ืคื’ื™ืขื•ืช ื‘-CRI-O ื”ืžืืคืฉืจืช ื’ื™ืฉืช ืฉื•ืจืฉ ืœืกื‘ื™ื‘ืช ื”ืžืืจื—

ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช (CVE-2022-0811) ื–ื•ื”ืชื” ื‘-CRI-O, ื–ืžืŸ ืจื™ืฆื” ืœื ื™ื”ื•ืœ ืงื•ื ื˜ื™ื™ื ืจื™ื ืžื‘ื•ื“ื“ื™ื, ื”ืžืืคืฉืจ ืœืš ืœืขืงื•ืฃ ืืช ื”ื‘ื™ื“ื•ื“ ื•ืœื”ืคืขื™ืœ ืืช ื”ืงื•ื“ ืฉืœืš ื‘ืฆื“ ื”ืžืขืจื›ืช ื”ืžืืจื—ืช. ืื ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘-CRI-O ื‘ืžืงื•ื containerd ื•-Docker ื›ื“ื™ ืœื”ืคืขื™ืœ ืงื•ื ื˜ื™ื™ื ืจื™ื ื”ืคื•ืขืœื™ื ืชื—ืช ืคืœื˜ืคื•ืจืžืช Kubernetes, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืฉื™ื’ ืฉืœื™ื˜ื” ืขืœ ื›ืœ ืฆื•ืžืช ื‘ืืฉื›ื•ืœ Kubernetes. ื›ื“ื™ ืœื‘ืฆืข ื”ืชืงืคื”, ื™ืฉ ืœืš ืจืง ืžืกืคื™ืง ื–ื›ื•ื™ื•ืช ืœื”ืคืขื™ืœ ืืช ื”ืžื™ื›ืœ ืฉืœืš ื‘ืืฉื›ื•ืœ Kubernetes.

ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ื›ืชื•ืฆืื” ืžื”ืืคืฉืจื•ืช ืœืฉื ื•ืช ืืช ื”ืคืจืžื˜ืจ sysctl kernel "kernel.core_pattern" ("/proc/sys/kernel/core_pattern"), ืฉื”ื’ื™ืฉื” ืืœื™ื• ืœื ื ื—ืกืžื”, ืœืžืจื•ืช ื”ืขื•ื‘ื“ื” ืฉื”ื•ื ืื™ื ื• ื‘ื™ืŸ ื”ืคืจืžื˜ืจื™ื ื”ื‘ื˜ื•ื—ื™ื ืœ- ืฉื™ื ื•ื™, ืชืงืฃ ืจืง ื‘ืžืจื—ื‘ ื”ืฉืžื•ืช ืฉืœ ื”ืžื›ื•ืœื” ื”ื ื•ื›ื—ื™ืช. ื‘ืืžืฆืขื•ืช ืคืจืžื˜ืจ ื–ื”, ืžืฉืชืžืฉ ืžืžื™ื›ืœ ื™ื›ื•ืœ ืœืฉื ื•ืช ืืช ื”ื”ืชื ื”ื’ื•ืช ืฉืœ ืœื™ื‘ืช ืœื™ื ื•ืงืก ื‘ื™ื—ืก ืœืขื™ื‘ื•ื“ ืงื‘ืฆื™ ืœื™ื‘ื” ื‘ืฆื“ ืฉืœ ืกื‘ื™ื‘ืช ื”ืžืืจื— ื•ืœืืจื’ืŸ ืืช ื”ื”ืฉืงื” ืฉืœ ืคืงื•ื“ื” ืฉืจื™ืจื•ืชื™ืช ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ ื‘ืฆื“ ื”ืžืืจื— ืขืœ ื™ื“ื™ ืฆื™ื•ืŸ ืžื˜ืคืœ ื›ืžื• "|/bin/sh -c 'ืคืงื•ื“ื•ืช'" .

ื”ื‘ืขื™ื” ืงื™ื™ืžืช ืžืื– ืฉื—ืจื•ืจื• ืฉืœ CRI-O 1.19.0 ื•ืชื•ืงื ื” ื‘ืขื“ื›ื•ื ื™ื 1.19.6, 1.20.7, 1.21.6, 1.22.3, 1.23.2 ื•-1.24.0. ื‘ื™ืŸ ื”ื”ืคืฆื•ืช, ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ื‘-Red Hat OpenShift Container Platform ื•ื‘ืžื•ืฆืจื™ openSUSE/SUSE, ืืฉืจ ื‘ืžืื’ืจื™ื ืฉืœื”ื ื™ืฉ ืืช ื—ื‘ื™ืœืช cri-o.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”