ืคื’ื™ืขื•ืช ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ ืฉืœ vhost-net ืžืงืจื ืœ ืœื™ื ื•ืงืก

ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ vhost-net, ื”ืžื‘ื˜ื™ื— ืืช ืคืขื•ืœืช virtio net ื‘ืฆื“ ื”ืกื‘ื™ื‘ื” ื”ืžืืจื—ืช, ืžื–ื•ื”ื” ืคื’ื™ืขื•ืช (CVE-2020-10942), ื”ืžืืคืฉืจ ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœื™ื–ื•ื ื”ืฆืคืช ืžื—ืกื ื™ืช ืœื™ื‘ื” ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ioctl(VHOST_NET_SET_BACKEND) ื‘ืคื•ืจืžื˜ ืžื™ื•ื—ื“ ืœืžื›ืฉื™ืจ /dev/vhost-net. ื”ื‘ืขื™ื” ื ื’ืจืžืช ืžื”ื™ืขื“ืจ ืื™ืžื•ืช ืชืงื™ืŸ ืฉืœ ืชื•ื›ืŸ ื”ืฉื“ื” sk_family ื‘ืงื•ื“ ื”ืคื•ื ืงืฆื™ื” get_raw_socket() .

ืขืœ ืคื™ ื ืชื•ื ื™ื ืจืืฉื•ื ื™ื™ื, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืคื’ื™ืขื•ืช ืœื‘ื™ืฆื•ืข ืžืชืงืคืช DoS ืžืงื•ืžื™ืช ืขืœ ื™ื“ื™ ื’ืจื™ืžืช ืงืจื™ืกืช ืœื™ื‘ื” (ืื™ืŸ ืžื™ื“ืข ืขืœ ื”ืฉื™ืžื•ืฉ ื‘-Stack overflow ืฉื ื’ืจื ืžื”ืคื’ื™ืขื•ืช ืœืืจื’ื•ืŸ ื‘ื™ืฆื•ืข ืงื•ื“).
ืคื’ื™ืขื•ืช ื—ื•ืกืœื• ื‘ืขื“ื›ื•ืŸ ืœื™ื‘ืช ืœื™ื ื•ืงืก 5.5.8. ืขื‘ื•ืจ ื”ืคืฆื•ืช, ืืชื” ื™ื›ื•ืœ ืœืขืงื•ื‘ ืื—ืจ ืฉื—ืจื•ืจ ืขื“ื›ื•ื ื™ ื”ื—ื‘ื™ืœื•ืช ื‘ื“ืคื™ื ื“ื‘ื™ืืŸ, ืื•ื‘ื•ื ื˜ื•, ืจื”ืœ, SUSE/openSUSE, ืคื“ื•ืจื”, ืงืฉืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”