Nuglaanta nidaamka-hoosaadka kernel-ka Linux Netfilter

Nuglaanta ayaa lagu aqoonsaday kernel Linux (CVE aan la meelayn) taas oo u oggolaanaysa isticmaale maxalli ah inuu helo xuquuqaha xididka nidaamka. Waxaa lagu dhawaaqay in ka faa'iidaysi la diyaariyay taas oo muujinaysa helitaanka mudnaanta asaasiga ah ee Ubuntu 22.04. Qalab hagaajinaya dhibaatada ayaa loo soo jeediyay in lagu daro kernel-ka.

Nuglaanta waxaa sababa gelitaanka aagga xusuusta ee hore loo xoreeyay (isticmaalka-ka-dib-free) marka la maamulayo liisaska la dejiyay iyadoo la adeegsanayo amarka NFT_MSG_NEWSET ee moduleka nf_tables. Si loo fuliyo weerarka, gelitaanka nftables ayaa loo baahan yahay, kaas oo laga heli karo meelo magacyo shabakad gaar ah haddii aad leedahay xuquuqaha CLONE_NEWUSER, CLONE_NEWNS ama CLONE_NEWNET (tusaale ahaan, haddii aad awooddo weel gooni ah).

Source: opennet.ru

Add a comment