แž“แŸ…แž€แŸ’แž“แžปแž„แž€แžถแžšแž แŸ…แž”แŸ’แžšแž–แŸแž“แŸ’แž’ futex แž›แž‘แŸ’แž’แž—แžถแž–แž“แŸƒแž€แžถแžšแž”แŸ’แžšแžแžทแž”แžแŸ’แžแžทแž€แžผแžŠแžขแŸ’แž“แž€แž”แŸ’แžšแžพแž”แŸ’แžšแžถแžŸแŸ‹แž“แŸ…แž€แŸ’แž“แžปแž„แž”แžšแžทแž”แž‘แž“แŸƒแžแžบแžŽแŸ‚แž›แžแŸ’แžšแžผแžœแž”แžถแž“แžšแž€แžƒแžพแž‰ แž“แžทแž„แž›แžปแž”แž”แŸ†แž”แžถแžแŸ‹

แž“แŸ…แž€แŸ’แž“แžปแž„แž€แžถแžšแžขแž“แžปแžœแžแŸ’แžแž“แŸƒแž€แžถแžšแž แŸ…แž”แŸ’แžšแž–แŸแž“แŸ’แž’ futex (fast userspace mutex) แž€แžถแžšแž”แŸ’แžšแžพแž”แŸ’แžšแžถแžŸแŸ‹แžขแž„แŸ’แž‚แž…แž„แž…แžถแŸ†แž‡แž„แŸ‹แž”แž“แŸ’แž‘แžถแž”แŸ‹แž–แžธแžฅแžแž‚แžทแžแžแŸ’แž›แŸƒแžแŸ’แžšแžผแžœแž”แžถแž“แžšแž€แžƒแžพแž‰ แž“แžทแž„แž›แžปแž”แž…แŸ„แž›แŸ” แž“แŸแŸ‡โ€‹แž‡แžถโ€‹แž€แžถแžšโ€‹แžขแž“แžปแž‰แŸ’แž‰แžถแžโ€‹แžฑแŸ’แž™โ€‹แžขแŸ’แž“แž€โ€‹แžœแžถแž™โ€‹แž”แŸ’แžšแž แžถแžšโ€‹แž”แŸ’แžšแžแžทแž”แžแŸ’แžแžทโ€‹แž€แžผแžŠโ€‹แžšแž”แžŸแŸ‹โ€‹แžแŸ’แž›แžฝแž“โ€‹แž€แŸ’แž“แžปแž„โ€‹แž”แžšแžทแž”แž‘โ€‹แž“แŸƒโ€‹แžแžบแžŽแŸ‚แž›โ€‹แžŠแŸ„แž™โ€‹แž˜แžถแž“โ€‹แž•แž›โ€‹แžœแžทแž”แžถแž€โ€‹แž‡แžถโ€‹แž”แž“แŸ’แžโ€‹แž”แž“แŸ’แž‘แžถแž”แŸ‹โ€‹แž–แžธโ€‹แž‘แžทแžŠแŸ’แž‹แž—แžถแž–โ€‹แžŸแžปแžœแžแŸ’แžแžทแž—แžถแž–แŸ” แž—แžถแž–แž„แžถแž™แžšแž„แž‚แŸ’แžšแŸ„แŸ‡แž‚แžบแž“แŸ…แž€แŸ’แž“แžปแž„แž€แžผแžŠแžขแŸ’แž“แž€แžŠแŸ„แŸ‡แžŸแŸ’แžšแžถแž™แž€แŸ†แž แžปแžŸแŸ”

แž€แžถแžšแž€แŸ‚แžแž˜แŸ’แžšแžผแžœ แž—แžถแž–แž„แžถแž™แžšแž„แž‚แŸ’แžšแŸ„แŸ‡แž“แŸแŸ‡แž”แžถแž“แž”แž„แŸ’แž แžถแž‰แžแŸ’แž›แžฝแž“แž“แŸ…แž€แŸ’แž“แžปแž„แž”แž“แŸ’แž‘แžถแžแŸ‹แž˜แŸแžšแž”แžŸแŸ‹แž›แžธแž“แžปแž…แž“แŸ…แžแŸ’แž„แŸƒแž‘แžธ 28 แžแŸ‚แž˜แž€แžšแžถ แž แžพแž™แž˜แžฝแž™แžแŸ’แž„แŸƒแž˜แžปแž“แž€แžถแž›แž–แžธแž˜แŸ’แžŸแžทแž›แž˜แžทแž‰แžœแžถแž”แžถแž“แž…แžผแž›แž‘แŸ…แž€แŸ’แž“แžปแž„แžแžบแžŽแŸ‚แž› 5.10.12, 5.4.94, 4.19.172, 4.14.218 แŸ”

แž€แŸ’แž“แžปแž„แžขแŸ†แžกแžปแž„แž–แŸแž›แž–แžทแž—แžถแž€แŸ’แžŸแžถแžขแŸ†แž–แžธแž€แžถแžšแž‡แžฝแžŸแž‡แžปแž›แž“แŸแŸ‡ แžœแžถแžแŸ’แžšแžผแžœแž”แžถแž“แžŽแŸ‚แž“แžถแŸ†แžแžถ แž—แžถแž–แž„แžถแž™แžšแž„แž‚แŸ’แžšแŸ„แŸ‡แž“แŸแŸ‡แž˜แžถแž“แž“แŸ…แž€แŸ’แž“แžปแž„แžแžบแžŽแŸ‚แž›แž‘แžถแŸ†แž„แžขแžŸแŸ‹แž…แžถแž”แŸ‹แžแžถแŸ†แž„แž–แžธแž†แŸ’แž“แžถแŸ† 2008แŸ–

https://www.openwall.com/lists/oss-security/2021/01/29/3

FWIW, this commit has: Fixes: 1b7558e457ed ("futexes: fix fault handling in futex_lock_pi") and that other commit is from 2008. So probably all currently maintained Linux distros and deployments are affected, unless something else mitigated the issue in some kernel versions.

แž”แŸ’แžšแž—แž–: linux.org.ru