Kusagadzikana kunobvumira kubuda kubva kune yakasarudzika QEMU nharaunda

Zvakazarurwa ruzivo rwakakosha rwekusagadzikana (CVE-2019-14378) mune yakasarudzika SLIRP mubato unoshandiswa muQEMU kumisikidza nzira yekutaurirana pakati peiyo virtual network adapta muhurongwa hwevaenzi uye network backend padivi reQEMU. Iyo nyaya inobatawo KVM-yakavakirwa virtualization masisitimu (in Usermode) uye Virtualbox, iyo inoshandisa slirp backend kubva kuQEMU, pamwe nemashandisirwo anoshandisa mushandisi-nzvimbo networking stack. libSLIRP (TCP/IP emulator).

Kusagadzikana kunobvumira kodhi kuti iitwe kudivi rehurongwa hwevaenzi nekodzero dzeQEMU mugadziri wekuita kana yakanyatsogadzirirwa yakakura kwazvo network packet inotumirwa kubva kune yevaenzi system, inoda kupatsanurwa. Nekuda kwekukanganisa kuri mu ip_reass () basa, rinodaidzwa kana uchiunganidzazve mapaketi anouya, chidimbu chekutanga chinogona kusakwana mubhafa yakagoverwa uye muswe wayo unozonyorwa kunzvimbo dzekurangarira padyo nebhafa.

Zvekuongororwa kare inowanikwa chimiro chinoshanda chekushandisa, chinopa kunzvenga ASLR uye kuita kodhi nekudzoreredza ndangariro ye main_loop_tlg array, kusanganisira QEMTimerList ine zvibatiso zvinodaidzwa nenguva.
Kusagadzikana kwakatogadziriswa mukati Fedora ΠΈ SUSE/openSUSE, asi inoramba isina kururamiswa mukati Debian, Arch Linux ΠΈ FreeBSD. The Ubuntu ΠΈ RHEL Dambudziko harisi kuoneka nekuda kwekusashandisa slirp. Kusagadzikana kunoramba kusingagadziriswe mukuburitswa kwazvino libslirp 4.0 (iyo gadziriso iripo ikozvino se chigamba).

Source: opennet.ru

Voeg