Kotsi ho Linux kernel network stack

Ho na le bofokoli bo fumanoe ka har'a khoutu ea TCP-based RDS protocol handler (Reliable Datagram Socket, net/rds/tcp.c) (CVE-2019-11815), e leng se ka lebisang ho fihlella sebakeng sa mohopolo se seng se lokolotsoe le ho hana tšebeletso (mohlomong, monyetla oa ho sebelisa bothata ho hlophisa ts'ebetso ea khoutu ha o qheleloe ka thoko). Bothata bo bakoa ke boemo ba morabe bo ka hlahang ha ho etsoa mosebetsi oa rds_tcp_kill_sock ha u ntse u hlakola li-sockets bakeng sa sebaka sa mabitso sa marang-rang.

Tlhaloso NVD bothata bo tšoailoe e le ntho e ka sebelisoang hole le marang-rang, empa ho latela tlhaloso e lokisa, ntle le boteng ba sebaka sa tsamaiso le ho qhekella ha libaka tsa mabitso, ho ke ke ha khoneha ho hlophisa tlhaselo ka thōko. Ka ho khetheha, ho ea ka maikutlo Bahlahisi ba SUSE, ho ba kotsing ho sebelisoa sebakeng sa heno feela; ho hlophisa tlhaselo ho rarahane haholo mme ho hloka litokelo tse eketsehileng tsamaisong. Haeba ho NVD boemo ba kotsi bo lekoa ho lintlha tsa 9.3 (CVSS v2) le 8.1 (CVSS v2), joale ho latela tekanyo ea SUSE kotsi e hlahlojoa ho lintlha tse 6.4 ho tse 10.

Baemeli ba Ubuntu le bona ananeloa kotsi ea bothata e nkoa e le e itekanetseng. Ka nako e ts'oanang, ho ea ka tlhaloso ea CVSS v3.0, bothata bo abeloa boemo bo phahameng ba tlhaselo e rarahaneng 'me ts'ebeliso e abeloa feela lintlha tse 2.2 ho tse 10.

Ho ahlola ka tlaleha ho tloha Cisco, ts'oaetso e sebelisoa ka thōko ka ho romela lipakete tsa TCP ho litšebeletso tsa marang-rang tse sebetsang. RDS 'me ho se ho ntse ho e-na le mohlala oa ts'ebetso. Tekanyo eo tlhahisoleseling ena e tsamaellanang le 'nete ka eona ha e e-so hlake; mohlomong tlaleho e etsa feela menahano ea NVD ka botaki. Ka tlhahisoleseding Ts'ebeliso ea VulDB ha e so thehoe mme bothata bo sebelisoa sebakeng sa heno feela.

Bothata bo hlaha ka har'a lithollo pele ho 5.0.8 'me bo thibetsoe ke March tokiso, e kenyelelitsoe ho kernel 5.0.8. Liphatlalatsong tse ngata bothata ha bo rarolloe (Debian, RHEL, Botho, sebelisa). Tokiso e lokollotsoe bakeng sa SLE12 SP3, openSUSE 42.3 le Fedora.

Source: opennet.ru

Eketsa ka tlhaloso