Ho ba kotsing ho Linux Netfilter kernel subsystem

Ho na le ts'oaetso ho Linux kernel (CVE ha e fuoe) e lumellang mosebelisi oa lehae ho fumana litokelo tsa metso tsamaisong. Ho phatlalalitsoe hore ho lokiselitsoe ts'ebetso e bonts'ang ho fumana litokelo tsa metso ho Ubuntu 22.04. Ho hlahisitsoe patch e lokisang bothata hore e kenngoe kernel.

Kotsi e bakoa ke ho fihlella sebaka sa memori se seng se lokolotsoe (sebelisa-kamora-mahala) ha o fetola manane a sete o sebelisa taelo ea NFT_MSG_NEWSET mojulung oa nf_tables. Ho etsa tlhaselo, ho hlokahala phihlello ea li-nftables, e ka fumanoang sebakeng se arohaneng sa mabitso sa marang-rang haeba u na le CLONE_NEWUSER, CLONE_NEWNS kapa CLONE_NEWNET litokelo (mohlala, haeba u ka tsamaisa sets'oants'o se ka thoko).

Source: opennet.ru

Eketsa ka tlhaloso