ืชื™ืžื” ืขืœ GRUB2 ื‘-dbx, GRUB2 ืืคืฉืจ ืœื˜ืขื•ืŸ ื›ืœ ืœื™ื‘ื” ื™ืฉื™ืจื•ืช ืžื‘ืœื™ ืœืืžืช ืืช ื”ื—ืชื™ืžื”.
  • CVE-2021-20225 - ืืคืฉืจื•ืช ืœื›ืชื™ื‘ืช ื ืชื•ื ื™ื ืžื—ื•ืฅ ืœืชื—ื•ื ื‘ืขืช ื”ืคืขืœืช ืคืงื•ื“ื•ืช ืขื ืžืกืคืจ ืจื‘ ืžืื•ื“ ืฉืœ ืืคืฉืจื•ื™ื•ืช.
  • CVE-2021-20233 - ืืคืฉืจื•ืช ืœื›ืชื™ื‘ืช ื ืชื•ื ื™ื ืžื—ื•ืฅ ืœืชื—ื•ื ืขืงื‘ ื—ื™ืฉื•ื‘ ืฉื’ื•ื™ ืฉืœ ื’ื•ื“ืœ ืžืื’ืจ ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืžื™ืจื›ืื•ืช. ื‘ืขืช ื—ื™ืฉื•ื‘ ื”ื’ื•ื“ืœ, ื”ื•ื ื—ื” ื›ื™ ื ื“ืจืฉื• ืฉืœื•ืฉ ืชื•ื•ื™ื ื›ื“ื™ ืœื‘ืจื•ื— ืžืžืจื›ืื” ื‘ื•ื“ื“ืช, ื›ืืฉืจ ืœืžืขืฉื” ื ื“ืจืฉื• ืืจื‘ืขื”.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”