ืคื’ื™ืขื•ื™ื•ืช ื‘-GRUB2 ืฉื™ื›ื•ืœื•ืช ืœืขืงื•ืฃ ืืช UEFI Secure Boot

2 ืคื’ื™ืขื•ื™ื•ืช ืชื•ืงื ื• ื‘ืžื˜ืขืŸ ื”ืืชื—ื•ืœ GRUB7 ื”ืžืืคืฉืจื•ืช ืœืš ืœืขืงื•ืฃ ืืช ืžื ื’ื ื•ืŸ ื”ืืชื—ื•ืœ ื”ืžืื•ื‘ื˜ื— ืฉืœ UEFI ื•ืœื”ืคืขื™ืœ ืงื•ื“ ืœื ืžืื•ืžืช, ืœืžืฉืœ, ืœื”ืฆื™ื’ ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ื”ืคื•ืขืœื•ืช ื‘ืจืžืช ื”ืืชื—ื•ืœ ืื• ืจืžืช ื”ืงืจื ืœ. ื‘ื ื•ืกืฃ, ื™ืฉื ื” ืคื’ื™ืขื•ืช ืื—ืช ื‘ืฉื›ื‘ืช ื”-shim, ื”ืžืืคืฉืจืช ืœืš ื’ื ืœืขืงื•ืฃ ืืช UEFI Secure Boot. ืงื‘ื•ืฆืช ื”ืคื’ื™ืขื•ืช ืงื™ื‘ืœื” ืืช ืฉื ื”ืงื•ื“ Boothole 3, ื‘ื“ื•ืžื” ืœื‘ืขื™ื•ืช ื“ื•ืžื•ืช ืฉื–ื•ื”ื• ื‘ืขื‘ืจ ื‘-bootloader.

ื›ื“ื™ ืœืคืชื•ืจ ื‘ืขื™ื•ืช ื‘-GRUB2 ื•ื‘-shim, ื”ืคืฆื•ืช ื™ื•ื›ืœื• ืœื”ืฉืชืžืฉ ื‘ืžื ื’ื ื•ืŸ SBAT (UEFI Secure Boot Advanced Targeting), ืืฉืจ ื ืชืžืš ืขื‘ื•ืจ GRUB2, shim ื•-fwupd. SBAT ืคื•ืชื—ื” ื‘ืžืฉื•ืชืฃ ืขื ืžื™ืงืจื•ืกื•ืคื˜ ื•ื›ื•ืœืœืช ื”ื•ืกืคืช ืžื˜ื ื ืชื•ื ื™ื ื ื•ืกืคื™ื ืœืงื‘ืฆื™ ื”ื”ืคืขืœื” ืฉืœ ืจื›ื™ื‘ื™ UEFI, ื”ื›ื•ืœืœื™ื ืžื™ื“ืข ืขืœ ื”ื™ืฆืจืŸ, ื”ืžื•ืฆืจ, ื”ืจื›ื™ื‘ ื•ื”ื’ืจืกื”. ื”ืžื˜ื ื ืชื•ื ื™ื ืฉืฆื•ื™ื ื• ืžืื•ืฉืจื™ื ื‘ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ื•ื ื™ืชืŸ ืœื›ืœื•ืœ ืื•ืชื ื‘ื ืคืจื“ ื‘ืจืฉื™ืžื•ืช ืฉืœ ืจื›ื™ื‘ื™ื ืžื•ืชืจื™ื ืื• ืืกื•ืจื™ื ืขื‘ื•ืจ UEFI Secure Boot.

ืจื•ื‘ ื”ื”ืคืฆื•ืช ืฉืœ ืœื™ื ื•ืงืก ืžืฉืชืžืฉื•ืช ื‘ืฉื›ื‘ืช shim ืงื˜ื ื” ื”ื—ืชื•ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ืขืœ ื™ื“ื™ ืžื™ืงืจื•ืกื•ืคื˜ ืœืืชื—ื•ืœ ืžืื•ืžืช ื‘ืžืฆื‘ UEFI Secure Boot. ืฉื›ื‘ื” ื–ื• ืžืืžืชืช ืืช GRUB2 ืขื ืชืขื•ื“ื” ืžืฉืœื”, ืžื” ืฉืžืืคืฉืจ ืœืžืคืชื—ื™ ื”ืคืฆื” ืœื ืœืงื‘ืœ ืื™ืฉื•ืจ ืœื›ืœ ืœื™ื‘ื” ื•ืขื“ื›ื•ืŸ GRUB ืขืœ ื™ื“ื™ ืžื™ืงืจื•ืกื•ืคื˜. ืคื’ื™ืขื•ื™ื•ืช ื‘-GRUB2 ืžืืคืฉืจื•ืช ืœืš ืœื”ืฉื™ื’ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœืš ื‘ืฉืœื‘ ืฉืœืื—ืจ ืื™ืžื•ืช shim ืžื•ืฆืœื—, ืืš ืœืคื ื™ ื˜ืขื™ื ืช ืžืขืจื›ืช ื”ื”ืคืขืœื”, ื”ื™ืฆืžื“ื•ืช ืœืฉืจืฉืจืช ื”ืืžื•ืŸ ื›ืืฉืจ ืžืฆื‘ Secure Boot ืคืขื™ืœ ื•ืงื‘ืœืช ืฉืœื™ื˜ื” ืžืœืื” ืขืœ ืชื”ืœื™ืš ื”ืืชื—ื•ืœ ื”ื ื•ืกืฃ, ื›ื•ืœืœ ื˜ืขื™ื ืช ืžืขืจื›ืช ื”ืคืขืœื” ืื—ืจืช, ืฉื™ื ื•ื™ ืžืขืจื›ืช ืจื›ื™ื‘ื™ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื•ืขืงื•ืฃ ื”ื’ื ืช ื ืขื™ืœื”.

ื›ื“ื™ ืœืชืงืŸ ื‘ืขื™ื•ืช ื‘-bootloader, ื”ืคืฆื•ืช ื™ืฆื˜ืจื›ื• ืœื™ืฆื•ืจ ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ืคื ื™ืžื™ื•ืช ื—ื“ืฉื•ืช ื•ืœืขื“ื›ืŸ ืžืชืงื™ื ื™ ืืชื—ื•ืœ, ืžื˜ืขื ื™ ืืชื—ื•ืœ, ื—ื‘ื™ืœื•ืช ืœื™ื‘ื”, ืงื•ืฉื—ื” fwupd ื•ืฉื›ื‘ืช shim. ืœืคื ื™ ื”ืฆื’ืช SBAT, ืขื“ื›ื•ืŸ ืจืฉื™ืžืช ื‘ื™ื˜ื•ืœื™ ื”ืื™ืฉื•ืจื™ื (dbx, UEFI Revocation List) ื”ื™ื” ืชื ืื™ ืžื•ืงื“ื ืœื—ืกื™ืžืช ื”ืคื’ื™ืขื•ืช ืœื—ืœื•ื˜ื™ืŸ, ืฉื›ืŸ ืชื•ืงืฃ, ืœืœื ืงืฉืจ ืœืžืขืจื›ืช ื”ื”ืคืขืœื” ืฉื‘ื” ื ืขืฉื” ืฉื™ืžื•ืฉ, ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืžื“ื™ื” ื ื™ืชื ืช ืœืืชื—ื•ืœ ืขื ื’ืจืกื” ื™ืฉื ื” ื•ืคื’ื™ืขื” ืฉืœ GRUB2, ืžืื•ืฉืจ ืขืœ ื™ื“ื™ ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช, ื›ื“ื™ ืœืกื›ืŸ ืืช UEFI Secure Boot .

ื‘ืžืงื•ื ืœื‘ื˜ืœ ื—ืชื™ืžื”, SBAT ืžืืคืฉืจ ืœืš ืœื—ืกื•ื ืืช ื”ืฉื™ืžื•ืฉ ื‘ื” ืขื‘ื•ืจ ืžืกืคืจื™ ื’ืจืกืื•ืช ืฉืœ ืจื›ื™ื‘ื™ื ื‘ื•ื“ื“ื™ื ืžื‘ืœื™ ืฉืชืฆื˜ืจืš ืœื‘ื˜ืœ ืืช ื”ืžืคืชื—ื•ืช ืขื‘ื•ืจ ืืชื—ื•ืœ ืžืื•ื‘ื˜ื—. ื—ืกื™ืžืช ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืืžืฆืขื•ืช SBAT ืื™ื ื” ืžืฆืจื™ื›ื” ืฉื™ืžื•ืฉ ื‘ืจืฉื™ืžืช ื‘ื™ื˜ื•ืœื™ ืื™ืฉื•ืจื™ UEFI (dbx), ืืœื ืžื‘ื•ืฆืขืช ื‘ืจืžืช ื”ื—ืœืคืช ื”ืžืคืชื— ื”ืคื ื™ืžื™ ืœื™ืฆื™ืจืช ื—ืชื™ืžื•ืช ื•ืขื“ื›ื•ืŸ GRUB2, shim ื•ื—ืคืฆื™ ืืชื—ื•ืœ ืื—ืจื™ื ื”ืžืกื•ืคืงื™ื ืขืœ ื™ื“ื™ ื”ืคืฆื•ืช. ื ื›ื•ืŸ ืœืขื›ืฉื™ื•, ืชืžื™ื›ืช SBAT ื›ื‘ืจ ื ื•ืกืคื” ืœืจื•ื‘ ื”ื”ืคืฆื•ืช ื”ืคื•ืคื•ืœืจื™ื•ืช ืฉืœ ืœื™ื ื•ืงืก.

ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉื–ื•ื”ื•:

