Kusagadzikana muLinux kernel inobvumira kushandura zvirimo zvetmpfs uye yakagovaniswa ndangariro

Kusagadzikana (CVE-2022-2590) kwakaonekwa muLinux kernel, iyo inobvumira mushandisi asina rusaruro kuti achinje ndangariro-mamepu mafaera (mmap) uye mafaera mutmpfs asina kodzero yekunyora kwavari, uye kukwidziridza maropafadzo avo muhurongwa. . Dambudziko rakaonekwa rakafanana mumhando kune Yakasviba COW kusagadzikana, asi inosiyana pakuti inongogumira kune iyo data mune yakagovaniswa ndangariro (shmem / tmpfs). Dambudziko rinogonawo kushandiswa kugadzirisa mafaera anogoneka anoshandisa ndangariro dzakagovaniswa.

Dambudziko rinokonzerwa nechimiro chenhangemutange mune yekurangarira manejimendi subsystem inoitika kana uchibata kusarudzika (kukanganisa) kwakakandwa paunenge uchiedza kunyora mukana wekuverenga-chete nzvimbo mune yakagovaniswa ndangariro inoratidzwa muCOW (copy-on-write mepu) modhi. Dambudziko rinoratidzika kutanga kubva ku kernel 5.16 pane masisitimu ane x86-64 uye aarch64 architecture paunenge uchivaka kernel neCONFIG_USERFAULTFD=y sarudzo. Kusagadzikana kwakagadziriswa mukuburitswa 5.19. Muenzaniso wekushandiswa kwakarongwa kuburitswa muna Nyamavhuvhu 15.

Source: opennet.ru

Voeg