ืคื’ื™ืขื•ืช ื‘ืžื•ื“ื•ืœื™ื ืืœื—ื•ื˜ื™ื™ื ืฉืœ Samsung Exynos ื”ืžื ื•ืฆืœื™ื ื“ืจืš ื”ืื™ื ื˜ืจื ื˜

ื—ื•ืงืจื™ื ืžืฆื•ื•ืช Google Project Zero ื“ื™ื•ื•ื—ื• ืขืœ ื’ื™ืœื•ื™ ืฉืœ 18 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืžื•ื“ืžื™ื ืฉืœ Samsung Exynos 5G/LTE/GSM. ืืจื‘ืข ื”ืคื’ื™ืขื•ื™ื•ืช ื”ืžืกื•ื›ื ื•ืช ื‘ื™ื•ืชืจ (CVE-2023-24033) ืžืืคืฉืจื•ืช ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืจืžืช ืฉื‘ื‘ ืคืก ื”ื‘ืกื™ืก ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ืžืจืฉืชื•ืช ืื™ื ื˜ืจื ื˜ ื—ื™ืฆื•ื ื™ื•ืช. ืœื“ื‘ืจื™ ื ืฆื™ื’ื™ Google Project Zero, ืœืื—ืจ ืžื—ืงืจ ืงื˜ืŸ ื ื•ืกืฃ, ืชื•ืงืคื™ื ืžื•ืกืžื›ื™ื ื™ื•ื›ืœื• ืœื”ื›ื™ืŸ ื‘ืžื”ื™ืจื•ืช ื ื™ืฆื•ืœ ืขื•ื‘ื“ ื”ืžืืคืฉืจ ืœื”ืฉื™ื’ ืฉืœื™ื˜ื” ืžืจื—ื•ืง ื‘ืจืžืช ื”ืžื•ื“ื•ืœ ื”ืืœื—ื•ื˜ื™, ื‘ื™ื“ื™ืขื” ืจืง ืืช ืžืกืคืจ ื”ื˜ืœืคื•ืŸ ืฉืœ ื”ืงื•ืจื‘ืŸ. ื”ื”ืชืงืคื” ื™ื›ื•ืœื” ืœื”ืชื‘ืฆืข ืœืœื ืชืฉื•ืžืช ืœื‘ ืœืžืฉืชืžืฉ ื•ืื™ื ื” ืžื—ื™ื™ื‘ืช ืื•ืชื• ืœื‘ืฆืข ื›ืœ ืคืขื•ืœื”.

ืœืฉืืจ 14 ื”ืคื’ื™ืขื•ื™ื•ืช ื™ืฉ ืจืžืช ื—ื•ืžืจื” ื ืžื•ื›ื” ื™ื•ืชืจ, ืžืื—ืจ ืฉื”ืžืชืงืคื” ื“ื•ืจืฉืช ื’ื™ืฉื” ืœืชืฉืชื™ืช ืฉืœ ืžืคืขื™ืœ ื”ืจืฉืช ื”ืกืœื•ืœืจื™ืช ืื• ื’ื™ืฉื” ืžืงื•ืžื™ืช ืœืžื›ืฉื™ืจ ื”ืžืฉืชืžืฉ. ืœืžืขื˜ ื”ืคื’ื™ืขื•ืช CVE-2023-24033, ืฉืชื™ืงื•ืŸ ืขื‘ื•ืจื” ื”ื•ืฆืข ื‘ืขื“ื›ื•ืŸ ื”ืงื•ืฉื—ื” ืฉืœ ืžืจืฅ ืขื‘ื•ืจ ืžื›ืฉื™ืจื™ Google Pixel, ื”ื‘ืขื™ื•ืช ื ื•ืชืจื• ืœืœื ืชื™ืงื•ืŸ. ื”ื“ื‘ืจ ื”ื™ื—ื™ื“ ื”ื™ื“ื•ืข ืขืœ ื”ืคื’ื™ืขื•ืช ืฉืœ CVE-2023-24033 ื”ื•ื ืฉื”ื™ื ื ื’ืจืžืช ืžื‘ื“ื™ืงื” ืฉื’ื•ื™ื” ืฉืœ ื”ืคื•ืจืžื˜ ืฉืœ ืชื›ื•ื ืช "accept-type" ื”ืžืฉื•ื“ืจืช ื‘ื”ื•ื“ืขื•ืช SDP (Session Description Protocol).

