Te whakaraeraetanga i roto i te punaha riipene kernel Netfilter Linux

Kua kitea he whakaraeraetanga i roto i te kernel Linux (kaore i tohua te CVE) ka taea e tetahi kaiwhakamahi o te rohe te whai mana pakiaka i roto i te punaha. Kua panuitia kua whakaritea he mahinga e whakaatu ana i te whiwhi mana pakiaka ki Ubuntu 22.04. He papaki hei whakatika i te raru kua whakaarohia kia whakauruhia ki roto i te kakano.

Ko te whakaraeraetanga ka puta mai i te uru ki tetahi waahi mahara kua wetekina (whakamahia-muri-kore) i te wa e raweke ana i nga rarangi huinga ma te whakamahi i te tono NFT_MSG_NEWSET i roto i te kōwae nf_tables. Hei whakahaere i te whakaeke, me uru ki nga nftables, ka taea te tiki i roto i nga mokowāingoa whatunga motuhake mena kei a koe nga mana CLONE_NEWUSER, CLONE_NEWNS, CLONE_NEWNET ranei (hei tauira, mena ka taea e koe te whakahaere i tetahi ipu taratahi).

Source: opennet.ru

Tāpiri i te kōrero