ืคื’ื™ืขื•ื™ื•ืช ื‘ืžื ื”ืœื™ ื”ืชืงื ื™ื ืขื‘ื•ืจ ืฉื‘ื‘ื™ Broadcom WiFi, ื”ืžืืคืฉืจื•ืช ืœืš ืœืชืงื•ืฃ ืžืจื—ื•ืง ืืช ื”ืžืขืจื›ืช

ื‘ื“ืจื™ื™ื‘ืจื™ื ืขื‘ื•ืจ ืฉื‘ื‘ื™ Broadcom ืืœื—ื•ื˜ื™ื™ื ื’ื™ืœื” ืืจื‘ืขื” ืคื’ื™ืขื•ืช. ื‘ืžืงืจื” ื”ืคืฉื•ื˜ ื‘ื™ื•ืชืจ, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืคื’ื™ืขื•ื™ื•ืช ื›ื“ื™ ืœื’ืจื•ื ืžืจื—ื•ืง ืœืžื ื™ืขืช ืฉื™ืจื•ืช, ืืš ืœื ื ื™ืชืŸ ืœืฉืœื•ืœ ืชืจื—ื™ืฉื™ื ื‘ื”ื ื ื™ืชืŸ ืœืคืชื— ื ื™ืฆื•ืœื™ื ื”ืžืืคืฉืจื™ื ืœืชื•ืงืฃ ืœื ืžืื•ืžืช ืœื‘ืฆืข ืืช ื”ืงื•ื“ ืฉืœื• ืขื ื”ืจืฉืื•ืช ืœื™ื‘ืช ืœื™ื ื•ืงืก ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืžื ื•ืช ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“.

ื”ื‘ืขื™ื•ืช ื–ื•ื”ื• ืขืœ ื™ื“ื™ ื”ื ื“ืกื” ืœืื—ื•ืจ ืฉืœ ืงื•ืฉื—ืช ื‘ืจื•ื“ืงื•ื. ื”ืฉื‘ื‘ื™ื ื”ืžื•ืฉืคืขื™ื ื ืžืฆืื™ื ื‘ืฉื™ืžื•ืฉ ื ืจื—ื‘ ื‘ืžื—ืฉื‘ื™ื ื ื™ื™ื“ื™ื, ืกืžืืจื˜ืคื•ื ื™ื ื•ืžื’ื•ื•ืŸ ืžื›ืฉื™ืจื™ื ืฆืจื›ื ื™ื™ื, ื”ื—ืœ ืžื˜ืœื•ื•ื™ื–ื™ื•ืช ื—ื›ืžื•ืช ื•ืขื“ ืœืžื›ืฉื™ืจื™ ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ื”ื“ื‘ืจื™ื. ื‘ืคืจื˜, ืฉื‘ื‘ื™ Broadcom ืžืฉืžืฉื™ื ื‘ืกืžืืจื˜ืคื•ื ื™ื ืฉืœ ื™ืฆืจื ื™ื ื›ืžื• ืืคืœ, ืกืžืกื•ื ื•-Huawei. ืจืื•ื™ ืœืฆื™ื™ืŸ ืฉื‘ืจื•ื“ืงื•ื ืงื™ื‘ืœื” ื”ื•ื“ืขื” ืขืœ ื ืงื•ื“ื•ืช ื”ืชื•ืจืคื” ืขื•ื“ ื‘ืกืคื˜ืžื‘ืจ 2018, ืืš ืœืงื— ื›-7 ื—ื•ื“ืฉื™ื ืœืฉื—ืจืจ ืชื™ืงื•ื ื™ื ื‘ืชื™ืื•ื ืขื ื™ืฆืจื ื™ ืฆื™ื•ื“.

ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืžืฉืคื™ืขื•ืช ืขืœ ื”ืงื•ืฉื—ื” ื”ืคื ื™ืžื™ืช ื•ืขืœื•ืœื•ืช ืœืืคืฉืจ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืกื‘ื™ื‘ืช ืžืขืจื›ืช ื”ื”ืคืขืœื” ื”ืžืฉืžืฉืช ื‘ืฉื‘ื‘ื™ ื‘ืจื•ื“ืงื•ื, ืžื” ืฉืžืืคืฉืจ ืœืชืงื•ืฃ ืกื‘ื™ื‘ื•ืช ืฉืื™ื ืŸ ืžืฉืชืžืฉื•ืช ื‘ืœื™ื ื•ืงืก (ืœื“ื•ื’ืžื”, ืื•ืฉืจื” ื”ืืคืฉืจื•ืช ืœืชืงื•ืฃ ืžื›ืฉื™ืจื™ ืืคืœ CVE-2019-8564). ื”ื‘ื” ื ื–ื›ื™ืจ ืฉื›ืžื” ืฉื‘ื‘ื™ Wi-Fi ืฉืœ Broadcom ื”ื ืžืขื‘ื“ ืžื™ื•ื—ื“ (ARM Cortex R4 ืื• M3), ื”ืžืจื™ืฅ ืžืขืจื›ืช ื”ืคืขืœื” ื“ื•ืžื” ืขื ื™ื™ืฉื•ืžื™ื ืฉืœ ื”ืžื—ืกื ื™ืช ื”ืืœื—ื•ื˜ื™ืช 802.11 (FullMAC). ื‘ืฉื‘ื‘ื™ื ื›ืืœื”, ื”ื ื”ื’ ืžื‘ื˜ื™ื— ืื™ื ื˜ืจืืงืฆื™ื” ืฉืœ ื”ืžืขืจื›ืช ื”ืจืืฉื™ืช ืขื ืงื•ืฉื—ืช ืฉื‘ื‘ ื”-Wi-Fi. ื›ื“ื™ ืœื”ืฉื™ื’ ืฉืœื™ื˜ื” ืžืœืื” ืขืœ ื”ืžืขืจื›ืช ื”ืจืืฉื™ืช ืœืื—ืจ ืคื’ื™ืขื” ื‘-FullMAC, ืžื•ืฆืข ืœื”ืฉืชืžืฉ ื‘ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื ื•ืกืคื•ืช ืื•, ื‘ืฉื‘ื‘ื™ื ืžืกื•ื™ืžื™ื, ืœื ืฆืœ ืืช ื”ื’ื™ืฉื” ื”ืžืœืื” ืœื–ื™ื›ืจื•ืŸ ื”ืžืขืจื›ืช. ื‘ืฉื‘ื‘ื™ื ืขื SoftMAC, ื”ืžื—ืกื ื™ืช ื”ืืœื—ื•ื˜ื™ืช 802.11 ืžื™ื•ืฉืžืช ื‘ืฆื“ ื”ื ื”ื’ ื•ืžื‘ื•ืฆืขืช ื‘ืืžืฆืขื•ืช ืžืขื‘ื“ ื”ืžืขืจื›ืช.

ืคื’ื™ืขื•ื™ื•ืช ื‘ืžื ื”ืœื™ ื”ืชืงื ื™ื ืขื‘ื•ืจ ืฉื‘ื‘ื™ Broadcom WiFi, ื”ืžืืคืฉืจื•ืช ืœืš ืœืชืงื•ืฃ ืžืจื—ื•ืง ืืช ื”ืžืขืจื›ืช

ืคื’ื™ืขื•ื™ื•ืช ืฉืœ ืžื ื”ืœื™ ื”ืชืงื ื™ื ืžืชืจื—ืฉื•ืช ื”ืŸ ื‘ืžื ื”ืœ ื”ืชืงืŸ wl ื”ืงื ื™ื™ื ื™ (SoftMAC ื•-FullMAC) ื•ื”ืŸ ื‘ืงื•ื“ ื”ืคืชื•ื— brcmfmac (FullMAC). ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ wl ื–ื•ื”ื• ืฉืชื™ ื’ืœื™ืฉื•ืช ืžืื’ืจ, ืžื ื•ืฆืœื•ืช ื›ืืฉืจ ื ืงื•ื“ืช ื”ื’ื™ืฉื” ืžืฉื“ืจืช ื”ื•ื“ืขื•ืช EAPOL ื‘ืคื•ืจืžื˜ ืžื™ื•ื—ื“ ื‘ืžื”ืœืš ืชื”ืœื™ืš ื”ืžืฉื ื•ืžืชืŸ ืขืœ ื”ื—ื™ื‘ื•ืจ (ื ื™ืชืŸ ืœื‘ืฆืข ืืช ื”ื”ืชืงืคื” ื‘ืขืช ื”ืชื—ื‘ืจื•ืช ืœื ืงื•ื“ืช ื’ื™ืฉื” ื–ื“ื•ื ื™ืช). ื‘ืžืงืจื” ืฉืœ ืฉื‘ื‘ ืขื SoftMAC, ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืžื•ื‘ื™ืœื•ืช ืœืคื’ื™ืขื” ื‘ื’ืจืขื™ืŸ ื”ืžืขืจื›ืช, ื•ื‘ืžืงืจื” ืฉืœ FullMAC, ื ื™ืชืŸ ืœื”ืคืขื™ืœ ืืช ื”ืงื•ื“ ื‘ืฆื“ ื”ืงื•ืฉื—ื”. brcmfmac ืžื›ื™ืœ ื’ืœื™ืฉืช ืžืื’ืจ ื•ืฉื’ื™ืืช ื‘ื“ื™ืงืช ืžืกื’ืจืช ื”ืžื ื•ืฆืœืช ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืžืกื’ืจื•ืช ื‘ืงืจื”. ื‘ืขื™ื•ืช ืขื ืžื ื”ืœ ื”ื”ืชืงืŸ ืฉืœ brcmfmac ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก ื–ื” ื”ื™ื” ื—ื•ืกืœื• ื‘ืคื‘ืจื•ืืจ.

ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉื–ื•ื”ื•:

  • CVE-2019-9503 - ื”ืชื ื”ื’ื•ืช ืฉื’ื•ื™ื” ืฉืœ ืžื ื”ืœ ื”ื”ืชืงืŸ ืฉืœ brcmfmac ื‘ืขืช ืขื™ื‘ื•ื“ ืžืกื’ืจื•ืช ื‘ืงืจื” ื”ืžืฉืžืฉื•ืช ืœืื™ื ื˜ืจืืงืฆื™ื” ืขื ื”ืงื•ืฉื—ื”. ืื ืžืกื’ืจืช ืขื ืื™ืจื•ืข ืงื•ืฉื—ื” ืžื’ื™ืขื” ืžืžืงื•ืจ ื—ื™ืฆื•ื ื™, ื”ื ื”ื’ ืžืฉืœื™ืš ืื•ืชื”, ืืš ืื ื”ืื™ืจื•ืข ืžืชืงื‘ืœ ื“ืจืš ื”ืื•ื˜ื•ื‘ื•ืก ื”ืคื ื™ืžื™, ื”ืžืกื’ืจืช ืžื“ืœื’ืช. ื”ื‘ืขื™ื” ื”ื™ื ืฉืื™ืจื•ืขื™ื ืžืžื›ืฉื™ืจื™ื ื”ืžืฉืชืžืฉื™ื ื‘-USB ืžื•ืขื‘ืจื™ื ื“ืจืš ื”ืืคื™ืง ื”ืคื ื™ืžื™, ืžื” ืฉืžืืคืฉืจ ืœืชื•ืงืคื™ื ืœื”ืขื‘ื™ืจ ื‘ื”ืฆืœื—ื” ืžืกื’ืจื•ืช ื‘ืงืจืช ืงื•ืฉื—ื” ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืžืชืืžื™ื ืืœื—ื•ื˜ื™ื™ื ืขื ืžืžืฉืง USB;
  • CVE-2019-9500 - ื›ืืฉืจ ืชื›ื•ื ืช "ื”ืชืขื•ืจืจื•ืช ื‘ืจืฉืช ืืœื—ื•ื˜ื™ืช" ืžื•ืคืขืœืช, ืืคืฉืจ ืœื’ืจื•ื ืœื’ืœื™ืฉื” ื‘ืขืจื™ืžื” ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ ืฉืœ brcmfmac (ืคื•ื ืงืฆื™ื” brcmf_wowl_nd_results) ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืžืกื’ืจืช ื‘ืงืจื” ืฉืฉื•ื ืชื” ื‘ืžื™ื•ื—ื“. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืคื’ื™ืขื•ืช ื–ื• ืœืืจื’ื•ืŸ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืžืขืจื›ืช ื”ืจืืฉื™ืช ืœืื—ืจ ืฉื”ืฉื‘ื‘ ื ืคืจืฅ ืื• ื‘ืฉื™ืœื•ื‘ ืขื ื”ืคื’ื™ืขื•ืช ืฉืœ CVE-2019-9503 ื›ื“ื™ ืœืขืงื•ืฃ ื‘ื“ื™ืงื•ืช ื‘ืžืงืจื” ืฉืœ ืฉืœื™ื—ื” ืžืจื—ื•ืง ืฉืœ ืžืกื’ืจืช ื‘ืงืจื”;
  • CVE-2019-9501 - ื’ืœื™ืฉืช ื—ื™ืฅ ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ wl (ืคื•ื ืงืฆื™ื™ืช wlc_wpa_sup_eapol) ื”ืžืชืจื—ืฉืช ื‘ืขืช ืขื™ื‘ื•ื“ ื”ื•ื“ืขื•ืช ืฉืชื•ื›ืŸ ืฉื“ื” ื”ืžื™ื“ืข ืฉืœ ื”ื™ืฆืจืŸ ืฉืœื”ืŸ ืขื•ืœื” ืขืœ 32 ื‘ืชื™ื;
  • CVE-2019-9502 - ื’ืœื™ืฉืช ื—ื™ืฅ ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ wl (ืคื•ื ืงืฆื™ื™ืช wlc_wpa_plumb_gtk) ืžืชืจื—ืฉืช ื‘ืขืช ืขื™ื‘ื•ื“ ื”ื•ื“ืขื•ืช ืฉืชื•ื›ืŸ ืฉื“ื” ื”ืžื™ื“ืข ืฉืœ ื”ื™ืฆืจืŸ ืฉืœื”ืŸ ืขื•ืœื” ืขืœ 164 ื‘ืชื™ื.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”