๊ถŒํ•œ ์ƒ์Šน์„ ํ—ˆ์šฉํ•˜๋Š” Linux์šฉ MCTP ํ”„๋กœํ† ์ฝœ ๊ตฌํ˜„์˜ ์ทจ์•ฝ์ 

Linux ์ปค๋„์—์„œ ์ทจ์•ฝ์ (CVE-2022-3977)์ด ํ™•์ธ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด ์ทจ์•ฝ์ ์€ ์ž ์žฌ์ ์œผ๋กœ ๋กœ์ปฌ ์‚ฌ์šฉ์ž๊ฐ€ ์‹œ์Šคํ…œ์—์„œ ๊ถŒํ•œ์„ ๋†’์ด๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ์ทจ์•ฝ์ ์€ ์ปค๋„ 5.18๋ถ€ํ„ฐ ๋‚˜ํƒ€๋‚˜๋ฉฐ ๋ธŒ๋žœ์น˜ 6.1์—์„œ ์ˆ˜์ •๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋ฐฐํฌํŒ์˜ ์ˆ˜์ • ์‚ฌํ•ญ์€ Debian, Ubuntu, Gentoo, RHEL, SUSE, Arch ํŽ˜์ด์ง€์—์„œ ์ถ”์ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ด ์ทจ์•ฝ์ ์€ ๊ด€๋ฆฌ ์ปจํŠธ๋กค๋Ÿฌ์™€ ๊ด€๋ จ ์žฅ์น˜ ๊ฐ„์˜ ์ƒํ˜ธ ์ž‘์šฉ์— ์‚ฌ์šฉ๋˜๋Š” MCTP(Management Component Transport Protocol) ํ”„๋กœํ† ์ฝœ ๊ตฌํ˜„์— ์กด์žฌํ•ฉ๋‹ˆ๋‹ค. ์ด ์ทจ์•ฝ์ ์€ ์†Œ์ผ“์„ ๋‹ซ๋Š” ๊ฒƒ๊ณผ ๋™์‹œ์— DROPTAG ioctl ์š”์ฒญ์„ ๋ณด๋‚ผ ๋•Œ use-after-free ๋ฉ”๋ชจ๋ฆฌ ์•ก์„ธ์Šค๋กœ ์ด์–ด์ง€๋Š” mctp_sk_unhash() ํ•จ์ˆ˜์˜ ๊ฒฝ์Ÿ ์กฐ๊ฑด์œผ๋กœ ์ธํ•ด ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : opennet.ru

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€