ืคื’ื™ืขื•ืช ื‘ืชืช-ืžืขืจื›ืช io_uring ื”ืžื•ื‘ื™ืœื” ืœื”ืกืœืžื” ืฉืœ ื”ืจืฉืื•ืช

ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช (CVE-5.1-2022) ื‘ื”ื˜ืžืขืช ืžืžืฉืง ื”ืงืœื˜/ืคืœื˜ ื”ืืกื™ื ื›ืจื•ื ื™ io_uring, ื”ื›ืœื•ืœ ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก ืžืื– ื’ืจืกื” 3910, ื”ืžืืคืฉืจ ืœืžืฉืชืžืฉ ื—ืกืจ ื”ืจืฉืื•ืช ืœื‘ืฆืข ืงื•ื“ ืขื ื”ืจืฉืื•ืช ืœื™ื‘ื”. ื”ื‘ืขื™ื” ื”ื•ืคื™ืขื” ื‘ืžื”ื“ื•ืจื•ืช 5.18 ื•-5.19, ื•ืชื•ืงื ื” ื‘ืขื ืฃ 6.0. ื“ื‘ื™ืืŸ, RHEL ื•-SUSE ืžืฉืชืžืฉื•ืช ื‘ืžื”ื“ื•ืจื•ืช ืœื™ื‘ื” ืขื“ 5.18, ืคื“ื•ืจื”, ื’'ื ื˜ื• ื•-Arch ื›ื‘ืจ ืžืฆื™ืขื•ืช ืœื™ื‘ื” 6.0. ืื•ื‘ื•ื ื˜ื• 22.10 ืžืฉืชืžืฉ ื‘ืœื™ื‘ืช 5.19 ื”ืคื’ื™ืขื”.

ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื’ื™ืฉื” ืœื‘ืœื•ืง ื–ื™ื›ืจื•ืŸ ืžืฉื•ื—ืจืจ ื›ื‘ืจ (use-after-free) ื‘ืชืช-ืžืขืจื›ืช io_uring, ื”ืงืฉื•ืจื” ืœืขื“ื›ื•ืŸ ืฉื’ื•ื™ ืฉืœ ืžื•ื ื” ื”ืคื ื™ื•ืช - ื‘ืขืช ืงืจื™ืื” ืœ-io_msg_ring() ืขื ืงื•ื‘ืฅ ืงื‘ื•ืข (ื ืžืฆื ื‘ืื•ืคืŸ ืงื‘ื•ืข ื‘ืžืื’ืจ ื”ื˜ื‘ืขื•ืช), ื”ืคื•ื ืงืฆื™ื” io_fput_file() ื ืงืจืืช ื‘ื˜ืขื•ืช ืชื•ืš ื”ืคื—ืชืช ืกืคื™ืจืช ื”ืคื ื™ื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”