FreeBSD ืชื™ืงืŸ 6 ืคื’ื™ืขื•ื™ื•ืช

ืขืœ FreeBSD ื—ื•ืกืœื• ืฉืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื”ืžืืคืฉืจื•ืช ืœืš ืœื‘ืฆืข ืžืชืงืคืช DoS, ืœืขื–ื•ื‘ ืืช ืกื‘ื™ื‘ืช ื”ื›ืœื, ืื• ืœืงื‘ืœ ื’ื™ืฉื” ืœื ืชื•ื ื™ ืœื™ื‘ื”. ื”ื‘ืขื™ื•ืช ืชื•ืงื ื• ื‘ืขื“ื›ื•ื ื™ื 12.1-RELEASE-p3 ื•-11.3-RELEASE-p7.

  • CVE-2020-7452 - ืขืงื‘ ืฉื’ื™ืื” ื‘ื™ื™ืฉื•ื ืžืžืฉืงื™ ืจืฉืช ื•ื™ืจื˜ื•ืืœื™ื™ื ืฉืœ ืืคื™ื™ืจ, ืžืฉืชืžืฉ ื‘ืขืœ ื–ื›ื•ื™ื•ืช PRIV_NET_IFCREATE ืื• ืฉื•ืจืฉ ืžืกื‘ื™ื‘ืช ื›ืœื ืžื‘ื•ื“ื“ืช ื™ื›ื•ืœ ืœื’ืจื•ื ืœืงืจื ืœ ืœืงืจื•ืก ืื• ืœื”ืคืขื™ืœ ืืช ื”ืงื•ื“ ืฉืœื• ืขื ื–ื›ื•ื™ื•ืช ืœื™ื‘ื”.
  • CVE-2020-7453 - ืื™ืŸ ื‘ื“ื™ืงื” ืœืกื™ื•ื ืžื—ืจื•ื–ืช ืขื ืชื• null ื‘ืขืช ืขื™ื‘ื•ื“ ืืคืฉืจื•ืช "osrelease" ื“ืจืš ืงืจื™ืืช ื”ืžืขืจื›ืช jail_set, ืžืืคืฉืจ ืœืš ืœื”ืฉื™ื’ ืืช ื”ืชื•ื›ืŸ ืฉืœ ืžื‘ื ื™ ื–ื™ื›ืจื•ืŸ ื”ืœื™ื‘ื” ื”ืกืžื•ื›ื™ื ื›ืืฉืจ ืžื ื”ืœ ืกื‘ื™ื‘ืช ื”ื›ืœื ืžื‘ืฆืข ืงืจื™ืืช jail_get, ืื ืชืžื™ื›ื” ื‘ื”ืคืขืœืช ื”ื›ืœื ื”ืžืงื ืŸ ืกื‘ื™ื‘ื•ืช ืžื•ืคืขืœื•ืช ื“ืจืš ื”ืคืจืžื˜ืจ children.max (ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื™ืฆื™ืจืช ืกื‘ื™ื‘ื•ืช ื›ืœื ืžืงื•ื ื ื•ืช ืืกื•ืจื”).
  • CVE-2019-15877 - ื‘ื“ื™ืงื” ืฉื’ื•ื™ื” ืฉืœ ื”ืจืฉืื•ืช ื‘ืขืช ื’ื™ืฉื” ืœืžื ื”ืœ ื”ื”ืชืงืŸ ixl ื‘ืืžืฆืขื•ืช ioctl ืžืืคืฉืจ ืœืžืฉืชืžืฉ ื—ืกืจ ื”ืจืฉืื•ืช ืœื”ืชืงื™ืŸ ืขื“ื›ื•ืŸ ืงื•ืฉื—ื” ืขื‘ื•ืจ ื”ืชืงื ื™ NVM.
  • CVE-2019-15876 - ื‘ื“ื™ืงื” ืฉื’ื•ื™ื” ืฉืœ ื”ืจืฉืื•ืช ื‘ืขืช ื’ื™ืฉื” ืœืžื ื”ืœ ื”ื”ืชืงืŸ ืื•ืกื” ื‘ืืžืฆืขื•ืช ioctl ืžืืคืฉืจ ืœืžืฉืชืžืฉ ื—ืกืจ ื”ืจืฉืื•ืช ืœืฉืœื•ื— ืคืงื•ื“ื•ืช ืœืงื•ืฉื—ื” ืฉืœ ืžืชืืžื™ ืจืฉืช Emulex OneConnect.
  • CVE-2020-7451 - ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืžืงื˜ืขื™ TCP SYN-ACK ืฉืชื•ื›ื ื ื• ื‘ืฆื•ืจื” ืžืกื•ื™ืžืช ื“ืจืš IPv6, ื ื™ืชืŸ ืœื“ืœื•ืฃ ื‘ื™ื™ื˜ ืื—ื“ ืฉืœ ื–ื™ื›ืจื•ืŸ ืœื™ื‘ื” ื‘ืจืฉืช (ื”ืฉื“ื” Traffic Class ืื™ื ื• ืžืื•ืชื—ืœ ื•ืžื›ื™ืœ ื ืชื•ื ื™ื ืฉื™ื•ืจื™ื™ื).
  • ืฉืœื•ืฉ ื˜ืขื•ื™ื•ืช ื‘ื“ืžื•ืŸ ืกื ื›ืจื•ืŸ ื–ืžืŸ ntpd ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื›ื“ื™ ืœื’ืจื•ื ืœืžื ื™ืขืช ืฉื™ืจื•ืช (ื”ื’ื•ืจื ืœืชื”ืœื™ืš ntpd ืœืงืจื•ืก).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”