Kubvisa iyo Linux Kernel yeBehavior-Changing Code yeMatanho Kutanga neX

Jason A. Donenfeld, munyori weVPN WireGuard, akakwevera kutarisisa kwevagadziri kune yakasviba hack iripo muLinux kernel code inoshandura maitiro emaitiro ane mazita anotanga nehunhu "X". Pakutanga kuona, zvigadziriso zvakadaro zvinowanzo shandiswa mumarootkits kusiya yakavanzika backdoor mukusunga, asi ongororo yakaratidza kuti shanduko yakawedzerwa muna 2019 kugadzirisa kwenguva pfupi kutyora kwepop-up userspace kuenderana, zvinoenderana nemusimboti unochinja kune kernel haifanire kutyora kuenderana nemaapplication.

Matambudziko akamuka pakuedza kushandisa michina yekushandura atomu yevhidhiyo modhi muDDX mutyairi xf86-vhidhiyo-modesetting yakashandiswa muX.Org server, izvo zvakakonzerwa nekusungirirwa kumaitiro anotanga nehunhu "X" (zvaifungidzirwa. kuti workaround yakashandiswa pakuita "Xorg"). Pakarepo dambudziko muX.Org rakagadziriswa (kushandiswa kweatomic API kwakavharwa nekusingaperi), asi vakakanganwa kubvisa gadziriso yenguva pfupi kubva kukernel uye kuedza kutumira ioctl kuti ishandure maitiro ezvese maitiro kutanga. hunhu "X" huchiri kuenderera mberi nekuunza kukanganisa. kana (ikozvino-> comm[0] == 'X' && req-> kukosha == 1) {pr_info("yakaputsika atomic modeset userspace yaonekwa, ichivharira atomiki\n"); kudzokera -EOPNOTSUPP; }

Source: opennet.ru

Voeg