ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ cgroups v1 ื•ื•ืึธืก ืึทืœืึทื•ื– ืึทื ื˜ืœื•ื™ืคืŸ ืคื•ืŸ ืึทืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ ืงืึทื ื˜ื™ื™ื ืขืจ

ืคืจื˜ื™ื ืคื•ืŸ ื ืฉื•ื•ืื›ืงื™ื™ื˜ (CVE-2022-0492) ืื™ืŸ ื“ืขืจ ืื™ืžืคืœืขืžืขื ื˜ืืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ cgroups v1 ืจืขืกื•ืจืก ืœื™ืžื™ื˜ื™ื ื’ ืžืขืงืื ื™ื–ื ืื™ืŸ ื“ื™ ืงืขืจื ืขืœ ื–ืขื ืขืŸ ื’ืขื•ื•ืืจืŸ ืื ื˜ืคืœืขืงื˜. Linux, ื•ื•ืึธืก ืงืขืŸ ื’ืขื ื•ืฆื˜ ื•ื•ืขืจืŸ ืฆื• ืึทื ื˜ืœื•ื™ืคืŸ ืคื•ืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืข ืงืึทื ื˜ื™ื™ื ืขืจืก. ื“ื™ ืคึผืจืึธื‘ืœืขื ืžืึทื ื™ืคืขืกื˜ื™ืจื˜ ื–ื™ืš ืึธื ื”ื™ื™ื‘ื ื“ื™ืง ืžื™ื˜ืŸ ืงืขืจื ืขืœ. Linux 2.6.24 ืื•ืŸ ืคืืจืจืื›ื˜ืŸ ืื™ืŸ ืงืขืจื ืขืœ ืื•ื™ืกื’ืื‘ืขืก 5.16.12, 5.15.26, 5.10.97, 5.4.177, 4.19.229, 4.14.266, ืื•ืŸ 4.9.301. ืื™ืจ ืงืขื ื˜ ื ืื›ืคืืœื’ืŸ ื“ื™ ืื•ื™ืกื’ืื‘ืข ืคื•ืŸ โ€‹โ€‹ืคืขืงืœ ืืคื“ืขื™ื˜ืก ืื™ืŸ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– ืื•ื™ืฃ ื“ื™ ื‘ืœืขื˜ืขืจ: Debian, ืกื•ืกืข, Ubuntu, RHEL, ืคืขื“ืึธืจืึท, ื“ื–ืฉืขื ื˜ื•, ืึทืจื˜ืฉ Linux.

ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืจืขื›ื˜ ืฆื• ืึท ืœืึธื’ื™ืง ื˜ืขื•ืช ืื™ืŸ ื“ื™ release_agent ื˜ืขืงืข ื”ืึทื ื“ืœืขืจ ื•ื•ืึธืก ืคื™ื™ืœื– ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ื’ืขื”ืขืจื™ืง ื˜ืฉืขืงืก ื•ื•ืขืŸ ืคืœื™ืกื ื“ื™ืง ื“ื™ ื”ืึทื ื“ืœืขืจ ืžื™ื˜ ืคื•ืœ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื–. ื“ื™ release_agent ื˜ืขืงืข ืื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ื“ืขืคื™ื ื™ืจืŸ ื“ื™ ืคึผืจืึธื’ืจืึทื ืฆื• ื–ื™ื™ืŸ ืขืงืกืึทืงื™ื•ื˜ืึทื“ ื“ื•ืจืš ื“ื™ ืงืขืจืŸ ื•ื•ืขืŸ ืึท ืคึผืจืึธืฆืขืก ืื™ืŸ ืึท cgroup ืื™ื– ื˜ืขืจืžืึทื ื™ื™ื˜ื™ื“. ื“ืขืจ ืคึผืจืึธื’ืจืึทื ืœื•ื™ืคื˜ ื•ื•ื™ ื•ื•ืึธืจืฆืœ ืื•ืŸ ืžื™ื˜ ืึทืœืข "ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื–" ืื™ืŸ ื“ืขืจ ื•ื•ืึธืจืฆืœ ื ืึทืžืขืกืคึผืึทืกืข. ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ืื ื’ืขื ื•ืžืขืŸ ืึทื– ื‘ืœื•ื™ื– ื“ืขืจ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ื”ืื˜ ืฆื•ื˜ืจื™ื˜ ืฆื• ื“ื™ release_agent ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ, ืึธื‘ืขืจ ืื™ืŸ ืคืึทืงื˜, ื“ื™ ื˜ืฉืขืงืก ื–ืขื ืขืŸ ืœื™ืžื™ื˜ืขื“ ืฆื• ื’ืขื‘ืŸ ืึทืงืกืขืก ืฆื• ื“ืขืจ ื•ื•ืึธืจืฆืœ ื‘ืึทื ื™ืฆืขืจ, ื•ื•ืึธืก ื”ืื˜ ื ื™ืฉื˜ ื•ื™ืกืฉืœื™ืกืŸ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก ืคื•ืŸ ื“ืขื ืงืึทื ื˜ื™ื™ื ืขืจ ืึธื“ืขืจ ื“ื•ืจืš ืึท ื•ื•ืึธืจืฆืœ ื‘ืึทื ื™ืฆืขืจ ืึธืŸ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืจืขื›ื˜ (CAP_SYS_ADMIN) ).

