10 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ื™ Xen ื›ื™ื™ืคึผืขืจื•ื•ื™ื™ื–ืขืจ

ืคึฟืึทืจืขืคึฟื ื˜ืœืขื›ื˜ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ 10 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ื™ Xen ื›ื™ื™ืคึผืขืจื•ื•ื™ื™ื–ืขืจ, ืคื•ืŸ ื•ื•ืึธืก ืคื™ื ืฃ (CVE-2019-17341, CVE-2019-17342, CVE-2019-17340, CVE-2019-17346, CVE-2019-17343) ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืœืึธื–ืŸ ืื™ืจ ื’ื™ื™ืŸ ื•ื•ื™ื™ึทื˜ืขืจ ืคื•ืŸ ื“ื™ ืงืจืึทื ื˜ ื’ืึทืกื˜ ืกื•ื•ื™ื•ื•ืข ืื•ืŸ ืคืึทืจื’ืจืขืกืขืจืŸ ื“ื™ื™ืŸ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื–, ืื™ื™ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2019-17347) ืึทืœืึทื•ื– ืึทืŸ ืึทื ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉื“ ืคึผืจืึธืฆืขืก ืฆื• ื‘ืึทืงื•ืžืขืŸ ืงืึธื ื˜ืจืึธืœ ืื™ื‘ืขืจ ื“ื™ ืคึผืจืึทืกืขืกืึทื– ืคื•ืŸ ืื ื“ืขืจืข ื™ื•ื–ืขืจื– ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ื’ืึทืกื˜ ืกื™ืกื˜ืขื, ื“ื™ ืจื•ืขืŸ ืคื™ืจ (CVE- 2019-17344, CVE- 2019-17345, CVE-2019-17348, CVE-2019-17351) ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืงืขื ืขืŸ ืึธื ืžืึทื›ืŸ ืึท ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ (ื™ื™ึทื ื‘ืจืึธืš ืคื•ืŸ ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืกื•ื•ื™ื•ื•ืข). ื™ืฉื•ื– ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ืจื™ืœื™ืกื™ื– Xen 4.12.1, 4.11.2 ืื•ืŸ 4.10.4.

  • CVE-2019-17341 - ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื‘ืึทืงื•ืžืขืŸ ืึทืงืกืขืก ืื•ื™ืฃ ื“ื™ ื›ื™ื™ืคึผืขืจื•ื•ื™ื™ื–ืขืจ ืžื“ืจื’ื” ืคึฟื•ืŸ ืึท ื’ืึทืกื˜ ืกื™ืกื˜ืขื ืงืึทื ื˜ืจืึธื•ืœื“ ื“ื•ืจืš ื“ื™ ืึทื˜ืึทืงืขืจ. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื‘ืœื•ื™ื– ืื•ื™ืฃ X86 ืกื™ืกื˜ืขืžืขืŸ ืื•ืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ื’ืขืกื˜ ื•ื•ืึธืก ืœื•ื™ืคืŸ ืื™ืŸ ืคึผืึทืจืึทื•ื•ื™ืจืึธื˜ื•ืึทืœื™ื–ืึทื˜ื™ืึธืŸ (ืคึผื•ื•) ืžืึธื“ืข ื•ื•ืขืŸ ืึท ื ื™ื™ึทืข PCI ืžื™ื˜ืœ ืื™ื– ื™ื ืกืขืจื˜ืึทื“ ืื™ืŸ ื“ื™ ืคืœื™ืกื ื“ื™ืง ื’ืึทืกื˜ ืกื™ืกื˜ืขื. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขืŸ ื ื™ืฉื˜ ื“ืขืจืฉื™ื™ึทื ืขืŸ ืื™ืŸ ื’ืึทืกื˜ ืกื™ืกื˜ืขืžืขืŸ ื•ื•ืึธืก ืœื•ื™ืคืŸ ืื™ืŸ HVM ืื•ืŸ PVH ืžืึธื“ืขืก;
  • CVE-2019-17340 - ืึท ื–ื™ืงืึธืจืŸ ืจื™ื ืขืŸ, ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืึทืœืึทื•ื™ื ื’ ืื™ืจ ืฆื• ืขืกืงืึทืœื™ื™ื˜ ื“ื™ื™ืŸ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืึธื“ืขืจ ื‘ืึทืงื•ืžืขืŸ ืึทืงืกืขืก ืฆื• ื“ืึทื˜ืŸ ืคึฟื•ืŸ ืื ื“ืขืจืข ื’ืึทืกื˜ ืกื™ืกื˜ืขืžืขืŸ.
    ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื‘ืœื•ื™ื– ืื•ื™ืฃ ืžื—ื ื•ืช ืžื™ื˜ ืžืขืจ ื•ื•ื™ 16 ื˜ื‘ ื‘ืึทืจืึทืŸ ืื•ื™ืฃ 64-ื‘ื™ืกืœ ืกื™ืกื˜ืขืžืขืŸ ืื•ืŸ 168 ื’ื™ื’ืื‘ื™ื™ื˜ ืื•ื™ืฃ 32-ื‘ื™ืกืœ ืกื™ืกื˜ืขืžืขืŸ.
    ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขื ืขืŸ ื‘ืœื•ื™ื– ื–ื™ื™ืŸ ืขืงืกืคึผืœื•ื™ื˜ืึทื“ ืคึฟื•ืŸ ื’ืึทืกื˜ ืกื™ืกื˜ืขืžืขืŸ ืื™ืŸ ืคึผื•ื• ืžืึธื“ืข (ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขืŸ ื ื™ืฉื˜ ื“ืขืจืฉื™ื™ึทื ืขืŸ ืื™ืŸ HVM ืื•ืŸ PVH ืžืึธื“ืขืก ื•ื•ืขืŸ ืื™ืจ ืึทืจื‘ืขื˜ ื“ื•ืจืš ืœื™ื‘ืงืกืœ);

