GRUB8 ããŒãããŒããŒã® 2 ä»¶ã®è匱æ§ã«é¢ããæ å ±ãå ¬éãããŸããããããã®è匱æ§ã«ãããUEFI ã»ãã¥ã¢ ããŒã ã¡ã«ããºã ããã€ãã¹ããæªæ€èšŒã®ã³ãŒããå®è¡ãããå¯èœæ§ããããŸããããšãã°ãããŒãããŒããŒãŸãã¯ã«ãŒãã« ã¬ãã«ã§å®è¡ããããã«ãŠã§ã¢ãå®è£ ãããŸãã
ã»ãšãã©ã®å Žåã LinuxUEFIã»ãã¥ã¢ããŒãã¢ãŒãã§æ€èšŒæžã¿ããŒãã䜿çšãããã£ã¹ããªãã¥ãŒã·ã§ã³ã¯ãMicrosoftã«ãã£ãŠããžã¿ã«çœ²åãããå°ããªã·ã ã¬ã€ã€ãŒã䜿çšããŸãããã®ã¬ã€ã€ãŒã¯ç¬èªã®èšŒææžã䜿çšããŠGRUB2ãæ€èšŒããããããã£ã¹ããªãã¥ãŒã·ã§ã³éçºè ã¯ã«ãŒãã«ãšGRUBã®ã¢ããããŒãããšã«Microsoftã«éç¥ããå¿ èŠããªããªããŸããGRUB2ã®è匱æ§ã«ãããã·ã æ€èšŒãæåããåŸããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãèµ·åããåã«ä»»æã®ã³ãŒããå®è¡ã§ããŸããããã«ãããã»ãã¥ã¢ããŒããæå¹ã«ãªã£ãŠããå Žåãæ»æè ã¯ä¿¡é Œãã§ãŒã³ãçªç Žããå¥ã®OSã®èµ·åããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã³ã³ããŒãã³ãã®å€æŽãããã¯ããŠã³ä¿è·ã®ãã€ãã¹ãªã©ããã®åŸã®ããŒãããã»ã¹ãå®å šã«å¶åŸ¡ã§ããããã«ãªããŸãã
æšå¹Žã®BootHoleè匱æ§ãšåæ§ã«ãããŒãããŒããŒãæŽæ°ããã ãã§ã¯ãã®åé¡ã¯è§£æ±ºããŸãããæ»æè ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®çš®é¡ã«é¢ä¿ãªããå€ãè匱ãªããžã¿ã«çœ²åä»ãGRUB2ããŒãžã§ã³ãå«ãããŒãã¡ãã£ã¢ã䜿çšããŠUEFIã»ãã¥ã¢ããŒãã䟵害ã§ããããã§ãããã®åé¡ã¯UEFI倱å¹ãªã¹ãïŒDBXïŒãæŽæ°ããããšã«ãã£ãŠã®ã¿è§£æ±ºã§ããŸãããããã«ããå€ãã€ã³ã¹ããŒã«ã¡ãã£ã¢ã®äœ¿çšãã§ããªããªããŸãã Linux.
倱å¹èšŒææžã®ãªã¹ããæŽæ°ããããã¡ãŒã ãŠã§ã¢ãæèŒããã·ã¹ãã ã§ã¯ãæŽæ°ããããã£ã¹ããªãã¥ãŒã·ã§ã³ãã«ãã®ã¿ãUEFIã»ãã¥ã¢ããŒãã¢ãŒãã§èµ·åã§ããŸãã Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã¯ãã€ã³ã¹ããŒã©ãŒãããŒãããŒããŒãã«ãŒãã«ããã±ãŒãžãfwupdãã¡ãŒã ãŠã§ã¢ãããã³ã·ã ã¬ã€ã€ãŒãæŽæ°ãããããã®æ°ããããžã¿ã«çœ²åãçæããå¿ èŠããããŸãããŠãŒã¶ãŒã¯ãã€ã³ã¹ããŒã«ã€ã¡ãŒãžããã®ä»ã®èµ·åå¯èœãªã¡ãã£ã¢ãæŽæ°ãã倱å¹èšŒææžã®ãªã¹ãïŒdbxïŒãUEFIãã¡ãŒã ãŠã§ã¢ã«ããŒãããå¿ èŠããããŸããUEFIã®dbxãæŽæ°ããããŸã§ãOSã®æŽæ°ã«é¢ä¿ãªãã·ã¹ãã ã¯è匱ãªãŸãŸã§ããè匱æ§ä¿®æ£ã®ç¶æ³ã¯ã次ã®ããŒãžã§ç¢ºèªã§ããŸãã UbuntuSUSEãRHELã Debian.
