Ko te whakaraerae i roto i te vhost-net e taea ai te wehe wehe i roto i nga punaha i runga i te QEMU-KVM

Whakakitea nga korero mo whakaraeraetanga (CVE-2019-14835), ka taea e koe te haere ki tua atu o te punaha manuhiri i roto i te KVM (qemu-kvm) me te whakahaere i to waehere ki te taha o te taiao manaaki i roto i te horopaki o te kernel Linux. Ko te whakaraeraetanga kua whakaingoatia V-gHost. Ko te raruraru ka taea e te punaha manuhiri te hanga i nga tikanga mo te putunga putunga i roto i te kōwae kernel vhost-net (whatunga backend mo virtio), ka mahia ki te taha o te taiao manaaki. Ko te whakaeke ka taea e te tangata whakaeke me te whai mana ki te punaha manuhiri i te wa o te mahi miihini mariko.

Te Whakatika i te Raruraru whakauru kei roto i te Linux 5.3 kernel. Hei mahi mo te aukati i te whakaraeraetanga, ka taea e koe te whakakore i te hekenga ora o nga punaha manuhiri, te whakakore ranei i te kōwae vhost-net (tapirihia te "blacklist vhost-net" ki /etc/modprobe.d/blacklist.conf). Ka puta te raruraru mai i te kernel Linux 2.6.34. Kua whakaritea te whakaraeraetanga ki roto Ubuntu и Fedora, engari kare tonu i te whakatikatika Debian, Arch Linux, SUSE и RHEL.

Source: opennet.ru

Tāpiri i te kōrero