ื‘ื™ื– ืึทื”ืขืจ, ืึทื–ืึท ืึท ืฉื˜ืจื™ืš ื•ื•ืึธืœื˜ ื ื™ืฉื˜ ื–ื™ื™ืŸ ื‘ืืžืขืจืงื˜ ื•ื•ื™ ืึท ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, ืึธื‘ืขืจ ื“ื™ ืกื™ื˜ื•ืึทืฆื™ืข ืื™ื– ืคืืจืขื ื“ืขืจื˜ ืžื™ื˜ ื“ื™ ืึทื“ื•ื•ืขื ื˜ ืคื•ืŸ ื‘ืึทื ื™ืฆืขืจ ื ืึทืžืขืกืคึผืึทืกืขืก (ื‘ืึทื ื™ืฆืขืจ ื ืึทืžืขืกืคึผืึทืกืขืก), ื•ื•ืึธืก ืœืึธื–ืŸ ืื™ืจ ืฆื• ืฉืึทืคึฟืŸ ื‘ืึทื–ื•ื ื“ืขืจ ื•ื•ืึธืจืฆืœ ื™ื•ื–ืขืจื– ืื™ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื– ื•ื•ืึธืก ื˜ืึธืŸ ื ื™ื˜ ืึธื•ื•ื•ืขืจืœืึทืคึผ ืžื™ื˜ ื“ื™ ื•ื•ืึธืจืฆืœ ื‘ืึทื ื™ืฆืขืจ. ื”ื•ื™ืคึผื˜ ืกื•ื•ื™ื•ื•ืข. ืึทืงืงืึธืจื“ื™ื ื’ืœื™, ืคึฟืึทืจ ืึท ื‘ืึทืคืึทืœืŸ, ืขืก ืื™ื– ื’ืขื ื•ื’ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ื“ื™ื™ืŸ release_agent ื”ืึทื ื“ืœืขืจ ืื™ืŸ ืึท ืงืึทื ื˜ื™ื™ื ืขืจ ื•ื•ืึธืก ื”ืื˜ ื–ื™ื™ืŸ ืื™ื™ื’ืขื ืข ื•ื•ืึธืจืฆืœ ื‘ืึทื ื™ืฆืขืจ ืื™ืŸ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืฉื™ื™ึทืŸ ืคึผืœืึทืฅ, ื•ื•ืึธืก, ื ืึธืš ืงืึทืžืคึผืœื™ื˜ื™ื ื’ ื“ืขื ืคึผืจืึธืฆืขืก, ื•ื•ืขื˜ ื–ื™ื™ืŸ ืขืงืกืึทืงื™ื•ื˜ืึทื“ ืžื™ื˜ ืคื•ืœ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืคื•ืŸ ื“ื™ ื”ื•ื™ืคึผื˜ ืกื•ื•ื™ื•ื•ืข.

ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, cgroupfs ืื™ื– ืžืึธื•ื ื˜ืขื“ ืื™ืŸ ืึท ืงืึทื ื˜ื™ื™ื ืขืจ ืื™ืŸ ืœื™ื™ืขื ืขืŸ-ื‘ืœื•ื™ื– ืžืึธื“ืข, ืึธื‘ืขืจ ืขืก ืื™ื– ืงื™ื™ืŸ ืคึผืจืึธื‘ืœืขื ืจื™ืžืึธื•ื ื˜ื™ื ื’ ื“ืขื ืคึผืกืขื•ื“ืึธืคืก ืื™ืŸ ืฉืจื™ื™ึทื‘ืŸ ืžืึธื“ืข ืื•ื™ื‘ ืื™ืจ ื”ืึธื‘ืŸ CAP_SYS_ADMIN ืจืขื›ื˜ ืึธื“ืขืจ ื“ื•ืจืš ืฉืึทืคึฟืŸ ืึท ื ืขืกื˜ืขื“ ืงืึทื ื˜ื™ื™ื ืขืจ ืžื™ื˜ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ื ืึธืžืขืŸ ืžื™ื˜ ื“ื™ ื•ื ืฉืึทืจืข ืกื™ืกื˜ืขื ืจื•ืคืŸ, ืื™ืŸ ื•ื•ืึธืก CAP_SYS_ADMIN ืจืขื›ื˜ ื–ืขื ืขืŸ ื‘ืืจืขื›ื˜ื™ื’ื˜ ืคึฟืึทืจ ื“ื™ ื‘ืืฉืืคืŸ ืงืึทื ื˜ื™ื™ื ืขืจ.

ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ cgroups v1 ื•ื•ืึธืก ืึทืœืึทื•ื– ืึทื ื˜ืœื•ื™ืคืŸ ืคื•ืŸ ืึทืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ ืงืึทื ื˜ื™ื™ื ืขืจ

ื“ื™ ืื˜ืืงืข ืงืขืŸ ื“ื•ืจื›ื’ืขืคื™ืจื˜ ื•ื•ืขืจืŸ ืžื™ื˜ ืจื•ื˜ ืคืจื™ื•ื•ื™ืœืขื’ื™ืขืก ืื™ืŸ ืืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืŸ ืงืื ื˜ืขื™ื ืขืจ ืื“ืขืจ ื•ื•ืขืŸ ืžืขืŸ ืœื•ื™ืคื˜ ื ืงืื ื˜ืขื™ื ืขืจ ืืŸ ื“ืขื no_new_privs ืคืืŸ, ื•ื•ืืก ืคืืจืžื™ื™ื“ื˜ ืฆื•ื’ืขืœื™ื™ื’ื˜ืข ืคืจื™ื•ื•ื™ืœืขื’ื™ืขืก ืคื•ืŸ ื’ืขื’ืขื‘ืŸ ื•ื•ืขืจืŸ. ื‘ืื ื™ืฆืขืจ ื ืขืžืขื ืกืคืขื™ืก ืžื•ื–ืŸ ื–ื™ื™ืŸ ืื™ื™ื ื’ืขืฉื˜ืขืœื˜ ืื•ื™ืคืŸ ืกื™ืกื˜ืขื (ืื™ื™ื ื’ืขืฉื˜ืขืœื˜ ื“ื•ืจืš ื“ื™ืคืืœื˜ ืื™ืŸ Ubuntu ืื•ืŸ ืคืขื“ืึธืจืึท, ืึธื‘ืขืจ ื ื™ืฉื˜ ืึทืงื˜ื™ื•ื•ื™ื–ื™ืจื˜ ืื™ืŸ Debian ืื•ืŸ RHEL) ืื•ืŸ ืฆื•ื˜ืจื™ื˜ ืฆื• ื“ืขืจ ื•ื•ืึธืจืฆืœ cgroup v1 (ืœืžืฉืœ, Docker ืœื•ื™ืคื˜ ืงืึธื ื˜ืขื™ื ืขืจืก ืื™ืŸ ื“ืขืจ ื•ื•ืึธืจืฆืœ RDMA cgroup). ื“ื™ ืึทื˜ืึทืงืข ืื™ื– ืื•ื™ืš ืžืขื’ืœืขืš ืžื™ื˜ CAP_SYS_ADMIN ืคึผืจื™ื•ื•ื™ืœืขื’ื™ืขืก, ืื™ืŸ ื•ื•ืขืœื›ืŸ ืคืึทืœ ื‘ืึทื ื™ืฆืขืจ ื ืขืžืขื ืกืคึผื™ื™ืก ืฉื˜ื™ืฆืข ืื•ืŸ ืฆื•ื˜ืจื™ื˜ ืฆื• ื“ืขืจ ื•ื•ืึธืจืฆืœ cgroup v1 ื›ื™ื™ืขืจืึทืจื›ื™ืข ื–ืขื ืขืŸ ื ื™ืฉื˜ ืคืืจืœืื ื’ื˜.

ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• ืึทื ื˜ืœื•ื™ืคืŸ ืคื•ืŸ ืึทืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ ืงืึทื ื˜ื™ื™ื ืขืจ, ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื•ื™ืš ืึทืœืึทื•ื– ืคึผืจืึทืกืขืกืึทื– ืœืึธื ื˜ืฉื˜ ื“ื•ืจืš ืึท ื•ื•ืึธืจืฆืœ ื‘ืึทื ื™ืฆืขืจ ืึธืŸ "ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื–" ืึธื“ืขืจ ืงื™ื™ืŸ ื‘ืึทื ื™ืฆืขืจ ืžื™ื˜ CAP_DAC_OVERRIDE ืจืขื›ื˜ (ื“ื™ ื‘ืึทืคืึทืœืŸ ืจื™ืงื•ื•ื™ื™ืขืจื– ืึทืงืกืขืก ืฆื• ื“ืขืจ ื˜ืขืงืข /sys/fs/cgroup/*/release_agent, ื•ื•ืึธืก ืื™ื– ืึธื•ื ื“ ื“ื•ืจืš ื•ื•ืึธืจืฆืœ) ืฆื• ื‘ืึทืงื•ืžืขืŸ ืึทืงืกืขืก ืฆื• ืึทืœืข ืกื™ืกื˜ืขืžื™ืง "ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื–".

ืขืก ื•ื•ืขืจื˜ ื‘ืึทืžืขืจืงื˜ ืึทื– ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขืŸ ื ื™ืฉื˜ ืื•ื™ืกื’ืขื ื•ืฆื˜ ื•ื•ืขืจืŸ ื•ื•ืขืŸ ืžืขืŸ ื ื™ืฆื˜ ื“ื™ Seccomp, AppArmor ืื“ืขืจ SE ืฉื•ืฅ ืžืขืงืึทื ื™ื–ืžืขืŸ.Linux ืคึฟืึทืจ ื ืึธืš ืžืขืจ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ืคึฟื•ืŸ ืงืึธื ื˜ืขื™ื ืขืจืก, ื•ื•ืฒึทืœ ืกืขืงืงืึธืžืคึผ ื‘ืœืึธืงื™ืจื˜ ื“ืขื ืจื•ืฃ ืฆื•ื unshare() ืกื™ืกื˜ืขื ืจื•ืฃ, ืื•ืŸ AppArmor ืื•ืŸ SELinux ืขืจืœื•ื™ื‘ื˜ ื ื™ืฉื˜ ืฆื• ืžืึธื ื˜ื™ืจืŸ cgroupfs ืื™ืŸ ืฉืจื™ื™ื‘ ืžืึธื“ืข.

ืžืงื•ืจ: opennet.ru

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster