Ropafadzo yekuwedzera kusazvibata muio_uring subsystem

Kusagadzikana (CVE-5.1-2022) kwakaonekwa mukuitwa kweiyo io_uring asynchronous yekupinda / kubuda interface, inosanganisirwa muLinux kernel kubva pakaburitswa 3910, iyo inobvumira mushandisi asina rombo rakanaka kuti aite kodhi ine kernel ropafadzo. Dambudziko rakaonekwa mukuburitswa 5.18 uye 5.19, uye rakagadziriswa mubazi re6.0. Debian, RHEL uye SUSE vanoshandisa kernel kuburitsa kusvika 5.18, Fedora, Gentoo uye Arch yatopa kernel 6.0. Ubuntu 22.10 inoshandisa iri panjodzi 5.19 kernel.

Kusagadzikana kunokonzerwa nekuwana yakatosunungurwa memory block (shandisa-mushure-yemahara) mune io_uring subsystem, inosanganiswa neiyo isiriyo kuvandudzwa kwereferensi counter - pakufona io_msg_ring() nefaira rakagadziriswa (rinowanikwa zvachose murin'i buffer), iyo io_fput_file() basa rinodaidzwa nekukanganisa kudzikisa referensi kuverenga.

Source: opennet.ru

Voeg