ืคื’ื™ืขื•ื™ื•ืช ื‘ืชืช ืžืขืจื›ืช ื”-QoS ืฉืœ ืœื™ื‘ืช ืœื™ื ื•ืงืก, ื”ืžืืคืฉืจื•ืช ืœืš ืœื”ืขืœื•ืช ืืช ื”ื”ืจืฉืื•ืช ืฉืœืš ื‘ืžืขืจื›ืช

ื–ื•ื”ื• ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก (CVE-2023-1281, CVE-2023-1829) ื”ืžืืคืฉืจื•ืช ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœื”ืขืœื•ืช ืืช ื”ื”ืจืฉืื•ืช ืฉืœื• ื‘ืžืขืจื›ืช. ื”ื”ืชืงืคื” ื“ื•ืจืฉืช ืกืžื›ื•ืช ืœื™ืฆื•ืจ ื•ืœืฉื ื•ืช ืžืกื•ื•ื’ื™ ืชืขื‘ื•ืจื”, ื”ื–ืžื™ื ื™ื ืขื ื–ื›ื•ื™ื•ืช CAP_NET_ADMIN, ืฉื ื™ืชืŸ ืœื”ืฉื™ื’ ืขื ื”ื™ื›ื•ืœืช ืœื™ืฆื•ืจ ืžืจื—ื‘ื™ ืฉืžื•ืช ืžืฉืชืžืฉื™ื. ื‘ืขื™ื•ืช ืžื•ืคื™ืขื•ืช ืžืื– ืœื™ื‘ืช 4.14 ื•ืžืชื•ืงื ื•ืช ื‘ืขื ืฃ 6.2.

ื”ืคื’ื™ืขื•ื™ื•ืช ื ื’ืจืžื•ืช ืขืœ ื™ื“ื™ ื’ื™ืฉื” ืœื–ื™ื›ืจื•ืŸ ืœืื—ืจ ืฉื—ืจื•ืจ (use-after-free) ื‘ืงื•ื“ ืžืกื•ื•ื’ ื”ืชืขื‘ื•ืจื” tcindex, ืฉื”ื•ื ื—ืœืง ืžืชืช-ืžืขืจื›ืช ื”-QoS (ืื™ื›ื•ืช ื”ืฉื™ืจื•ืช) ืฉืœ ืœื™ื‘ืช ืœื™ื ื•ืงืก. ื”ืคื’ื™ืขื•ืช ื”ืจืืฉื•ื ื” ืžืชื‘ื˜ืืช ื‘ืฉืœ ืžืฆื‘ ื’ื–ืข ื‘ืขืช ืขื“ื›ื•ืŸ ืžืกื ื ื™ hash ืœื ืื•ืคื˜ื™ืžืœื™ื™ื, ื•ื”ื—ื•ืœื” ื”ืฉื ื™ื™ื” ื‘ืขืช ืžื—ื™ืงืช ืžืกื ืŸ hash ืื•ืคื˜ื™ืžืœื™. ืืชื” ื™ื›ื•ืœ ืœืขืงื•ื‘ ืื—ืจ ื”ืชื™ืงื•ืŸ ื‘ื”ืคืฆื•ืช ื‘ื“ืคื™ื ื”ื‘ืื™ื: Debian, Ubuntu, Gentoo, RHEL, SUSE, Fedora, Gentoo, Arch. ื›ื“ื™ ืœื—ืกื•ื ืืช ื ื™ืฆื•ืœ ื”ืคื’ื™ืขื•ืช ื‘ืคืชืจื•ืŸ ืขื•ืงืฃ, ืืชื” ื™ื›ื•ืœ ืœื”ืฉื‘ื™ืช ืืช ื”ื™ื›ื•ืœืช ืœื™ืฆื•ืจ ืžืจื—ื‘ื™ ืฉืžื•ืช ืขืœ ื™ื“ื™ ืžืฉืชืžืฉื™ื ืœืœื ื”ืจืฉืื•ืช ("sudo sysctl -w kernel.unprivileged_userns_clone=0").

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”