ืฉื—ืจื•ืจ ืกืคืจื™ื™ืช ืžืขืจื›ืช Glibc 2.32

ืœืื—ืจ ืฉื™ืฉื” ื—ื•ื“ืฉื™ื ืฉืœ ืคื™ืชื•ื— ืคื•ืจืกื ืฉื—ืจื•ืจ ืกืคืจื™ื™ืช ืžืขืจื›ืช ืกืคืจื™ื™ืช GNU C (glibc) 2.32, ื”ืชื•ืื ื‘ืื•ืคืŸ ืžืœื ืœื“ืจื™ืฉื•ืช ืฉืœ ืชืงื ื™ ISO C11 ื•-POSIX.1-2017. ื”ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื” ื›ื•ืœืœืช ืชื™ืงื•ื ื™ื ืž-67 ืžืคืชื—ื™ื.

ืžืืœื” ืฉื™ื•ืฉืžื• ื‘-Glibc 2.32 ืฉื™ืคื•ืจื™ื ืืชื” ื™ื›ื•ืœ ืœืฆื™ื™ืŸ:

  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืžืขื‘ื“ื™ Synopsys ARC HS (ARCv2 ISA). ื”ื™ืฆื™ืื” ื“ื•ืจืฉืช ืœืคื—ื•ืช binutils 2.32, gcc 8.3 ื•- Linux kernel 5.1 ื›ื“ื™ ืœืคืขื•ืœ. ืฉืœื•ืฉ ื’ืจืกืื•ืช ABI ื ืชืžื›ื•ืช: arc-linux-gnu, arc-linux-gnuhf ื•-arceb-linux-gnu (big-endian);
  • ื˜ืขื™ื ืช ืžื•ื“ื•ืœื™ ื‘ื™ืงื•ืจืช ืฉืฆื•ื™ื ื• ื‘ืกืขื™ืคื™ื DT_AUDIT ื•
    DT_DEPAUDIT ืฉืœ ืงื•ื‘ืฅ ื”ื”ืคืขืœื”.

  • ืขื‘ื•ืจ ืืจื›ื™ื˜ืงื˜ื•ืจืช powerpc64le, ืžื™ื•ืฉืžืช ืชืžื™ื›ื” ื‘ืกื•ื’ ื”ื›ืคื•ืœ ื”ืืจื•ืš IEEE128, ืืฉืจ ืžื•ืคืขืœืช ื‘ืขืช ื‘ื ื™ื™ื” ืขื ืืคืฉืจื•ืช "-mabi=ieeelongdouble".
  • ื›ืžื” ืžืžืฉืงื™ API ืžืกื•ืžื ื™ื ื‘ืชื›ื•ื ืช 'ื’ื™ืฉื”' ืฉืœ GCC, ื”ืžืืคืฉืจืช ืœื”ืคื™ืง ืื–ื”ืจื•ืช ื˜ื•ื‘ื•ืช ื™ื•ืชืจ ื‘ืขืช ื”ื™ื“ื•ืจ ื‘-GCC 10 ื›ื“ื™ ืœื–ื”ื•ืช ื’ืœื™ืฉื” ืืคืฉืจื™ืช ืฉืœ ืžืื’ืจ ื•ืชืจื—ื™ืฉื™ื ืื—ืจื™ื ืžื—ื•ืฅ ืœืชื—ื•ื.
  • ืขื‘ื•ืจ ืžืขืจื›ื•ืช ืœื™ื ื•ืงืก, ื”ืคื•ื ืงืฆื™ื•ืช pthread_attr_setsigmask_np ื•
    pthread_attr_getsigmask_np, ื”ืžืขื ื™ืงื™ื ืœืืคืœื™ืงืฆื™ื” ืืช ื”ื™ื›ื•ืœืช ืœืฆื™ื™ืŸ ืžืกื™ื›ืช ืื•ืชื•ืช ืขื‘ื•ืจ ืฉืจืฉื•ืจื™ื ืฉื ื•ืฆืจื• ื‘ืืžืฆืขื•ืช pthread_create.

  • ื ืชื•ื ื™ ืงื™ื“ื•ื“, ืžื™ื“ืข ืขืœ ืกื•ื’ ืชื•ื•ื™ื ื•ื˜ื‘ืœืื•ืช ืชืขืชื™ืง ืขื•ื“ื›ื ื• ื›ื“ื™ ืœืชืžื•ืš ื‘ืžืคืจื˜ Unicode 13.0.0;
  • ื ื•ืกืฃ ืงื•ื‘ืฅ ื›ื•ืชืจืช ื—ื“ืฉ , ื”ืžื’ื“ื™ืจ ืืช ื”ืžืฉืชื ื” __libc_single_threaded, ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื‘ื™ื™ืฉื•ืžื™ื ืขื‘ื•ืจ ืื•ืคื˜ื™ืžื™ื–ืฆื™ื•ืช ืฉืœ ื—ื•ื˜ ื™ื—ื™ื“.
  • ื ื•ืกืคื• ืคื•ื ืงืฆื™ื•ืช sigabbrev_np ื•-sigdescr_np ื”ืžื—ื–ื™ืจื•ืช ืืช ื”ืฉื ื•ื”ืชื™ืื•ืจ ื”ืžืงื•ืฆืจ ืฉืœ ื”ืื•ืช (ืœื“ื•ื’ืžื”, "HUP" ื•-"Hangup" ืขื‘ื•ืจ SIGHUP).
  • ื ื•ืกืคื• ืคื•ื ืงืฆื™ื•ืช strerrorname_np ื•-strerrordesc_np ื”ืžื—ื–ื™ืจื•ืช ืืช ื”ืฉื ื•ื”ืชื™ืื•ืจ ืฉืœ ื”ืฉื’ื™ืื” (ืœื“ื•ื’ืžื”, "EINVAL" ื•-"ืืจื’ื•ืžื ื˜ ืœื ื—ื•ืงื™" ืขื‘ื•ืจ EINVAL).
  • ืขื‘ื•ืจ ืคืœื˜ืคื•ืจืžืช ARM64, ื ื•ืกืฃ ื“ื’ืœ "--enable-standard-branch-protection" (ืื• -branch-protection=standard ื‘-GCC), ื”ืžืืคืฉืจ ืœืžื ื’ื ื•ืŸ ARMv8.5-BTI (Branch Target Indicator) ืœื”ื’ืŸ ืขืœ ื‘ื™ืฆื•ืข ืžืขืจื›ื™ ืคืงื•ื“ื•ืช ืฉืืกื•ืจ ืœื‘ืฆืข.ืžืขื‘ืจื™ื ืžืกื•ืขืคื™ื. ื—ืกื™ืžืช ืžืขื‘ืจื™ื ืœืงื˜ืขื™ ืงื•ื“ ืฉืจื™ืจื•ืชื™ื™ื ืžื™ื•ืฉืžืช ื›ื“ื™ ืœืžื ื•ืข ื™ืฆื™ืจืช ื’ืื“ื’'ื˜ื™ื ื‘ื ื™ืฆื•ืœื™ื ื”ืžืฉืชืžืฉื™ื ื‘ื˜ื›ื ื™ืงื•ืช ืชื›ื ื•ืช ืžื•ื›ื•ื•ื ื•ืช ื”ื—ื–ืจื” (ROP - Return-Oriented Programming; ื”ืชื•ืงืฃ ืœื ืžื ืกื” ืœืžืงื ืืช ื”ืงื•ื“ ืฉืœื• ื‘ื–ื™ื›ืจื•ืŸ, ืืœื ืคื•ืขืœ ืขืœ ื—ืœืงื™ื ืฉื›ื‘ืจ ืงื™ื™ืžื™ื ืฉืœ ื”ื•ืจืื•ืช ืžื›ื•ื ื” ื”ืžืกืชื™ื™ืžื•ืช ื‘ื”ื•ืจืื” ื‘ืงืจืช ื—ื–ืจื”, ืฉืžืžื ื” ื ื‘ื ื™ืช ืฉืจืฉืจืช ืฉื™ื—ื•ืช ืœืงื‘ืœืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ื”ืจืฆื•ื™ื”).
