Kusagadzikana muvhost-net mutyairi kubva kuLinux kernel

Mune vhost-net mutyairi, iyo inovimbisa kushanda kwevirtio net padivi penzvimbo yevaenzi, kuzivikanwa kusagadzikana (CVE-2020-10942), zvichibvumira mushandisi wepanzvimbo kuti atange kernel stack kufashukira nekutumira yakanyatso kurongeka ioctl(VHOST_NET_SET_BACKEND) kune /dev/vhost-net mudziyo. Dambudziko rinokonzerwa nekushaikwa kwechokwadi chekusimbisa zviri mukati me sk_family field mu get_raw_socket() function code.

Zvinoenderana nedata rekutanga, kusazvibata kunogona kushandiswa kuita kurwisa kweDoS yemuno nekukonzeresa kuparara kwekernel (hapana ruzivo nezve mashandisirwo ekufashukira kwakakonzerwa nekusagadzikana kwekuronga kodhi kuuraya).
Kunetseka kubviswa muLinux kernel 5.5.8 update. Nekugovera, unogona kuteedzera kuburitswa kwepakeji zvigadziriso pamapeji Debian, Ubuntu, RHEL, SUSE/openSUSE, Fedora, Arch.

Source: opennet.ru

Voeg