Kusagadzikana muLinux kernel network stack

Kusagadzikana kwaonekwa mukodhi yeTCP-based RDS protocol handler (Reliable Datagram Socket, net/rds/tcp.c) (CVE-2019-11815), izvo zvinogona kutungamira kusvika kune yakatosunungurwa ndangariro nzvimbo uye kurambwa kwesevhisi (zvichida, mukana wekushandisa dambudziko kuronga kuurayiwa kwekodhi haina kubviswa). Dambudziko rinokonzerwa nemamiriro emujaho anogona kuitika paunenge uchiita rds_tcp_kill_sock basa uchibvisa zvigadziko zvetiweki namespace.

Mukutaura NDV dambudziko rinoratidzwa serinoshandisika kure netiweki, asi tichitarisa netsanangudzo fixes, pasina huvepo hwemunharaunda muhurongwa uye kushandiswa kwemazita, hazvizoitike kuronga kurwisa kure. Kunyanya, maererano mafungiro Vagadziri veSUSE, kusazvibata kunoshandiswa munharaunda chete; kuronga kurwiswa kwakaoma uye kunoda mamwe maropafadzo muhurongwa. Kana muNVD mwero wengozi uchiongororwa pa9.3 (CVSS v2) uye 8.1 (CVSS v2) mapoinzi, zvino zvichienderana nechiyero cheSUSE njodzi inoongororwa pa6.4 point kubva pagumi.

Ubuntu vamiririri zvakare kuongwa ngozi yedambudziko inonzi ine mwero. Panguva imwecheteyo, maererano neCVSS v3.0 tsanangudzo, dambudziko rinopiwa huwandu hwepamusoro hwekurwiswa uye kushandiswa kunopihwa chete 2.2 points kubva pagumi.

Kutonga na report kubva kuCisco, kusagadzikana kunoshandiswa kure nekutumira TCP mapaketi kunoshanda network masevhisi. RDS uye kwatove neprototype yekushandiswa. Humwe ruzivo urwu hunoenderana neicho chokwadi hahusati hwajeka; pamwe chirevo chinongogadzira fungidziro dzeNVD. By ruzivo Iyo VulDB yekubiridzira haisati yagadzirwa uye dambudziko rinongoshandiswa munharaunda.

Dambudziko rinoonekwa mumakernels pamberi pe5.0.8 uye rakavharwa neMarch kururamisa, inosanganisirwa mu kernel 5.0.8. Mukugovera kwakawanda dambudziko rinoramba risina kugadziriswa (Debian, RHEL, Ubuntu, suse) Iyo gadziriso yakaburitswa SLE12 SP3, openSUSE 42.3 uye Fedora.

Source: opennet.ru

Voeg