ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืชืช-ืžืขืจื›ืช eBPF ื”ืžืืคืฉืจื•ืช ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืจืžืช ืœื™ื‘ืช ืœื™ื ื•ืงืก

ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื—ื“ืฉื•ืช ื–ื•ื”ื• ื‘ืชืช ื”ืžืขืจื›ืช eBPF, ื”ืžืืคืฉืจืช ืœื”ืจื™ืฅ ืžื˜ืคืœื™ื ื‘ืชื•ืš ืœื™ื‘ืช ืœื™ื ื•ืงืก ื‘ืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช ืžื™ื•ื—ื“ืช ืขื JIT. ืฉืชื™ ื”ืคื’ื™ืขื•ื™ื•ืช ืžืืคืฉืจื•ืช ืœื”ืคืขื™ืœ ืืช ื”ืงื•ื“ ืฉืœืš ืขื ื–ื›ื•ื™ื•ืช ืœื™ื‘ื”, ืžื—ื•ืฅ ืœืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช eBPF ืžื‘ื•ื“ื“ืช. ืžื™ื“ืข ืขืœ ื”ื‘ืขื™ื•ืช ืคื•ืจืกื ืขืœ ื™ื“ื™ ืฆื•ื•ืช Zero Day Initiative, ื”ืžืคืขื™ืœ ืืช ืชื—ืจื•ืช Pwn2Own, ืฉื‘ืžื”ืœื›ื” ื”ื•ื›ื—ื• ื”ืฉื ื” ืฉืœื•ืฉ ื”ืชืงืคื•ืช ืขืœ ืื•ื‘ื•ื ื˜ื• ืœื™ื ื•ืงืก ืฉื”ืฉืชืžืฉื• ื‘ืคืจืฆื•ืช ืฉืœื ื”ื™ื• ื™ื“ื•ืขื•ืช ืขื“ ื›ื” (ื”ืื ืœื ื“ื•ื•ื— ื”ืื ื”ืคื’ื™ืขื•ื™ื•ืช ื‘-eBPF ืงืฉื•ืจื•ืช ืœื”ืชืงืคื•ืช ืืœื•) .

  • CVE-2021-3490 - ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืžื”ื™ืขื“ืจ ื‘ื“ื™ืงืช 32 ืกื™ื‘ื™ื•ืช ืžื—ื•ืฅ ืœืชื—ื•ื ื‘ืขืช ื‘ื™ืฆื•ืข ืคืขื•ืœื•ืช AND, OR ื•-XOR ื‘-eBPF ALU32. ืชื•ืงืฃ ื™ื›ื•ืœ ืœื ืฆืœ ืืช ื”ืฉื’ื™ืื” ื”ื–ื• ื›ื“ื™ ืœืงืจื•ื ื•ืœื›ืชื•ื‘ ื ืชื•ื ื™ื ืžื—ื•ืฅ ืœื’ื‘ื•ืœื•ืช ื”ืžืื’ืจ ื”ืžื•ืงืฆื”. ื”ื‘ืขื™ื” ื‘ืคืขื•ืœื•ืช XOR ืžื•ืคื™ืขื” ื”ื—ืœ ืžื’ืจืกืช ืœื™ื‘ื” 5.7-rc1, ื•-AND ื•-OR - ื”ื—ืœ ืž-5.10-rc1.
  • CVE-2021-3489 - ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืžืฉื’ื™ืื” ื‘ื™ื™ืฉื•ื ืžืื’ืจ ื”ื˜ื‘ืขืช ื•ื ื•ื‘ืขืช ืžื›ืš ืฉื”ืคื•ื ืงืฆื™ื” bpf_ringbuf_reserve ืœื ื‘ื“ืงื” ืืช ื”ืืคืฉืจื•ืช ืฉื’ื•ื“ืœ ืื–ื•ืจ ื”ื–ื™ื›ืจื•ืŸ ืฉื”ื•ืงืฆื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ืงื˜ืŸ ืžื”ื’ื•ื“ืœ ื”ืืžื™ืชื™ ืฉืœ ื”ืจื™ื ื’ื‘ืืฃ. ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืžืื– ื’ืจืกื” 5.8-rc1.

