ืคื’ื™ืขื•ืช ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก ืฉืขืœื•ืœื” ืœื’ืจื•ื ืœืงืจื™ืกื” ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื—ื‘ื™ืœืช UDP

ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก ืžื–ื•ื”ื” ืคื’ื™ืขื•ืช (CVE-2019-11683), ื”ืžืืคืฉืจ ืœืš ืœื’ืจื•ื ืžืจื—ื•ืง ืœืžื ื™ืขืช ืฉื™ืจื•ืช ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืžื ื•ืช UDP ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“ (ื—ื‘ื™ืœืช ืžื•ื•ืช). ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ืฉื’ื™ืื” ื‘ืžื˜ืคืœ udp_gro_receive_segment (net/ipv4/udp_offload.c) ื‘ื™ื™ืฉื•ื ื˜ื›ื ื•ืœื•ื’ื™ื™ืช GRO (Generic Receive Offload) ื•ืขืœื•ืœื” ืœื”ื•ื‘ื™ืœ ืœืคื’ื™ืขื” ื‘ืชื•ื›ืŸ ืฉืœ ืื–ื•ืจื™ ื–ื™ื›ืจื•ืŸ ื”ืœื™ื‘ื” ื‘ืขืช ืขื™ื‘ื•ื“ ืžื ื•ืช UDP ืขื ืจื™ืคื•ื“ ืืคืก (ืžื˜ืขืŸ ืจื™ืง).

ื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ืจืง ืขืœ ื”ืงืจื ืœ 5.0ืžืื– ื”ื™ื™ืชื” ืชืžื™ื›ืช GRO ืขื‘ื•ืจ ืฉืงืขื™ UDP ืžื•ื˜ืžืข ื‘ื ื•ื‘ืžื‘ืจ ื‘ืฉื ื” ืฉืขื‘ืจื” ื•ื”ืฆืœื™ื— ืœื”ื™ื›ื ืก ืจืง ืœืžื”ื“ื•ืจืช ื”ืงืจื ืœ ื”ื™ืฆื™ื‘ื” ื”ืื—ืจื•ื ื”. ื˜ื›ื ื•ืœื•ื’ื™ื™ืช GRO ืžืืคืฉืจืช ืœืš ืœื”ืื™ืฅ ืืช ื”ืขื™ื‘ื•ื“ ืฉืœ ืžืกืคืจ ืจื‘ ืฉืœ ืžื ื•ืช ื ื›ื ืกื•ืช ืขืœ ื™ื“ื™ ืฆื‘ื™ืจื” ืฉืœ ืžืกืคืจ ืžื ื•ืช ืœื‘ืœื•ืงื™ื ื’ื“ื•ืœื™ื ื™ื•ืชืจ ืฉืื™ื ื ื“ื•ืจืฉื™ื ืขื™ื‘ื•ื“ ื ืคืจื“ ืฉืœ ื›ืœ ื—ื‘ื™ืœื”.
ืขื‘ื•ืจ TCP, ื”ื‘ืขื™ื” ืœื ืžืชืจื—ืฉืช, ืžื›ื™ื•ื•ืŸ ืฉืคืจื•ื˜ื•ืงื•ืœ ื–ื” ืื™ื ื• ืชื•ืžืš ื‘ืฆื‘ื™ืจื” ืฉืœ ืžื ื•ืช ืœืœื ืžื˜ืขืŸ.

ื”ืคื’ื™ืขื•ืช ืชื•ืงื ื” ืขื“ ื›ื” ืจืง ื‘ื˜ื•ืคืก ืชื™ืงื•ืŸ, ื”ืขื“ื›ื•ืŸ ื”ืžืชืงืŸ ืขื“ื™ื™ืŸ ืœื ืคื•ืจืกื (ืชื™ืงื•ืŸ ืขื“ื›ื•ืŸ 5.0.11 ืฉืœ ืืชืžื•ืœ ืœื ื›ืœื•ืœ). ืžืขืจื›ื•ืช ื”ืคืฆื”, ืงืจื ืœ 5.0 ื”ืฆืœื™ื— ืœื”ื™ื›ืœืœ ืคื“ื•ืจื” 30, ืื•ื‘ื•ื ื˜ื• 19.04, Arch Linux, ื’'ื ื˜ื• ื•ื”ืคืฆื•ืช ืื—ืจื•ืช ื”ืžืชืขื“ื›ื ื•ืช ื‘ืจืฆื™ืคื•ืช. ื“ื‘ื™ืืŸ, ืื•ื‘ื•ื ื˜ื• 18.10 ื•ืžืขืœื”, RHEL/CentOS ะธ SUSE/openSUSE ื”ื‘ืขื™ื” ืœื ืžืฉืคื™ืขื”.

ื”ื‘ืขื™ื” ื ืžืฆืื” ื›ืชื•ืฆืื” ืžื›ืš ืœื”ืฉืชืžืฉ ืžืขืจื›ืช ืื•ื˜ื•ืžื˜ื™ืช ืœื‘ื“ื™ืงืช ื˜ืฉื˜ื•ืฉ ืฉื ื•ืฆืจื” ืขืœ ื™ื“ื™ ื’ื•ื’ืœ syzbot ื•ืžื ืชื— ืงืืกืŸ (KernelAddressSanitizer), ืฉืžื˜ืจืชื• ืœื–ื”ื•ืช ืฉื’ื™ืื•ืช ื‘ืขืช ืขื‘ื•ื“ื” ืขื ื–ื™ื›ืจื•ืŸ ื•ืขื•ื‘ื“ื•ืช ืฉืœ ื’ื™ืฉื” ืœื ื ื›ื•ื ื” ืœื–ื™ื›ืจื•ืŸ, ื›ื’ื•ืŸ ื’ื™ืฉื” ืœืื–ื•ืจื™ ื–ื™ื›ืจื•ืŸ ืžืฉื•ื—ืจืจื™ื ื•ื”ืฆื‘ืช ืงื•ื“ ื‘ืื–ื•ืจื™ ื–ื™ื›ืจื•ืŸ ืฉืื™ื ื ืžื™ื•ืขื“ื™ื ืœืžื ื™ืคื•ืœืฆื™ื•ืช ื›ืืœื”.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”