ื™ืฉื ื” ืคื’ื™ืขื•ืช ื‘-Glibc ืฉืžืืคืฉืจืช ืœืชื”ืœื™ืš ืฉืœ ืžื™ืฉื”ื• ืื—ืจ ืœืงืจื•ืก

ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช (CVE-2021-38604) ื‘-Glibc, ื”ืžืืคืฉืจืช ืœื™ื–ื•ื ืงืจื™ืกืช ืชื”ืœื™ื›ื™ื ื‘ืžืขืจื›ืช ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื”ื•ื“ืขื” ืฉืชื•ื›ื ื ื” ื‘ืžื™ื•ื—ื“ ื“ืจืš ื”-API ืฉืœ POSIX message queues. ื”ื‘ืขื™ื” ืขื“ื™ื™ืŸ ืœื ื”ื•ืคื™ืขื” ื‘ื”ืคืฆื•ืช, ืžื›ื™ื•ื•ืŸ ืฉื”ื™ื ืงื™ื™ืžืช ืจืง ื‘ืžื”ื“ื•ืจื” 2.34, ืฉืคื•ืจืกืžื” ืœืคื ื™ ืฉื‘ื•ืขื™ื™ื.

ื”ื‘ืขื™ื” ื ื’ืจืžืช ืžื˜ื™ืคื•ืœ ืฉื’ื•ื™ ื‘ื ืชื•ื ื™ NOTIFY_REMOVED ื‘ืงื•ื“ mq_notify.c, ืžื” ืฉืžื•ื‘ื™ืœ ืœื”ืคื ื™ื™ืช ืžืฆื‘ื™ืข NULL ื•ืœืงืจื™ืกืช ืชื”ืœื™ืš. ืžืขื ื™ื™ืŸ ืœืฆื™ื™ืŸ ืฉื”ื‘ืขื™ื” ื”ื™ื ืชื•ืฆืื” ืฉืœ ืคื’ื ื‘ืชื™ืงื•ืŸ ืคื’ื™ืขื•ืช ื ื•ืกืคืช (CVE-2021-33574), ืฉืชื•ืงืŸ ื‘ืžื”ื“ื•ืจืช Glibc 2.34. ื™ืชืจื” ืžื›ืš, ืื ื”ืคื’ื™ืขื•ืช ื”ืจืืฉื•ื ื” ื”ื™ื™ืชื” ื“ื™ ืงืฉื” ืœื ื™ืฆื•ืœ ื•ื”ืฆืจื™ื›ื” ืฉื™ืœื•ื‘ ืฉืœ ื ืกื™ื‘ื•ืช ืžืกื•ื™ืžื•ืช, ืื– ื”ืจื‘ื” ื™ื•ืชืจ ืงืœ ืœื‘ืฆืข ื”ืชืงืคื” ื‘ืืžืฆืขื•ืช ื”ื‘ืขื™ื” ื”ืฉื ื™ื™ื”.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”