Nuglaanta gudaha vhost-net taas oo u oggolaanaysa go'doominta nidaamyada ku salaysan QEMU-KVM

kashifay macluumaadka ku saabsan baylahda (CVE-2019-14835), kaas oo kuu ogolaanaya inaad ka gudubto nidaamka martida ee KVM (qemu-kvm) oo aad ku socodsiiso koodhkaaga dhinaca deegaanka martida loo yahay ee macnaha Linux kernel. Nuglaanta waxaa loo magacaabay V-gHost. Dhibaatadu waxay u oggolaanaysaa nidaamka martida inuu abuuro shuruudo loogu talagalay qulqulka qulqulka ee moduleka vhost-net kernel (backend network for virtio), oo lagu fuliyay dhinaca deegaanka martida loo yahay. Weerarka waxaa fulin kara weeraryahan si gaar ah u leh marin u helka nidaamka martida inta lagu jiro hawlgalka socdaalka mashiinka farsamada.

Hagaajinta Dhibaatada waxaa ka mid ahaa oo lagu daray Linux 5.3 kernel. Sida xalalka looga hortagayo nuglaanta, waxaad joojin kartaa guuritaanka tooska ah ee nidaamyada martida ama waxaad dami kartaa moduleka vhost-net (ku dar "list-black vhost-net" /etc/modprobe.d/blacklist.conf). Dhibaatadu waxay u muuqataa in laga bilaabo Linux kernel 2.6.34. Nuglaanta ayaa lagu hagaajiyay gudaha Ubuntu ΠΈ Fedora, laakiin wali lama sixin gudaha Debian, Arch Linux, SUSE ΠΈ RHEL.

Source: opennet.ru

Add a comment