ื ื™ื• ื•ื•ืขืจืกื™ืข ืคื•ืŸ โ€‹โ€‹nginx 1.27.0 ืžื™ื˜ ื“ื™ ื™ืœื™ืžืึทื ื™ื™ืฉืึทืŸ ืคื•ืŸ 4 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ื™ ื”ื˜ื˜ืคึผ / 3 ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ

ื“ืขืจ ืขืจืฉื˜ืขืจ ืžืขืœื“ื•ื ื’ ืคื•ืŸ ื“ื™ ื ื™ื™ึทืข ื”ื•ื™ืคึผื˜ ืฆื•ื•ื™ื™ึทื’ ืคื•ืŸ nginx 1.27.0 ืื™ื– ื“ืขืจืœืื ื’ื˜, ืื™ืŸ ื•ื•ืึธืก ื“ื™ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ืคื•ืŸ ื ื™ื™ึทืข ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ื•ื•ืขื˜ ืคืึธืจื–ืขืฆืŸ. ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜, nginx 1.26.1 ืื™ื– ื‘ืืคืจื™ื™ื˜, ื•ื•ืึธืก ื’ืขื”ืขืจื˜ ืฆื• ื“ื™ ืคึผืึทืจืึทืœืขืœ ื’ืขืฉื˜ื™ืฆื˜ ืกื˜ืึทื‘ื™ืœ ืฆื•ื•ื™ื™ึทื’, ื•ื•ืึธืก ื‘ืœื•ื™ื– ื™ื ืงืœื•ื“ื– ืขื ื“ืขืจื•ื ื’ืขืŸ ืฉื™ื™ึทื›ื•ืช ืฆื• ื“ื™ ื™ืœื™ืžืึทื ื™ื™ืฉืึทืŸ ืคื•ืŸ ืขืจื ืกื˜ ืขืจืจืึธืจืก ืื•ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–. ื•ื•ื™ื™ึทื˜ืขืจ ื™ืึธืจ, ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ ื”ื•ื™ืคึผื˜ ืฆื•ื•ื™ื™ึทื’ 1.27.ืงืก, ืึท ืกื˜ืึทื‘ื™ืœ ืฆื•ื•ื™ื™ึทื’ 1.28 ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขืฉืืคืŸ. ื“ื™ ืคึผืจื•ื™ืขืงื˜ ืงืึธื“ ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ C ืื•ืŸ ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืื•ื ื˜ืขืจ ื“ื™ BSD ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ.

ื“ื™ ื ื™ื™ึทืข ืจื™ืœื™ืกื™ื– ืคืึทืจืจื™ื›ื˜ืŸ 4 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื•ื•ืึธืก ื•ื•ื™ืจืงืŸ ื“ื™ ื™ืงืกืคึผืขืจืžืขื ืึทืœ ngx_http_v3 ืžืึธื“ื•ืœืข (ืคืึทืจืงืจื™ืคึผืœื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜), ื•ื•ืึธืก ื’ื™ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื“ื™ ื”ื˜ื˜ืคึผ / 3 ืคึผืจืึธื˜ืึธืงืึธืœ ื ื™ืฆืŸ ื“ื™ QUIC ืคึผืจืึธื˜ืึธืงืึธืœ ื•ื•ื™ ืึท ืึทืจื™ื‘ืขืจืคื™ืจืŸ ืคึฟืึทืจ ื”ื˜ื˜ืคึผ / 2. ืคึผืจืึธื‘ืœืขืžืก ื“ืขืจืฉื™ื™ึทื ืขืŸ ื‘ืœื•ื™ื– ื•ื•ืขืŸ ื“ื™ ngx_http_v3_module ืžืึธื“ื•ืœืข ืื™ื– ืึทืงื˜ื™ื•ื•ื™ื™ื˜ื™ื“ ืื•ืŸ ื“ื™ "ืฉื ืขืœ" ืึธืคึผืฆื™ืข ืื™ื– ื‘ืึทืฉื˜ื™ืžื˜ ืื™ืŸ ื“ื™ "ื”ืขืจืŸ" ื“ื™ืจืขืงื˜ื™ื•ื•. ืขืก ืื™ื– ื ืึธืš ืงื™ื™ืŸ ื•ื•ืึธืจื˜ ื•ื•ืขื’ืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืคื•ืŸ ื“ื™ Angie ืื•ืŸ FreeNginx ืคืึธืจืงืก.

