ืคื’ื™ืขื•ืช ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก ื”ืžืืคืฉืจืช ืœืš ืœืขืงื•ืฃ ืืช ื”ื’ื‘ืœื•ืช ืžืฆื‘ ื”ื ืขื™ืœื”

ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก (CVE-2022-21505) ื”ืžืืคืฉืจืช ืœืขืงื•ืฃ ื‘ืงืœื•ืช ืืช ืžื ื’ื ื•ืŸ ื”ืื‘ื˜ื—ื” ืฉืœ Lockdown, ื”ืžื’ื‘ื™ืœ ืืช ื’ื™ืฉืช ืžืฉืชืžืฉื™ ื”ืฉื•ืจืฉ ืœืœื™ื‘ื” ื•ื—ื•ืกื ื ืชื™ื‘ื™ ืขืงื™ืคืช UEFI Secure Boot. ื›ื“ื™ ืœืขืงื•ืฃ ืื•ืชื•, ืžื•ืฆืข ืœื”ืฉืชืžืฉ ื‘ืชืช-ืžืขืจื›ืช ื”ืงืจื ืœ IMA (Integrity Measurement Architecture), ืฉื ื•ืขื“ื” ืœืืžืช ืืช ืชืงื™ื ื•ืชื ืฉืœ ืจื›ื™ื‘ื™ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื‘ืืžืฆืขื•ืช ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ื•-hash.

ืžืฆื‘ ื ืขื™ืœื” ืžื’ื‘ื™ืœ ืืช ื”ื’ื™ืฉื” ืœ-/dev/mem, /dev/kmem, /dev/port, /proc/kcore, debugfs, kprobes mode debug, mmiotrace, tracefs, BPF, PCMCIA CIS (ืžื‘ื ื” ืžื™ื“ืข ื›ืจื˜ื™ืก), ื›ืžื” ืžืžืฉืงื™ ACPI ื•-CPU ืื•ื’ืจื™ MSR, ืฉื™ื—ื•ืช kexec_file ื•-kexec_load ื—ืกื•ืžื•ืช, ืžืฆื‘ ืฉื™ื ื” ืืกื•ืจ, ื”ืฉื™ืžื•ืฉ ื‘-DMA ืขื‘ื•ืจ ื”ืชืงื ื™ PCI ืžื•ื’ื‘ืœ, ื™ื‘ื•ื ืงื•ื“ ACPI ืžืžืฉืชื ื™ EFI ืืกื•ืจ, ืžื ื™ืคื•ืœืฆื™ื•ืช ืขื ื™ืฆื™ืื•ืช I/O ืื™ื ืŸ ืžื•ืชืจื•ืช, ื›ื•ืœืœ ืฉื™ื ื•ื™ ืžืกืคืจ ื”ืคืกื™ืงื” ื•ื™ืฆื™ืื” I /O ืขื‘ื•ืจ ื™ืฆื™ืื” ื˜ื•ืจื™ืช.

ืžื”ื•ืช ื”ืคื’ื™ืขื•ืช ื”ื™ื ืฉื›ืืฉืจ ืžืฉืชืžืฉื™ื ื‘ืคืจืžื˜ืจ ื”ืืชื—ื•ืœ "ima_appraise=log", ืืคืฉืจ ืœืงืจื•ื ืœ-kexec ื›ื“ื™ ืœื˜ืขื•ืŸ ืขื•ืชืง ื—ื“ืฉ ืฉืœ ื”ืœื™ื‘ื” ืื ืžืฆื‘ ื”ืืชื—ื•ืœ ื”ืžืื•ื‘ื˜ื— ืื™ื ื• ืคืขื™ืœ ื‘ืžืขืจื›ืช ื•ืžืฆื‘ ื”ื ืขื™ืœื” ืžืฉืžืฉ ื‘ื ืคืจื“ ืžื–ื”. IMA ืื™ื ื” ืžืืคืฉืจืช ืืช ื”ืคืขืœืช ืžืฆื‘ "ima_appraise" ื›ืืฉืจ ืืชื—ื•ืœ ืžืื•ื‘ื˜ื— ืคืขื™ืœ, ืืš ืื™ื ื” ืœื•ืงื—ืช ื‘ื—ืฉื‘ื•ืŸ ืืช ื”ืืคืฉืจื•ืช ืฉืœ ืฉื™ืžื•ืฉ ื‘ื ืขื™ืœื” ื‘ื ืคืจื“ ืžืืชื—ื•ืœ ืžืื•ื‘ื˜ื—.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”