ืคื’ื™ืขื•ืช ื‘ืชืช-ืžืขืจื›ืช netfilter ื”ืžืืคืฉืจืช ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืจืžืช ืœื™ื‘ืช ืœื™ื ื•ืงืก

ืœ-Netfilter, ืชืช-ืžืขืจื›ืช ืฉืœ ืœื™ื‘ืช ืœื™ื ื•ืงืก ื”ืžืฉืžืฉืช ืœืกื™ื ื•ืŸ ื•ืฉื™ื ื•ื™ ืžื ื•ืช ืจืฉืช, ื™ืฉื ื” ืคื’ื™ืขื•ืช (CVE-2022-25636) ื”ืžืืคืฉืจืช ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืจืžืช ื”ืœื™ื‘ื”. ื”ื•ื›ืจื– ื›ื™ ื”ื•ื›ื ื” ื“ื•ื’ืžื” ืœื ื™ืฆื•ืœ ื”ืžืืคืฉืจ ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœื”ืขืœื•ืช ืืช ื”ื”ืจืฉืื•ืช ืฉืœื• ื‘ืื•ื‘ื•ื ื˜ื• 21.10 ื›ืืฉืจ ืžื ื’ื ื•ืŸ ื”ื”ื’ื ื” KASLR ืžื•ืฉื‘ืช. ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ื”ื—ืœ ืžื’ืจืขื™ืŸ 5.4. ื”ืชื™ืงื•ืŸ ืขื“ื™ื™ืŸ ื–ืžื™ืŸ ื›ืชื™ืงื•ืŸ (ืžื”ื“ื•ืจื•ืช ืœื™ื‘ื” ืžืชืงื ื•ืช ืœื ื ื•ืฆืจื•). ืืชื” ื™ื›ื•ืœ ืœืขืงื•ื‘ ืื—ืจ ื”ืคืจืกื•ืžื™ื ืฉืœ ืขื“ื›ื•ื ื™ ื—ื‘ื™ืœื•ืช ื‘ื”ืคืฆื•ืช ื‘ื“ืคื™ื ืืœื”: Debian, SUSE, Ubuntu, RHEL, Fedora, Gentoo, Arch Linux.

ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืžืฉื’ื™ืื” ื‘ื—ื™ืฉื•ื‘ ื’ื•ื“ืœ ืžืขืจืš flow->rule->action.entries ื‘ืคื•ื ืงืฆื™ื™ืช nft_fwd_dup_netdev_offload (ืžื•ื’ื“ืจืช ื‘ืงื•ื‘ืฅ net/netfilter/nf_dup_netdev.c), ืžื” ืฉืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœื ืชื•ื ื™ื ื‘ืฉืœื™ื˜ืช ืชื•ืงืฃ. ื ื›ืชื‘ ืœืื–ื•ืจ ื–ื™ื›ืจื•ืŸ ืžืขื‘ืจ ืœื’ื‘ื•ืœ ื”ืžืื’ืจ ื”ืžื•ืงืฆื”. ื”ืฉื’ื™ืื” ืžื•ืคื™ืขื” ื‘ืขืช ื”ื’ื“ืจืช ื›ืœืœื™ "dup" ื•-"fwd" ื‘ืฉืจืฉืจื•ืช ืฉืขื‘ื•ืจืŸ ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื”ืืฆืช ื—ื•ืžืจื” ืฉืœ ืขื™ื‘ื•ื“ ืžื ื•ืช (offload). ืžื›ื™ื•ื•ืŸ ืฉื”ื’ืœื™ืฉื” ืžืชืจื—ืฉืช ืœืคื ื™ ื™ืฆื™ืจืช ื›ืœืœ ืžืกื ืŸ ืžื ื•ืช ื•ื‘ื“ื™ืงืช ืชืžื™ื›ื” ื‘-offload, ื”ืคื’ื™ืขื•ืช ื—ืœื” ื’ื ืขืœ ื”ืชืงื ื™ ืจืฉืช ืฉืื™ื ื ืชื•ืžื›ื™ื ื‘ื”ืืฆืช ื—ื•ืžืจื”, ื›ื’ื•ืŸ ืžืžืฉืง loopback.

ื™ืฉ ืœืฆื™ื™ืŸ ืฉื”ื‘ืขื™ื” ื“ื™ ืคืฉื•ื˜ื” ืœื ื™ืฆื•ืœ, ืฉื›ืŸ ืขืจื›ื™ื ื”ื—ื•ืจื’ื™ื ืžื”ืžืื’ืจ ื™ื›ื•ืœื™ื ืœื“ืจื•ืก ืืช ื”ืžืฆื‘ื™ืข ืœืžื‘ื ื” net_device, ื•ื ืชื•ื ื™ื ืขืœ ื”ืขืจืš ืฉื”ื•ื—ืœืฃ ืžื•ื—ื–ืจื™ื ืœืžืจื—ื‘ ื”ืžืฉืชืžืฉ, ืžื” ืฉืžืืคืฉืจ ืœืš ืœื’ืœื•ืช ืืช ื”ื›ืชื•ื‘ื•ืช ื‘ื–ื™ื›ืจื•ืŸ ื”ื“ืจื•ืฉ ืœื‘ื™ืฆื•ืข ื”ืคื™ื’ื•ืข. ื ื™ืฆื•ืœ ื”ืคื’ื™ืขื•ืช ืžืฆืจื™ืš ื™ืฆื™ืจืช ื›ืœืœื™ื ืžืกื•ื™ืžื™ื ื‘-nftables, ืžื” ืฉืžืชืืคืฉืจ ืจืง ืขื ื”ืจืฉืื•ืช CAP_NET_ADMIN, ืฉื ื™ืชืŸ ืœื”ืฉื™ื’ ืขืœ ื™ื“ื™ ืžืฉืชืžืฉ ื—ืกืจ ื”ืจืฉืื•ืช ื‘ืžืจื—ื‘ื™ ืฉืžื•ืช ื ืคืจื“ื™ื ื‘ืจืฉืช. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืคื’ื™ืขื•ืช ื’ื ื›ื“ื™ ืœืชืงื•ืฃ ืžืขืจื›ื•ืช ื‘ื™ื“ื•ื“ ืงื•ื ื˜ื™ื™ื ืจื™ื.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”