ื“ื™ CVE-2024-34161 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ื– ื“ื™ ืึทืจื‘ืขื˜ืขืจ ืคึผืจืึธืฆืขืก ื–ื›ึผืจื•ืŸ ืฆื• ืจื™ื ืขืŸ ืื•ื™ืฃ ืกื™ืกื˜ืขืžืขืŸ ืžื™ื˜ ืึท MTU ื•ื•ืขืจื˜ ื’ืจืขืกืขืจ ื•ื•ื™ 4096 ื‘ื™ื˜ืขืก. ื ื–ื›ึผืจื•ืŸ ืจื™ื ืขืŸ ืึทืงืขืจื– ื•ื•ืขืŸ CRYPTO ืจืึธืžืขืŸ ื’ืขื ื™ืฆื˜ ืื™ืŸ ืงืฉืจ ืคืึทืจื”ืึทื ื“ืœื•ื ื’ ื–ืขื ืขืŸ ื’ืขืฉื™ืงื˜ ื ืึธืš ื“ืขืจ ืงืœื™ืขื ื˜ ืกืขื ื“ื– ื“ื™ ืคื™ื ืึทืœื™ื–ืึทื˜ื™ืึธืŸ ืึธื ื–ืึธื’.

ื“ื™ CVE-2024-31079, CVE-2024-32760 ืื•ืŸ CVE-2024-35200 ื–ื™ืงืึธืจืŸ ืงืึธืจื•ืคึผืฆื™ืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืœืึธื–ืŸ ืึท ื•ื•ื™ื™ึทื˜ ืึทื˜ืึทืงืขืจ ืฆื• ืงืจืึทืš ืึท nginx ืึทืจื‘ืขื˜ ืคึผืจืึธืฆืขืก ื“ื•ืจืš ื’ืจื™ื ื“ืŸ ืึท ืกืคึผืขืฉืœื™ ืงืจืึทืคื˜ืขื“ ืกืขืกื™ืข ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ QUIC ืคึผืจืึธื˜ืึธืงืึธืœ. ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜, ืคึฟืึทืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– CVE-2024-31079 ืื•ืŸ CVE-2024-32760, ืื ื“ืขืจืข ืงืึทื ืกืึทืงื•ื•ืขื ืกืึทื– ืคื•ืŸ ื“ื™ ื‘ืึทืคืึทืœืŸ ืงืขื ืขืŸ ื ื™ื˜ ื–ื™ื™ืŸ ื™ืงืกืงืœื•ื“ื™ื“ (ื“ื™ ืคึผืึธื˜ืขื ืฆื™ืขืœ ืžืขื’ืœืขื›ืงื™ื™ื˜ ืคื•ืŸ ืขืงืกืึทืงื™ื•ื˜ื™ื ื’ ื“ื™ ืึทื˜ืึทืงืขืจ ืก ืงืึธื“?). ื“ืขื˜ืึทื™ืœืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ื’ืขื’ืขื‘ืŸ, ืึธื‘ืขืจ ืื•ื™ื‘ ืžืฉืคื˜ืŸ ืœื•ื™ื˜ ื“ื™ ืงืขืจืขืงืฉืึทื ื– ืื™ืŸ ื“ื™ ืงืึธื“, ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืึทืงืกืขืก ืฉื•ื™ืŸ ื‘ืืคืจื™ื™ื˜ ื–ื›ึผืจื•ืŸ (ื ื•ืฆืŸ-ื ืึธืš-ืคึฟืจื™ื™ึท), ืคืึทืœืฉ ื–ื™ืงืึธืจืŸ ืึทืœืึทืงื™ื™ืฉืึทืŸ ืคึฟืึทืจ ืึท ืžืขื ื’ืข, ื ืึทืœ ื˜ื™ื™ึทื˜ืœ ื“ืขืจืคืขืจืึทื ืก ืื•ืŸ ืคืขืœืŸ ืคื•ืŸ ื’ืขื”ืขืจื™ืง ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ืคื•ืŸ ื“ื™ ื’ืจื™ื™ืก ืคื•ืŸ ื“ืึทื˜ืŸ ื’ืขืฉื˜ืขืœื˜ ืื™ืŸ ื“ื™ ื‘ืึทืคืขืจ.

