Ukukhutshwa kwemodyuli yokukhusela ubuthathaka be-LKRG 0.9.0 kernel Linux

Iprojekthi ye-Openwall ipapashe ukukhululwa kwemodyuli ye-LKRG 0.9.0 kernel (Linux I-Kernel Runtime Guard, eyenzelwe ukubona nokuthintela ukuhlaselwa kunye nokwaphulwa kobume be-kernel. Umzekelo, imodyuli inokukhusela kutshintsho olungagunyaziswanga kwi-kernel esebenzayo kwaye izame ukutshintsha amalungelo eenkqubo zomsebenzisi (ukufumanisa i-exploits). Imodyuli ifanelekile ukukhusela kwi-exploits ye-kernel vulnerability eyaziwayo. Linux (umzekelo, kwiimeko apho ukuhlaziya i-kernel yenkqubo kuyingxaki) kunye nokulwa nokuxhathisa ubuthathaka obungaziwayo. Ikhowudi yeprojekthi isasazwa phantsi kwelayisenisi ye-GPLv2.

Phakathi kotshintsho kwinguqulelo entsha:

  • Ukuhambelana neekernel kuyaqinisekiswa Linux ukusuka kwi-5.8 ukuya kwi-5.12, kunye nee-kernel ezizinzileyo eziyi-5.4.87 nezamva (eziquka iimpawu ezintsha ezivela kwii-kernel eziyi-5.8 nezamva) kunye nee-kernel ezivela kwiinguqulelo ze-RHEL ukuya kuthi ga kwi-8.4, ngelixa zigcina inkxaso yazo zonke iinguqulelo ze-kernel ezixhaswe ngaphambili, ezifana nee-kernel ezivela kwi-RHEL 7;
  • Kongeze amandla okwakha i-LKRG kungekuphela nje njengemodyuli yangaphandle, kodwa nanjengenxalenye yomthi we-kernel Linux, kuquka ukufakwa kwayo kumfanekiso we-kernel;
  • Inkxaso eyongeziweyo yeekernel ezininzi ezongezelelweyo kunye noqwalaselo lwenkqubo;
  • Ukulungisa iimpazamo ezininzi ezibalulekileyo kunye neentsilelo kwi-LKRG;
  • Ukuphunyezwa kwamanye amacandelo e-LKRG kwenziwe lula kakhulu;
  • Utshintsho lwenziwe lula ngakumbi inkxaso kunye nokulungiswa kwe-LKRG;
  • Ukuvavanya i-LKRG, ukudibanisa kunye ne-out-of-tree kunye ne-mkosi yongezwe;
  • Indawo yokugcina iprojekthi isusiwe kwiBitBucket ukuya kwiGitHub kwaye ukuhlanganiswa okuqhubekayo kongezwe kusetyenziswa iiGitHub Actions kunye ne-mkosi, kubandakanya ukujonga ukwakhiwa kwe-LKRG kunye nokulayisha kwii-kernel ezikhutshiweyo. Ubuntu, kunye nezo zibonelelwe yiprojekthi Ubuntu Ukwakhiwa kwemihla ngemihla kwee-kernel zamva nje eziphambili.

Abaphuhlisi abaninzi ababengazange bathathe inxaxheba kule projekthi ngaphambili banegalelo ngokuthe ngqo kule nguqulelo ye-LKRG (ngezicelo zokutsala kwiGitHub). Ngokukodwa, uBoris Lukashev wongeze amandla okwakha njengenxalenye yomthi we-kernel. Linuxkunye noVitaly Chikunov ovela kwi-ALT Linux — ukuhlanganiswa ne-mkosi kunye ne-GitHub Actions.

Ngokubanzi, nangona ukongezwa okubalulekileyo, inani lemigca ye-LKRG yekhowudi liye lancitshiswa kancinane okwesibini ngokulandelelana (kwaye kwancitshiswa ngaphambili phakathi kweenguqu ze-0.8 kunye ne-0.8.1).

Okwangoku, iphakheji ye-LKRG ikwi-Arch Linux sele ihlaziyiwe ukuya kwinguqulelo 0.9.0, kwaye ezinye iipakeji ezininzi zisebenzisa iinguqulelo zamva nje ze-git ze-LKRG kwaye kusenokwenzeka ukuba ihlaziywe ukuya kwinguqulelo 0.9.0 nangaphezulu kungekudala.

Ukongeza, sinokuphawula upapasho lwakutsha nje oluvela kubaphuhlisi be-Aurora OS (ukuguqulwa kwesiRashiya kweSailfish OS) malunga nokomelezwa okunokwenzeka kweLKRG kusetyenziswa i-ARM TrustZone.

Ngolwazi oluthe kratya malunga ne-LKRG, jonga isibhengezo senguqulo 0.8 kunye nengxoxo eyenzeka ngoko.

umthombo: opennet.ru

Thenga ukusingathwa okuthembekileyo kwiindawo ezinokhuseleko lweDDoS, iiseva zeVPS VDS 🔥 Thenga ukusingathwa kwewebhusayithi okuthembekileyo ngokhuseleko lwe-DDoS, iiseva zeVPS VDS | ProHoster