  • CVE-2021-3696, CVE-2021-3695 ื”ื ื’ืœื™ืฉื•ืช ื—ื™ืฅ ืžื‘ื•ืกืกื•ืช ืขืจื™ืžื•ืช ื‘ืขืช ืขื™ื‘ื•ื“ ืชืžื•ื ื•ืช PNG ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“, ืืฉืจ ืชื™ืื•ืจื˜ื™ืช ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ืŸ ืœื‘ื™ืฆื•ืข ืงื•ื“ ืชื•ืงืฃ ื•ืœืขืงื•ืฃ ืืช UEFI Secure Boot. ื™ืฆื•ื™ืŸ ืฉื”ื‘ืขื™ื” ืงืฉื” ืœื ื™ืฆื•ืœ, ืฉื›ืŸ ื™ืฆื™ืจืช ื ื™ืฆื•ืœ ืขื•ื‘ื“ ื“ื•ืจืฉืช ืœืงื—ืช ื‘ื—ืฉื‘ื•ืŸ ืžืกืคืจ ืจื‘ ืฉืœ ื’ื•ืจืžื™ื ื•ื–ืžื™ื ื•ืช ื”ืžื™ื“ืข ืขืœ ืคืจื™ืกืช ื”ื–ื™ื›ืจื•ืŸ.
  • CVE-2021-3697 - ื–ืจื™ืžืช ื—ื™ืฅ ื‘ืงื•ื“ ืขื™ื‘ื•ื“ ืชืžื•ื ื” JPEG. ื ื™ืฆื•ืœ ื”ื ื•ืฉื ื“ื•ืจืฉ ื™ื“ืข ื‘ืคืจื™ืกืช ื”ื–ื™ื›ืจื•ืŸ ื•ื”ื•ื ื‘ืขืจืš ื‘ืื•ืชื” ืจืžืช ืžื•ืจื›ื‘ื•ืช ื›ืžื• ื‘ืขื™ื™ืช ื”-PNG (CVSS 7.5).
  • CVE-2022-28733 - ื’ืœื™ืฉืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘ืคื•ื ืงืฆื™ื” grub_net_recv_ip4_packets() ืžืืคืฉืจืช ืœื”ืฉืคื™ืข ืขืœ ื”ืคืจืžื˜ืจ rsm->total_len ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื—ื‘ื™ืœืช IP ื‘ืขืœืช ืžื‘ื ื” ืžื™ื•ื—ื“. ื”ื ื•ืฉื ืžืกื•ืžืŸ ื›ืžืกื•ื›ืŸ ื‘ื™ื•ืชืจ ืžื‘ื™ืŸ ื”ืคื’ื™ืขื•ื™ื•ืช ื”ืžื•ืฆื’ื•ืช (CVSS 8.1). ืื ืžื ื•ืฆืœืช ื‘ื”ืฆืœื—ื”, ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœื›ืชื•ื‘ ื ืชื•ื ื™ื ืžืขื‘ืจ ืœื’ื‘ื•ืœ ื”ืžืื’ืจ ืขืœ ื™ื“ื™ ื”ืงืฆืืช ื’ื•ื“ืœ ื–ื™ื›ืจื•ืŸ ืงื˜ืŸ ื™ื•ืชืจ ื‘ื›ื•ื•ื ื”.
  • CVE-2022-28734 - ื’ืœื™ืฉืช ืžืื’ืจ ืฉืœ ื‘ืชื™ื ื‘ื•ื“ื“ื™ื ื‘ืขืช ืขื™ื‘ื•ื“ ื›ื•ืชืจื•ืช HTTP ืžื•ืคืฉื˜ื•ืช. ื‘ืขื™ื” ืขืœื•ืœื” ืœื’ืจื•ื ืœืคื’ื™ืขื” ื‘ืžื˜ื-ื ืชื•ื ื™ื ืฉืœ GRUB2 (ื›ืชื™ื‘ืช byte null ืžื™ื“ ืœืื—ืจ ืกื™ื•ื ื”ืžืื’ืจ) ื‘ืขืช ื ื™ืชื•ื— ื‘ืงืฉื•ืช HTTP ื‘ืขืœื•ืช ืžื‘ื ื” ืžื™ื•ื—ื“.
  • CVE-2022-28735 ื‘ืขื™ื” ื‘ืžืืžืช shim_lock ืžืืคืฉืจืช ื˜ืขื™ื ืช ืงื‘ืฆื™ื ืฉืื™ื ื ื”ืœื™ื‘ื”. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืคื’ื™ืขื•ืช ื›ื“ื™ ืœื˜ืขื•ืŸ ืžื•ื“ื•ืœื™ ืœื™ื‘ื” ืœื ื—ืชื•ืžื™ื ืื• ืงื•ื“ ืœื ืžืื•ืžืช ื‘ืžืฆื‘ UEFI Secure Boot.
  • CVE-2022-28736 ื’ื™ืฉืช ื–ื™ื›ืจื•ืŸ ืžืฉื•ื—ืจืจืช ื›ื‘ืจ ื‘ืคื•ื ืงืฆื™ื” grub_cmd_chainloader() ื‘ืืžืฆืขื•ืช ื”ืคืขืœื” ื—ื•ื–ืจืช ืฉืœ ืคืงื•ื“ืช chainloader, ื”ืžืฉืžืฉืช ืœืืชื—ื•ืœ ืžืขืจื›ื•ืช ื”ืคืขืœื” ืฉืื™ื ืŸ ื ืชืžื›ื•ืช ืขืœ ื™ื“ื™ GRUB2. ื ื™ืฆื•ืœ ืขืœื•ืœ ืœื’ืจื•ื ืœื‘ื™ืฆื•ืข ืงื•ื“ ืชื•ืงืฃ ืื ื”ืชื•ืงืฃ ืžืกื•ื’ืœ ืœืงื‘ื•ืข ื”ืงืฆืืช ื–ื™ื›ืจื•ืŸ ื‘-GRUB2
  • CVE-2022-28737 - ื’ืœื™ืฉืช ื—ื™ืฅ ื‘ืฉื›ื‘ืช ื”-shim ืžืชืจื—ืฉืช ื‘ืคื•ื ืงืฆื™ื” handle_image() ื‘ืขืช ื˜ืขื™ื ื” ื•ื‘ื™ืฆื•ืข ืฉืœ ืชืžื•ื ื•ืช EFI ืžืขื•ืฆื‘ื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”