ืฆื•ื•ื™ืฉืŸ ื“ื™ ืขื ื“ืขืจื•ื ื’ืขืŸ ื•ื•ืึธืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ืฉื™ื™ืš ืฆื• ื“ื™ ื™ืœื™ืžืึทื ื™ื™ืฉืึทืŸ ืคื•ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ nginx 1.27.0:

  • ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื•ื•ืขืจื™ืึทื‘ืึทืœื– ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ื“ื™ ื“ื™ื™ืจืขืงื˜ื™ื•ื•ื– "proxy_limit_rate", "fastcgi_limit_rate", "scgi_limit_rate" ืื•ืŸ "uwsgi_limit_rate".
  • ืจื™ื“ื•ืกื˜ ื–ื™ืงืึธืจืŸ ืงืึทื ืกืึทืžืฉืึทืŸ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืœืึทื ื’-ื’ืขืœืขื‘ื˜ ืจื™ืงื•ื•ืขืก ืื™ืŸ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทื ื– ื•ื•ืึธืก ื ื•ืฆืŸ ื“ื™ "gzip", "gunzip", "ssi", "sub_filter" ืึธื“ืขืจ "grpc_pass" ื“ื™ื™ืจืขืงื˜ื™ื•ื•ื–.
  • ืกืึทืœื•ื•ื“ ืคึผืจืึธื‘ืœืขืžืก ืžื™ื˜ ื‘ืึทืฉื˜ืขื˜ื™ืง ืื™ืŸ GCC 14 ื•ื•ืขืŸ ื ื™ืฆืŸ ื“ื™ "--ืžื™ื˜-ืึทื˜ืึธืžื™ืฉืข" ืึธืคึผืฆื™ืข.
  • ืขืจืจืึธืจืก ืื™ืŸ ื”ื˜ื˜ืคึผ / 3 ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ื–ืขื ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜.

ืื™ืŸ ื“ืขืจืฆื•, ืžื™ืจ ืงืขื ืขืŸ ื˜ืึธืŸ ื“ื™ ื•ื™ืกื’ืึทื‘ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ื ื™ื™ึทืข ื”ื•ื™ืคึผื˜ ืฆื•ื•ื™ื™ึทื’ ืคื•ืŸ FreeNginx 1.27.0, ืึท ื’ืึธืคึผืœ ืคื•ืŸ Nginx ื“ืขื•ื•ืขืœืึธืคึผืขื“ ื“ื•ืจืš ืžืึทืงืกื™ื ื“ื•ื ื™ืŸ, ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืฉืœื™ืกืœ ื“ืขื•ื•ืขืœืึธืคึผืขืจืก ืคื•ืŸ Nginx. FreeNginx ืื™ื– ืคึผืึทื–ื™ืฉืึทื ื“ ื•ื•ื™ ืึท ื ืึทืŸ-ื ื•ืฅ ืคึผืจื•ื™ืขืงื˜ ื•ื•ืึธืก ื’ื™ื˜ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ืคื•ืŸ ื“ื™ Nginx ืงืึธื“ ื‘ืึทื–ืข ืึธืŸ ืคึฟื™ืจืžืข ืืจื™ื™ื ืžื™ืฉื•ื ื’. ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืข ื”ืื˜ ื™ืžืคึผืจื•ื•ื•ื“ ื˜ืขื•ืช ื”ืึทื ื“ืœื™ื ื’ ื•ื•ืขืŸ ืœื™ื™ืขื ืขืŸ ื“ื™ ื‘ืขื˜ืŸ ื’ื•ืฃ, ื™ืžืคึผืจื•ื•ื•ื“ ืคึฟืึทืจื–ืึทืžืœื•ื ื’ ืื™ืŸ NetBSD 10.0 ืื•ืŸ ื™ืžืคึผืจื•ื•ื•ื“ ืฉืจื™ื™ื‘ืŸ ืคื•ืŸ PID ื˜ืขืงืขืก (ื“ื™ "ืึทื•ื•ืขืง" ืคึผืึทืจืึทืžืขื˜ืขืจ ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ื“ื™ "ืคึผื™ื“" ื“ื™ืจืขืงื˜ื™ื•ื•).

ืžืงื•ืจ: opennet.ru

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster