Ko te Atekōkiri Floppy i Maue Karekau i Te Kernel Linux

Kei roto i te Linux 5.3 kernel whakaaetia he huringa ki te taapiri atu i te whakamarumaru mo nga waea ioctl e pa ana ki te taraiwa piangore, a ko te taraiwa tonu ka tohua he kore tiaki.
(“pani”), e tohu ana te whakamutua o ana whakamatautau.

Ko te taraiwa e kiia ana he tawhito, na te mea he uaua ki te rapu taputapu mahi mo te whakamatautau - ko nga puku o waho o naianei, hei tikanga, whakamahia te atanga USB. I te wa ano, ko te tangohanga o te taraiwa mai i te kakano ka raruhia e te meka kei te peehia tonu nga kaiwhakahaere kōpae pīngore i roto i nga punaha mariko. Na reira, kei te rongoa tonu te taraiwa i roto i te kernel, engari kaore i te whakamanahia tana mahi tika.

Ano, i roto i te taraiwa pire whakakorea whakaraeraetanga (CVE-2019-14283), ka tuku, na roto i te raweke o te ioctl, he kaiwhakamahi kore whai mana e whai mana ana ki te whakauru i tana ake kōpae pīngore, ki te panui raraunga mai i nga waahi mahara kei waho atu o nga rohe o te taapiri kape (hei tauira, kei roto pea nga waahi tata he toenga raraunga mai i te kōpae. keteroki me te papaa whakauru). I tetahi taha, ko te whakaraeraetanga ka mau tonu mai i te mea ka utaina aunoatia te taraiwa piango ki te mea he rite tonu te mana whakahaere i roto i nga punaha mariko (hei tauira, ka whakamahia taunoa i roto i te QEMU), engari i tetahi atu taha, hei whakamahi i te raru, he mea tika kia honoa he whakaahua kōpae pīngore kua whakaritea e te kai-whakaeke.

Source: opennet.ru

Tāpiri i te kōrero