ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-Netfilter ื•-io_uring ื”ืžืืคืฉืจื•ืช ืœืš ืœื”ืขืœื•ืช ืืช ื”ื”ืจืฉืื•ืช ืฉืœืš ื‘ืžืขืจื›ืช

ื–ื•ื”ื• ืคื’ื™ืขื•ื™ื•ืช ื‘ืชืช-ืžืขืจื›ื•ืช ืœื™ื‘ืช ืœื™ื ื•ืงืก Netfilter ื•-io_uring ื”ืžืืคืฉืจื•ืช ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœื”ื’ื“ื™ืœ ืืช ื”ื”ืจืฉืื•ืช ืฉืœื• ื‘ืžืขืจื›ืช:

  • ืคื’ื™ืขื•ืช (CVE-2023-32233) ื‘ืชืช-ืžืขืจื›ืช Netfilter ื”ื ื’ืจืžืช ืžื’ื™ืฉื” ืœื–ื™ื›ืจื•ืŸ ืœืœื ืฉื™ืžื•ืฉ ื‘ืžื•ื“ื•ืœ nf_tables, ื”ืžืกืคืง ืืช ืžืกื ืŸ ื”ืžื ื•ืช nftables. ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉื•ืช ื‘ืขืœื•ืช ืžื‘ื ื” ืžื™ื•ื—ื“ ืœืขื“ื›ื•ืŸ ืชืฆื•ืจืช ื”-nftables. ื›ื“ื™ ืœื‘ืฆืข ืืช ื”ืžืชืงืคื”, ื ื“ืจืฉืช ื’ื™ืฉื” ืœ-nftables, ืฉื ื™ืชืŸ ืœื”ืฉื™ื’ ื‘ืžืจื—ื‘ื™ ืฉืžื•ืช ื ืคืจื“ื™ื ืฉืœ ืจืฉืช ืื ื™ืฉ ืœืš ื–ื›ื•ื™ื•ืช CLONE_NEWUSER, CLONE_NEWNS ืื• CLONE_NEWNET (ืœื“ื•ื’ืžื”, ืื ืืชื” ื™ื›ื•ืœ ืœื”ืคืขื™ืœ ืงื•ื ื˜ื™ื™ื ืจ ืžื‘ื•ื“ื“).

    ื›ื“ื™ ืœืชืช ืœืžืฉืชืžืฉื™ื ื–ืžืŸ ืœื”ืชืงื™ืŸ ืขื“ื›ื•ื ื™ื, ื”ื—ื•ืงืจ ืฉื–ื™ื”ื” ืืช ื”ื‘ืขื™ื” ื”ื‘ื˜ื™ื— ืœื“ื—ื•ืช ื‘ืฉื‘ื•ืข (ืขื“ 15 ื‘ืžืื™) ืืช ืคืจืกื•ื ื”ืžื™ื“ืข ื”ืžืคื•ืจื˜ ื•ื“ื•ื’ืžื” ืœื ื™ืฆื•ืœ ืขื•ื‘ื“ ื”ืžืกืคืง ืžืขื˜ืคืช ืฉื•ืจืฉ. ื”ืคื’ื™ืขื•ืช ืชื•ืงื ื” ื‘ืขื“ื›ื•ืŸ 6.4-rc1. ื ื™ืชืŸ ืœืขืงื•ื‘ ืื—ืจ ืชื™ืงื•ืŸ ื”ืคื’ื™ืขื•ืช ื‘ื”ืคืฆื•ืช ื‘ื“ืคื™ื: Debian, Ubuntu, Gentoo, RHEL, Fedora, SUSE/openSUSE, Arch.

  • ืคื’ื™ืขื•ืช (ืขื“ื™ื™ืŸ ืœื ื”ื•ืงืฆืชื” CVE) ื‘ื”ื˜ืžืขืช ืžืžืฉืง ื”ืงืœื˜/ืคืœื˜ ื”ืืกื™ื ื›ืจื•ื ื™ io_uring, ื”ื ื›ืœืœ ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก ืžืื– ื’ืจืกื” 5.1. ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื‘ืื’ ื‘ืคื•ื ืงืฆื™ื” io_sqe_buffer_register, ื”ืžืืคืฉืจืช ื’ื™ืฉื” ืœื–ื™ื›ืจื•ืŸ ืคื™ื–ื™ ืžืขื‘ืจ ืœื’ื‘ื•ืœ ืฉืœ ืžืื’ืจ ืฉื”ื•ืงืฆื” ืกื˜ื˜ื™ืช. ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืจืง ื‘ืขื ืฃ 6.3 ื•ืชืชื•ืงืŸ ื‘ืขื“ื›ื•ืŸ ื”ืงืจื•ื‘ 6.3.2. ืื‘ ื˜ื™ืคื•ืก ืขื•ื‘ื“ ืฉืœ ื”ื ื™ืฆื•ืœ ื›ื‘ืจ ื–ืžื™ืŸ ืœื‘ื“ื™ืงื”, ื•ืžืืคืฉืจ ืœืš ืœื‘ืฆืข ืงื•ื“ ืขื ื”ืจืฉืื•ืช ืœื™ื‘ื”.

ื”ื•ืกืคืช ืชื’ื•ื‘ื”