倱å¹ããèšŒææžé åžæã«çºçããåé¡ã解決ããããã«ãå°æ¥çã«ã¯GRUB2ãshimãfwupdã§ãµããŒããå®è£ ãããŠããSBATïŒUEFI Secure Boot Advanced TargetingïŒæ©æ§ãå©çšããäºå®ã§ã次åã¢ããããŒããã察å¿äºå®ã§ãã dbxtool ããã±ãŒãžã«ãã£ãŠæäŸãããæ©èœã®ä»£ããã«äœ¿çšãããŸãã SBAT 㯠Microsoft ãšå ±åéçºãããã¡ãŒã«ãŒã補åãã³ã³ããŒãã³ããããŒãžã§ã³æ å ±ãå«ãæ°ããã¡ã¿ããŒã¿ã UEFI ã³ã³ããŒãã³ãã®å®è¡å¯èœãã¡ã€ã«ã«è¿œå ããŸããæå®ãããã¡ã¿ããŒã¿ã¯ããžã¿ã«çœ²åã§èšŒæãããŠãããUEFI ã»ãã¥ã¢ ããŒãã®èš±å¯ãŸãã¯çŠæ¢ã³ã³ããŒãã³ãã®ãªã¹ãã«è¿œå ã§å«ããããšãã§ããŸãããããã£ãŠãSBAT ã䜿çšãããšãã»ãã¥ã¢ ããŒãçšã®ããŒãåçæããããã«ãŒãã«ãshimãgrub2ãããã³ fwupd ã®æ°ãã眲åãçæãããããããšãªãã倱å¹äžã«ã³ã³ããŒãã³ãã®ããŒãžã§ã³çªå·ãæäœã§ããŸãã
ç¹å®ãããè匱æ§:
- CVE-2020-14372 â GRUB2 ã® acpi ã³ãã³ãã䜿çšãããšãããŒã«ã« ã·ã¹ãã ã®ç¹æš©ãŠãŒã¶ãŒã¯ãSSDT (ã»ã«ã³ã㪠ã·ã¹ãã èšè¿°ããŒãã«) ã /boot/efi ãã£ã¬ã¯ããªã«é 眮ããgrub.cfg ã®èšå®ã倿Žããããšã§ã倿Žããã ACPI ããŒãã«ãããŒãã§ããŸããã»ãã¥ã¢ ããŒã ã¢ãŒãã¯ã¢ã¯ãã£ãã§ãããææ¡ããã SSDT ã¯ã«ãŒãã«ã«ãã£ãŠå®è¡ãããUEFI ã»ãã¥ã¢ ããŒã ãã€ãã¹ ãã¹ããããã¯ãã LockDown ä¿è·ãç¡å¹ã«ããããã«äœ¿çšã§ããŸãããã®çµæãæ»æè ã¯ããžã¿ã«çœ²åããã§ãã¯ããã«ãkexec ã¡ã«ããºã ãéããŠã«ãŒãã« ã¢ãžã¥ãŒã«ã®ããŒããã³ãŒãã®å®è¡ãå®è¡ã§ããŸãã
- CVE-2020-25632 ã¯ãrmmod ã³ãã³ãã®å®è£ ã«ããã use-after-free ã¡ã¢ãª ã¢ã¯ã»ã¹ã§ãããã¢ãžã¥ãŒã«ã«é¢é£ä»ããããäŸåé¢ä¿ãèæ ®ããã«ã¢ãžã¥ãŒã«ãã¢ã³ããŒãããããšãããšçºçããŸãããã®è匱æ§ã¯ãã»ãã¥ã¢ ããŒãæ€èšŒããã€ãã¹ããŠã³ãŒããå®è¡ããå¯èœæ§ã®ãããšã¯ã¹ããã€ãã®äœæãæé€ãããã®ã§ã¯ãããŸããã
