ืœื™ื‘ืช ืœื™ื ื•ืงืก 5.4 ืงื™ื‘ืœื” ืชื™ืงื•ื ื™ื ื›ื“ื™ ืœื”ื’ื‘ื™ืœ ืืช ื’ื™ืฉืช ื”ืฉื•ืจืฉ ืœื—ืœืง ื”ืคื ื™ืžื™ ืฉืœ ื”ืœื™ื‘ื”

ืœื™ื ื•ืก ื˜ื•ืจื‘ืœื“ืก ืงื™ื‘ืœ ืืช ื›ืœื•ืœื” ื‘ืžื”ื“ื•ืจื” ื”ืงืจื•ื‘ื” ืฉืœ ืœื™ื‘ืช ืœื™ื ื•ืงืก 5.4 ื”ื™ื ืกื˜ ืฉืœ ืชื™ืงื•ื ื™ื "ื ืขื™ืœื”", ืžื•ึผืฆึธืข ื“ื™ื•ื•ื™ื“ ื”ืื•ื•ืœืก (ืจื“ ื”ืื˜) ื•ืžืชื™ื• ื’ืืจื˜ (ืžืชื™ื• ื’ืืจื˜, ืขื•ื‘ื“ ื‘-Google) ื›ื“ื™ ืœื”ื’ื‘ื™ืœ ืืช ื’ื™ืฉืช ืžืฉืชืžืฉ ืฉื•ืจืฉ ืœืงืจื ืœ. ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ื”ืงืฉื•ืจื” ืœื ืขื™ืœื” ื›ืœื•ืœื” ื‘ืžื•ื“ื•ืœ LSM ืฉื ื˜ืขืŸ ืื•ืคืฆื™ื•ื ืœื™ (ืžื•ื“ื•ืœ ืื‘ื˜ื—ื” ืฉืœ ืœื™ื ื•ืงืก), ืฉืžืฆื™ื‘ ืžื—ืกื•ื ื‘ื™ืŸ UID 0 ืœื‘ื™ืŸ ื”ืœื™ื‘ื”, ื”ืžื’ื‘ื™ืœ ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืžืกื•ื™ืžืช ื‘ืจืžื” ื ืžื•ื›ื”.

ืื ืชื•ืงืฃ ืžืฉื™ื’ ื‘ื™ืฆื•ืข ืงื•ื“ ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ, ื”ื•ื ื™ื›ื•ืœ ืœื”ืคืขื™ืœ ืืช ื”ืงื•ื“ ืฉืœื• ื‘ืจืžืช ื”ืœื™ื‘ื”, ืœืžืฉืœ, ืขืœ ื™ื“ื™ ื”ื—ืœืคืช ื”ืœื™ื‘ื” ื‘ืืžืฆืขื•ืช kexec ืื• ื–ื™ื›ืจื•ืŸ ืงืจื™ืื”/ื›ืชื™ื‘ื” ื‘ืืžืฆืขื•ืช /dev/kmem. ื”ืชื•ืฆืื” ื”ื‘ืจื•ืจื” ื‘ื™ื•ืชืจ ืฉืœ ืคืขื™ืœื•ืช ื›ื–ื• ืขืฉื•ื™ื” ืœื”ื™ื•ืช ืœึทืขึฒืงื•ึนืฃ UEFI Secure Boot ืื• ืื—ื–ื•ืจ ื ืชื•ื ื™ื ืจื’ื™ืฉื™ื ื”ืžืื•ื—ืกื ื™ื ื‘ืจืžืช ื”ืœื™ื‘ื”.

ื‘ืชื—ื™ืœื”, ืคื•ื ืงืฆื™ื•ืช ื”ื’ื‘ืœืช ืฉื•ืจืฉ ืคื•ืชื—ื• ื‘ื”ืงืฉืจ ืฉืœ ื—ื™ื–ื•ืง ื”ื”ื’ื ื” ืขืœ ืืชื—ื•ืœ ืžืื•ืžืช, ื•ื”ืคืฆื•ืช ืžืฉืชืžืฉื•ืช ื‘ืชื™ืงื•ื ื™ื ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ื›ื“ื™ ืœื—ืกื•ื ืขืงื™ืคืช UEFI Secure Boot ื›ื‘ืจ ื–ืžืŸ ืจื‘. ื™ื—ื“ ืขื ื–ืืช, ื”ื’ื‘ืœื•ืช ื›ืืœื” ืœื ื ื›ืœืœื• ื‘ื”ืจื›ื‘ ื”ืขื™ืงืจื™ ืฉืœ ื”ื’ืจืขื™ืŸ ื‘ืฉืœ ื—ื™ืœื•ืงื™ ื“ืขื•ืช ื‘ื™ื™ืฉื•ืžื ื•ื—ืฉืฉื•ืช ืžืฉื™ื‘ื•ืฉ ืžืขืจื›ื•ืช ืงื™ื™ืžื•ืช. ืžื•ื“ื•ืœ ื”"ื ืขื™ืœื”" ืกืคื’ ืชื™ืงื•ื ื™ื ืฉื›ื‘ืจ ื”ื™ื• ื‘ืฉื™ืžื•ืฉ ื‘ื”ืคืฆื•ืช, ืฉืขื•ืฆื‘ื• ืžื—ื“ืฉ ื‘ืฆื•ืจื” ืฉืœ ืชืช-ืžืขืจื›ืช ื ืคืจื“ืช ืฉืื™ื ื” ืงืฉื•ืจื” ืœ-UEFI Secure Boot.

