Floppy Driver Akasara Asina Kuchengetwa muLinux Kernel

Inosanganisirwa muLinux 5.3 kernel zvakagamuchirwa shanduko yekuwedzera imwe dziviriro yeioctl mafoni ane chekuita nemutyairi wefloppy, uye mutyairi pachawo anomakwa seasina kuchengetedzwa.
("nherera"), izvo zvinoreva kuguma kwekuedzwa kwayo.

Mutyairi anoonekwa seachinyakare, sezvo zvakaoma kuwana zvishandiso zvekushanda zvekuiedza - ese aripo ekunze madhiraivha, sekutonga, shandisa iyo USB interface. Panguva imwecheteyo, kubviswa kwemutyairi kubva kukernel kunokanganiswa nenyaya yekuti floppy disk controllers vachiri kutevedzerwa mu virtualization systems. Nokudaro, mutyairi achiri kuchengetwa mu kernel, asi kushanda kwayo kwakarurama hakuna kuvimbiswa.

Zvakare, mune floppy driver kubviswa vulnerability (CVE-2019-14283), kubvumira, kuburikidza nekushandiswa kweiyo ioctl, mushandisi asina rusarura anokwanisa kuisa floppy disk yake, kuverenga data kubva munzvimbo dzekurangarira kunze kwemiganhu yekopi buffer (semuenzaniso, nzvimbo dziri padyo dzinogona kunge dziine data yakasara kubva kudhisiki. cache uye yekuisa buffer). Kune rimwe divi, kusazvibata kunoramba kwakakosha sezvo mutyairi wefloppy anotakurwa otomatiki kana paine anoteedzera anoteedzera controller mune virtualization masisitimu (semuenzaniso, anoshandiswa nekusarudzika muQEMU), asi kune rimwe divi, kushandisa dambudziko, zvinodikanwa kuti mufananidzo wefloppy disk wakagadzirirwa neanorwisa ubatanidzwe.

Source: opennet.ru

Voeg