- CVE-2020-25647 USB ããã€ã¹ã®åæåæã«åŒã³åºããã grub_usb_device_initialize() 颿°ã®ç¯å²å€æžã蟌ã¿ããã®åé¡ã¯ãUSB æ§é ã«å²ãåœãŠããããããã¡ã®ãµã€ãºã«å¯Ÿå¿ããªããµã€ãºã®ãã©ã¡ãŒã¿ãåºåãããç¹å¥ã«çšæããã USB ããã€ã¹ãæ¥ç¶ããããšã«ãã£ãŠæªçšãããå¯èœæ§ããããŸããæ»æè 㯠USB ããã€ã¹ãæäœããããšã§ãã»ãã¥ã¢ ããŒãã§æ€èšŒãããŠããªãã³ãŒããå®è¡ããå¯èœæ§ããããŸãã
- CVE-2020-27749 ã¯ãgrub_parser_split_cmdline() 颿°ã«ããããããã¡ ãªãŒããŒãããŒã§ãããGRUB2 ã³ãã³ã ã©ã€ã³ã§ 1 KB ãè¶ ãã倿°ãæå®ããããšã«ãã£ãŠçºçããå¯èœæ§ããããŸãããã®è匱æ§ã«ãããã³ãŒãå®è¡ã«ããã»ãã¥ã¢ ããŒãããã€ãã¹ãããå¯èœæ§ããããŸãã
- CVE-2020-27779 â Cutmem ã³ãã³ãã䜿çšãããšãæ»æè ãã¡ã¢ãªããã¢ãã¬ã¹ç¯å²ãåé€ããŠã»ãã¥ã¢ ããŒãããã€ãã¹ã§ããããã«ãªããŸãã
- CVE-2021-3418 - shim_lock ãžã®å€æŽã«ãããæšå¹Žã®èåŒ±æ§ CVE-2020-15705 ãæªçšãã远å ã®ãã¯ã¿ãŒãäœæãããŸããã GRUB2 ã®çœ²åã«äœ¿çšãããèšŒææžã dbx ã«ã€ã³ã¹ããŒã«ããããšã«ãããGRUB2 ã¯çœ²åãæ€èšŒããã«ä»»æã®ã«ãŒãã«ãçŽæ¥ããŒãã§ããããã«ãªããŸããã
- CVE-2021-20225 - éåžžã«å€ãã®ãªãã·ã§ã³ãæå®ããŠã³ãã³ããå®è¡ãããšãç¯å²å€ã®ããŒã¿ãæžã蟌ãŸããå¯èœæ§ããããŸãã
- CVE-2021-20233 - åŒçšç¬Šã䜿çšããå Žåã®ãããã¡ ãµã€ãºã®èšç®ãæ£ãããªããããããŒã¿ãç¯å²å€ã«æžã蟌ãŸããå¯èœæ§ããããŸãããµã€ãºãèšç®ããéãäžéåŒçšç¬Šããšã¹ã±ãŒãããã«ã¯ XNUMX æåãå¿ èŠã§ãããšæ³å®ãããŸããããå®éã«ã¯ XNUMX æåãå¿ èŠã§ããã
åºæïŒ ãªãŒãã³ããã.ru
