ืคื’ื™ืขื•ืช ื‘-vhost-net ื”ืžืืคืฉืจืช ืžืขืงืฃ ื‘ื™ื“ื•ื“ ื‘ืžืขืจื›ื•ืช ื”ืžื‘ื•ืกืกื•ืช ืขืœ QEMU-KVM

ื’ื™ืœื” ืžื™ื“ืข ืขืœ ืคื’ื™ืขื•ืช (CVE-2019-14835), ื”ืžืืคืฉืจ ืœืš ืœืขื‘ื•ืจ ืžืขื‘ืจ ืœืžืขืจื›ืช ื”ืื•ืจื—ืช ื‘-KVM (qemu-kvm) ื•ืœื”ืจื™ืฅ ืืช ื”ืงื•ื“ ืฉืœืš ื‘ืฆื“ ืฉืœ ืกื‘ื™ื‘ืช ื”ืžืืจื—ืช ื‘ื”ืงืฉืจ ืฉืœ ืœื™ื‘ืช ืœื™ื ื•ืงืก. ื”ืคื’ื™ืขื•ืช ืงื™ื‘ืœื” ืืช ืฉื ื”ืงื•ื“ V-gHost. ื”ื‘ืขื™ื” ืžืืคืฉืจืช ืœืžืขืจื›ืช ื”ืื•ืจื—ืช ืœื™ืฆื•ืจ ืชื ืื™ื ืœื”ืฆืคืช ื—ื•ืฆืฅ ื‘ืžื•ื“ื•ืœ ืœื™ื‘ืช vhost-net (ื’ื‘ื™ ืจืฉืช ืขื‘ื•ืจ virtio), ื”ืžื‘ื•ืฆืข ื‘ืฆื“ ืฉืœ ืกื‘ื™ื‘ืช ื”ืžืืจื—. ื”ื”ืชืงืคื” ื™ื›ื•ืœื” ืœื”ืชื‘ืฆืข ืขืœ ื™ื“ื™ ืชื•ืงืฃ ืขื ื’ื™ืฉื” ืžื•ืกืžื›ืช ืœืžืขืจื›ืช ื”ืื•ืจื—ืช ื‘ืžื”ืœืš ืคืขื•ืœืช ื”ืขื‘ืจืช ืžื—ืฉื‘ ื•ื™ืจื˜ื•ืืœื™.

ืชื™ืงื•ืŸ ื”ื‘ืขื™ื” ื›ืœื•ืœ ื›ืœื•ืœ ื‘ืœื™ื‘ืช Linux 5.3. ื›ืคืชืจื•ืŸ ืขื•ืงืฃ ืœื—ืกื™ืžืช ื”ืคื’ื™ืขื•ืช, ืืชื” ื™ื›ื•ืœ ืœื”ืฉื‘ื™ืช ืืช ื”ื”ื’ื™ืจื” ื‘ื–ืžืŸ ืืžืช ืฉืœ ืžืขืจื›ื•ืช ืื•ืจื—ื™ื ืื• ืœื”ืฉื‘ื™ืช ืืช ืžื•ื“ื•ืœ vhost-net (ื”ื•ืกืฃ "blacklist vhost-net" ืœ-/etc/modprobe.d/blacklist.conf). ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ื”ื—ืœ ืžื’ืจืกืช ืœื™ื ื•ืงืก 2.6.34. ื”ืคื’ื™ืขื•ืช ืชื•ืงื ื” ื‘ ืื•ื‘ื•ื ื˜ื• ะธ ืคื“ื•ืจื”, ืื‘ืœ ืขื“ื™ื™ืŸ ืœื ืžืชื•ืงืŸ ื‘ ื“ื‘ื™ืืŸ, Arch Linux, SUSE ะธ ืจื”ืœ.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”