  • ื‘ื•ืฆืข ื ื™ืงื•ื™ ื’ื“ื•ืœ ืฉืœ ืชื›ื•ื ื•ืช ืžื™ื•ืฉื ื•ืช, ื›ื•ืœืœ ื”ืกืจืช ื”ืืคืฉืจื•ื™ื•ืช "--enable-obsolete-rpc" ื•-"--enable-obsolete-nsl", ืงื•ื‘ืฅ ื”ื›ื•ืชืจืช . ื”ืคื•ื ืงืฆื™ื•ืช sstk, siginterrupt, sigpause, sighold, sigrelse, sigignore ื•-sigset, ื”ืžืขืจื›ื™ื sys_siglist, _sys_siglist ื•-sys_sigabbrev, ื”ืกืžืœื™ื sys_errlist, _sys_errlist, sys_nerr ื•-_sys_nerr, ื•ืžื•ื“ื•ืœ ื”-NSS ื”ื•ืกืจ.
  • ldconfig ื”ื•ืขื‘ืจื” ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืœืฉื™ืžื•ืฉ ื‘ืคื•ืจืžื˜ ld.so.cache ื”ื—ื“ืฉ, ืฉื ืชืžืš ื‘-glibc ื›ื‘ืจ ื›ืžืขื˜ 20 ืฉื ื”.
  • ืคื’ื™ืขื•ื™ื•ืช ืฉืชื•ืงื ื•:
    • CVE-2016-10228 - ืœื•ืœืื” ื‘ื›ืœื™ ื”ืฉื™ืจื•ืช iconv ืžืชืจื—ืฉืช ื‘ืขืช ื”ืคืขืœื” ืขื ื”ืืคืฉืจื•ืช "-c" ื‘ืขืช ืขื™ื‘ื•ื“ ื ืชื•ื ื™ื ืฉื’ื•ื™ื™ื ืฉืœ ืจื™ื‘ื•ื™ ื‘ืชื™ื.
    • CVE-2020-10029 ืฉื—ื™ืชื•ืช ืžื—ืกื ื™ืช ื‘ืขืช ืงืจื™ืื” ืœืคื•ื ืงืฆื™ื•ืช ื˜ืจื™ื’ื•ื ื•ืžื˜ืจื™ื•ืช ืขื ืืจื’ื•ืžื ื˜ ืคืกืื•ื“ื•-null.
    • CVE-2020-1752 - ื’ื™ืฉื” ืœื–ื™ื›ืจื•ืŸ ืœืœื ืฉื™ืžื•ืฉ ื‘ืคื•ื ืงืฆื™ื™ืช ื’ืœื•ื‘ ื‘ืขืช ื”ืจื—ื‘ืช ื”ืคื ื™ื” ืœืกืคืจื™ื™ืช ื”ื‘ื™ืช ("~ืžืฉืชืžืฉ") ื‘ื ืชื™ื‘ื™ื.
    • CVE-2020-6096 โ€“ ื˜ื™ืคื•ืœ ืฉื’ื•ื™ ื‘ืคืœื˜ืคื•ืจืžืช ARMv7 ืฉืœ ืขืจื›ื™ ืคืจืžื˜ืจื™ื ืฉืœื™ืœื™ื™ื ื‘-memcpy() ื•- memmove(), ื”ืงื•ื‘ืข ืืช ื’ื•ื“ืœ ื”ืื–ื•ืจ ื”ืžื•ืขืชืง. ืžืืคืฉืจ ืืจื’ืŸ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ื‘ืขืช ืขื™ื‘ื•ื“ ื ืชื•ื ื™ื ื”ืžืขื•ืฆื‘ื™ื ื‘ืฆื•ืจื” ืžืกื•ื™ืžืช ื‘ืคื•ื ืงืฆื™ื•ืช memcpy() ื•- memmove(). ื–ื” ืžืฉืžืขื•ืชื™ ืฉื”ื‘ืขื™ื” ื ืฉืืจ ืœื ืชื•ืงืŸ ื‘ืžืฉืš ื›ืžืขื˜ ื—ื•ื“ืฉื™ื™ื ืžืื– ืฉื”ืžื™ื“ืข ื ื—ืฉืฃ ืœืฆื™ื‘ื•ืจ ื•ื—ืžื™ืฉื” ื—ื•ื“ืฉื™ื ืžืื– ื”ื•ื“ืขื” ืœืžืคืชื—ื™ Glibc.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”