ืขื“ ืฉื”ืคื’ื™ืขื•ื™ื•ืช ื™ืชื•ืงื ื• ืขืœ ื™ื“ื™ ื”ื™ืฆืจื ื™ื, ืžื•ืžืœืฅ ืœืžืฉืชืžืฉื™ื ืœื”ืฉื‘ื™ืช ืืช ืชืžื™ื›ืช VoLTE (Voice-over-LTE) ื•ืืช ืคื•ื ืงืฆื™ื™ืช ื”ื”ืชืงืฉืจื•ืช ื‘ืืžืฆืขื•ืช Wi-Fi ื‘ื”ื’ื“ืจื•ืช. ืคื’ื™ืขื•ื™ื•ืช ืžืชื‘ื˜ืื•ืช ื‘ืžื›ืฉื™ืจื™ื ื”ืžืฆื•ื™ื“ื™ื ื‘ืฉื‘ื‘ื™ Exynos, ืœืžืฉืœ, ื‘ืกืžืืจื˜ืคื•ื ื™ื ืฉืœ ืกืžืกื•ื ื’ (S22, M33, M13, M12, A71, A53, A33, A21, A13, A12 ื•-A04), Vivo (S16, S15, S6, X70, X60 ื•-X30), Google Pixel (6 ื•-7), ื›ืžื• ื’ื ืžื›ืฉื™ืจื™ื ืœื‘ื™ืฉื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ ืขืจื›ืช ื”ืฉื‘ื‘ื™ื Exynos W920 ื•ืžืขืจื›ื•ืช ืจื›ื‘ ืขื ืฉื‘ื‘ Exynos Auto T5123.

ื‘ืฉืœ ืกื›ื ืช ื”ืคื’ื™ืขื•ืช ื•ื”ืžืฆื™ืื•ืชื™ื•ืช ืฉืœ ื”ื•ืคืขืชื• ื”ืžื”ื™ืจื” ืฉืœ ื ื™ืฆื•ืœ, ื’ื•ื’ืœ ื”ื—ืœื™ื˜ื” ืœืขืฉื•ืช ื—ืจื™ื’ ืขื‘ื•ืจ 4 ื”ื‘ืขื™ื•ืช ื”ืžืกื•ื›ื ื•ืช ื‘ื™ื•ืชืจ ื•ืœื“ื—ื•ืช ืืช ื—ืฉื™ืคืช ื”ืžื™ื“ืข ืขืœ ืื•ืคื™ ื”ื‘ืขื™ื•ืช. ืขื‘ื•ืจ ืฉืืจ ื”ืคื’ื™ืขื•ื™ื•ืช, ืœื•ื— ื”ื–ืžื ื™ื ืฉืœ ื—ืฉื™ืคืช ื”ืคืจื˜ื™ื ื™ืชื‘ืฆืข 90 ื™ื•ื ืœืื—ืจ ืงื‘ืœืช ื”ื•ื“ืขื” ืœื™ืฆืจืŸ (ืžื™ื“ืข ืขืœ ืคืจืฆื•ืช CVE-2023-26072, CVE-2023-26073, CVE-2023-26074, CVE-2023-26075 ื•-CVE -2023-26076 ื›ื‘ืจ ื–ืžื™ืŸ ื‘ืžืขืจื›ืช ืžืขืงื‘ ืื—ืจ ื‘ืื’ื™ื, ื•ืขื‘ื•ืจ 9 ื”ื‘ืขื™ื•ืช ื”ื ื•ืชืจื•ืช, ื”ืžืชื ื” ืฉืœ 90 ื™ื•ื ื˜ืจื ืคื’). ื”ืคื’ื™ืขื•ื™ื•ืช ื”ืžื“ื•ื•ื—ื•ืช CVE-2023-2607* ื ื’ืจืžื•ืช ืขืœ ื™ื“ื™ ื”ืฆืคืช ืžืื’ืจ ื‘ืขืช ืคืขื ื•ื— ืืคืฉืจื•ื™ื•ืช ื•ืจืฉื™ืžื•ืช ืžืกื•ื™ืžื•ืช ื‘-Codec NrmmMsgCodec ื•- NrSmPcoCodec.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”