  • CVE-2019-17346 - ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ื•ื•ืขืŸ ื ื™ืฆืŸ PCID (ืคึผืจืึธืกืขืก ืงืึธื ื˜ืขืงืกื˜ ื™ื“ืขื ื˜ื™ืคื™ืขืจืก) ืฆื• ืคึฟืึทืจื‘ืขืกืขืจืŸ ื“ื™ ืคืึธืจืฉื˜ืขืœื•ื ื’ ืคื•ืŸ ืฉื•ืฅ ืงืขื’ืŸ ืื ืคืืœืŸ
    Meltdown ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืึทืงืกืขืก ื“ืึทื˜ืŸ ืคื•ืŸ ืื ื“ืขืจืข ื’ืขืกื˜ ืื•ืŸ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืขืกืงืึทืœื™ื™ื˜ ื“ื™ื™ืŸ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื–. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืขืงืกืคึผืœื•ื™ื˜ืึทื“ ื‘ืœื•ื™ื– ืคึฟื•ืŸ ื’ืขืกื˜ ืื™ืŸ ืคึผื•ื• ืžืึธื“ืข ืื•ื™ืฃ ืงืก86 ืกื™ืกื˜ืขืžืขืŸ (ื“ื™ ืคึผืจืึธื‘ืœืขื ืงืขืŸ ื ื™ืฉื˜ ืคึผืึทืกื™ืจืŸ ืื™ืŸ HVM ืื•ืŸ PVH ืžืึธื“ืขืก, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ืื™ืŸ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทื ื– ื•ื•ืึธืก ื˜ืึธืŸ ื ื™ื˜ ื”ืึธื‘ืŸ ื’ืขืกื˜ ืžื™ื˜ PCID ืขื ื™ื™ื‘ืึทืœื“ (PCID ืื™ื– ืขื ื™ื™ื‘ืึทืœื“ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜));

  • CVE-2019-17342 - ืึท ืคึผืจืึธื‘ืœืขื ืื™ืŸ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ XENMEM_exchange ื›ื™ื™ืคึผืขืจืงืึทืœืœ ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืคืึทืจื’ืจืขืกืขืจืŸ ื“ื™ื™ืŸ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืื™ืŸ ื™ื ื•ื•ื™ื™ืจืึทื ืžืึทื ืฅ ืžื™ื˜ ื‘ืœื•ื™ื– ืื™ื™ืŸ ื’ืึทืกื˜ ืกื™ืกื˜ืขื. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขื ืขืŸ ื‘ืœื•ื™ื– ื–ื™ื™ืŸ ืขืงืกืคึผืœื•ื™ื˜ืึทื“ ืคึฟื•ืŸ ื’ืึทืกื˜ ืกื™ืกื˜ืขืžืขืŸ ืื™ืŸ ืคึผื•ื• ืžืึธื“ืข (ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขืŸ ื ื™ืฉื˜ ื“ืขืจืฉื™ื™ึทื ืขืŸ ืื™ืŸ HVM ืื•ืŸ PVH ืžืึธื“ืขืก);
  • CVE-2019-17343 - ืคืึทืœืฉ ืžืึทืคึผื™ื ื’ ืื™ืŸ IOMMU ืžืื›ื˜ ืขืก ืžืขื’ืœืขืš, ืื•ื™ื‘ ืขืก ืื™ื– ืึทืงืกืขืก ืคึฟื•ืŸ ื“ื™ ื’ืึทืกื˜ ืกื™ืกื˜ืขื ืฆื• ืึท ื’ืฉืžื™ื•ืช ืžื™ื˜ืœ, ืฆื• ื ื•ืฆืŸ DMA ืฆื• ื˜ื•ื™ืฉืŸ ื–ื™ื™ืŸ ืื™ื™ื’ืขื ืข ื–ื™ืงืึธืจืŸ ื‘ืœืึทื˜ ื˜ื™ืฉ ืื•ืŸ ื‘ืึทืงื•ืžืขืŸ ืึทืงืกืขืก ืื•ื™ืฃ ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืžื“ืจื’ื”. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื‘ืœื•ื™ื– ืื™ืŸ ื’ืึทืกื˜ ืกื™ืกื˜ืขืžืขืŸ ืื™ืŸ ืคึผื•ื• ืžืึธื“ืข ืื•ื™ื‘ ื–ื™ื™ ื”ืึธื‘ืŸ ืจืขื›ื˜ ืฆื• ืคืึธืจื•ื™ืก PCI ื“ืขื•ื•ื™ืกืขืก.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’