ื ื™ืชืŸ ืœืขืงื•ื‘ ืื—ืจ ื”ืžืฆื‘ ืฉืœ ืชื™ืงื•ืŸ ืคื’ื™ืขื•ื™ื•ืช ื‘ื”ืคืฆื•ืช ื‘ื“ืคื™ื ืืœื”: ืื•ื‘ื•ื ื˜ื•, ื“ื‘ื™ืืŸ, RHEL, Fedora, SUSE, Arch). ืชื™ืงื•ื ื™ื ื–ืžื™ื ื™ื ื’ื ื›ืชื™ืงื•ื ื™ื (CVE-2021-3489, CVE-2021-3490). ื”ืื ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ื‘ืขื™ื” ืชืœื•ื™ื” ื‘ืฉืืœื” ืื ืงืจื™ืืช ืžืขืจื›ืช eBPF ื ื’ื™ืฉื” ืœืžืฉืชืžืฉ. ืœื“ื•ื’ืžื”, ื‘ืชืฆื•ืจืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื‘-RHEL, ื ื™ืฆื•ืœ ื”ืคื’ื™ืขื•ืช ื“ื•ืจืฉ ืžื”ืžืฉืชืžืฉ ื–ื›ื•ื™ื•ืช CAP_SYS_ADMIN.

ื‘ื ืคืจื“, ืื ื• ื™ื›ื•ืœื™ื ืœืฆื™ื™ืŸ ืคื’ื™ืขื•ืช ื ื•ืกืคืช ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก - CVE-2021-32606, ื”ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœื”ืขืœื•ืช ืืช ื”ื”ืจืฉืื•ืช ืฉืœื• ืœืจืžืช ื”ืฉื•ืจืฉ. ื”ื‘ืขื™ื” ื ื™ื›ืจืช ืžืื– ืœื™ื‘ืช ืœื™ื ื•ืงืก 5.11 ื•ื”ื™ื ื ื’ืจืžืช ืžืžืฆื‘ ืžื™ืจื•ืฅ ื‘ื™ื™ืฉื•ื ืคืจื•ื˜ื•ืงื•ืœ CAN ISOTP, ื”ืžืืคืฉืจ ืœืฉื ื•ืช ืืช ืคืจืžื˜ืจื™ ื”-socket binding ืขืงื‘ ื”ื™ืขื“ืจ ื”ื’ื“ืจืช ื”ืžื ืขื•ืœื™ื ื”ืžืชืื™ืžื™ื ื‘ืคื•ื ืงืฆื™ื™ืช isotp_setsockopt() ื‘ืขืช ืขื™ื‘ื•ื“ ื“ื’ืœ CAN_ISOTP_SF_BROADCAST.

ืœืื—ืจ ืกื’ื™ืจืช ืฉืงืข ISOTP, ื”ืงื™ืฉื•ืจ ืœืฉืงืข ื”ื ืžืขืŸ ื ืฉืืจ ื‘ืชื•ืงืฃ, ืืฉืจ ื™ื›ื•ืœ ืœื”ืžืฉื™ืš ืœื”ืฉืชืžืฉ ื‘ืžื‘ื ื™ื ื”ืžืฉื•ื™ื›ื™ื ืœืฉืงืข ืœืื—ืจ ืฉื—ืจื•ืจ ื”ื–ื™ื›ืจื•ืŸ ื”ืžืฉื•ื™ืš ืืœื™ื”ื (use-after-free ืขืงื‘ ื”ืงืจื™ืื” ืœืžื‘ื ื” isotp_sock ืฉื›ื‘ืจ ืฉื•ื—ืจืจ ื›ืืฉืจ ื ืงืจื isotp_rcv()). ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ื ืชื•ื ื™ื, ืืชื” ื™ื›ื•ืœ ืœืขืงื•ืฃ ืืช ื”ืžืฆื‘ื™ืข ืœืคื•ื ืงืฆื™ื” sk_error_report() ื•ืœื”ืคืขื™ืœ ืืช ื”ืงื•ื“ ืฉืœืš ื‘ืจืžืช ื”ืงืจื ืœ.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”