ืžืฆื‘ ื ืขื™ืœื” ืžื’ื‘ื™ืœ ืืช ื”ื’ื™ืฉื” ืœ-/dev/mem, /dev/kmem, /dev/port, /proc/kcore, debugfs, kprobes mode debug, mmiotrace, tracefs, BPF, PCMCIA CIS (ืžื‘ื ื” ืžื™ื“ืข ื›ืจื˜ื™ืก), ื›ืžื” ืžืžืฉืงื™ ACPI ื•-CPU ืื•ื’ืจื™ MSR, ืฉื™ื—ื•ืช kexec_file ื•-kexec_load ื—ืกื•ืžื•ืช, ืžืฆื‘ ืฉื™ื ื” ืืกื•ืจ, ื”ืฉื™ืžื•ืฉ ื‘-DMA ืขื‘ื•ืจ ื”ืชืงื ื™ PCI ืžื•ื’ื‘ืœ, ื™ื‘ื•ื ืงื•ื“ ACPI ืžืžืฉืชื ื™ EFI ืืกื•ืจ,
ืžื ื™ืคื•ืœืฆื™ื•ืช ืขื ื™ืฆื™ืื•ืช I/O ืื™ื ืŸ ืžื•ืชืจื•ืช, ื›ื•ืœืœ ืฉื™ื ื•ื™ ืžืกืคืจ ื”ื”ืคืกืงื” ื•ื™ืฆื™ืืช I/O ืขื‘ื•ืจ ื”ื™ืฆื™ืื” ื”ื˜ื•ืจื™ืช.

ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืžื•ื“ื•ืœ ื”ื ืขื™ืœื” ืื™ื ื• ืคืขื™ืœ, ื”ื•ื ื ื‘ื ื” ื›ืืฉืจ ื”ืืคืฉืจื•ืช SECURITY_LOCKDOWN_LSM ืžืฆื•ื™ื ืช ื‘-kconfig ื•ืžื•ืคืขืœืช ื‘ืืžืฆืขื•ืช ืคืจืžื˜ืจ ื”ืœื™ื‘ื” "lockdown=", ืงื•ื‘ืฅ ื”ื‘ืงืจื” "/sys/kernel/security/lockdown" ืื• ืืคืฉืจื•ื™ื•ืช ื”ืจื›ื‘ื” LOCK_DOWN_KERNEL_FORCE_*, ืฉื™ื›ื•ืœ ืœืงื—ืช ืืช ื”ืขืจื›ื™ื "ื™ื•ืฉืจื”" ื•"ืกื•ื“ื™ื•ืช". ื‘ืžืงืจื” ื”ืจืืฉื•ืŸ ื ื—ืกืžื•ืช ืชื›ื•ื ื•ืช ื”ืžืืคืฉืจื•ืช ืœื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื‘ืงืจื ืœ ื”ืคื•ืขืœ ืžืžืจื—ื‘ ื”ืžืฉืชืžืฉ, ื•ื‘ืžืงืจื” ื”ืฉื ื™ ืžื•ืฉื‘ืชืช ื’ื ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื” ื›ื“ื™ ืœื—ืœืฅ ืžื™ื“ืข ืจื’ื™ืฉ ืžื”ืงืจื ืœ.

ื—ืฉื•ื‘ ืœืฆื™ื™ืŸ ื›ื™ ื”ื ืขื™ืœื” ืจืง ืžื’ื‘ื™ืœื” ืืช ื”ื’ื™ืฉื” ื”ืกื˜ื ื“ืจื˜ื™ืช ืœืงืจื ืœ, ืืš ืื™ื ื” ืžื’ื™ื ื” ืžืคื ื™ ืฉื™ื ื•ื™ื™ื ื›ืชื•ืฆืื” ืžื ื™ืฆื•ืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื”. ื›ื“ื™ ืœื—ืกื•ื ืฉื™ื ื•ื™ื™ื ื‘ืœื™ื‘ื” ื”ืคื•ืขืœืช ื›ืืฉืจ ืžื ืฆืœื™ื ืืช ืคืจื•ื™ืงื˜ Openwall ืžืชืคืชื— ืžื•ื“ื•ืœ ื ืคืจื“ LKRG (Linux Kernel Runtime Guard).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”