Kusagadzikana muLinux Netfilter kernel subsystem

Kusagadzikana kwaonekwa muLinux kernel (CVE isina kupihwa) iyo inobvumira mushandisi wenzvimbo kuwana kodzero dzemidzi muhurongwa. Zvinoziviswa kuti kushandiswa kwakagadzirirwa kunoratidza kuwana midzi ropafadzo muUbuntu 22.04. Chigamba chinogadzirisa dambudziko chakakurudzirwa kuti chibatanidzwe mukernel.

Kusagadzikana uku kunokonzerwa nekuwana yatosunungurwa ndangariro nzvimbo (shandisa-mushure-yemahara) paunenge uchinyengedza maseti rondedzero uchishandisa NFT_MSG_NEWSET murairo mune nf_tables module. Kuti uite kurwiswa kwacho, kuwana nftables kunodiwa, iyo inogona kuwanikwa munzvimbo dzakasiyana dzetiweki mazita kana uine CLONE_NEWUSER, CLONE_NEWNS kana CLONE_NEWNET kodzero (semuenzaniso, kana uchikwanisa kumhanyisa mudziyo uri wega).

Source: opennet.ru

Voeg