Kusagadzikana muvhost-net inobvumira kuparadzaniswa nekupfuura mumasystem akavakirwa paQEMU-KVM

Zvakazarurwa ruzivo nezve vulnerabilities (CVE-2019-14835), iyo inokutendera kuti uende kupfuura iyo yevaenzi sisitimu muKVM (qemu-kvm) uye mhanyisa kodhi yako padivi penzvimbo yevaenzi mumamiriro ezvinhu eLinux kernel. Kusagadzikana kwacho kwakanzi V-gHost. Dambudziko rinobvumira iyo yevaenzi sisitimu kuti igadzire mamiriro eiyo buffer kufashukira mu vhost-net kernel module (network backend ye virtio), inouraiwa padivi penzvimbo inotambira. Kurwiswa kwacho kunogona kuitwa neanorwisa ane rombo rekuwana kune yevaenzi sisitimu panguva yekuona muchina wekufambisa.

Kugadzirisa Dambudziko zvinosanganisira inosanganisirwa muLinux 5.3 kernel. Semagadzirirwo ekuvharisa kusagadzikana, unogona kudzima kutama kwevaenzi kana kudzima vhost-net module (wedzera "blacklist vhost-net" ku /etc/modprobe.d/blacklist.conf). Dambudziko rinoratidzika kutanga kubva kuLinux kernel 2.6.34. Kusagadzikana kwakagadziriswa mukati Ubuntu ΠΈ Fedora, asi zvakadaro inoramba isina kururamiswa mukati Debian, Arch Linux, suse ΠΈ RHEL.

Source: opennet.ru

Voeg