ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ CRI-O ื•ื•ืึธืก ืึทืœืึทื•ื– ื•ื•ืึธืจืฆืœ ืึทืงืกืขืก ืฆื• ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืกื•ื•ื™ื•ื•ืข

ื ืงืจื™ื˜ื™ืฉ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2022-0811) ืื™ื– ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ CRI-O, ืึท ืจื•ื ื˜ื™ืžืข ืคึฟืึทืจ ืึธื ืคื™ืจื•ื ื’ ืืคื’ืขื–ื•ื ื“ืขืจื˜ ืงืึทื ื˜ื™ื™ื ืขืจื–, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื‘ื™ื™ืคึผืึทืก ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ืื•ืŸ ื•ื™ืกืคื™ืจืŸ ื“ื™ื™ืŸ ืงืึธื“ ืื•ื™ืฃ ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืกื™ืกื˜ืขื ื–ื™ื™ึทื˜. ืื•ื™ื‘ CRI-O ืื™ื– ื’ืขื ื™ืฆื˜ ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื“ ืื•ืŸ ื“ืึธืงืขืจ ืฆื• ืœื•ื™ืคืŸ ืงืึทื ื˜ื™ื™ื ืขืจื– ืื•ื ื˜ืขืจ ื“ื™ Kubernetes ืคึผืœืึทื˜ืคืึธืจืžืข, ืึท ืึทื˜ืึทืงืขืจ ืงืขื ืขืŸ ื‘ืึทืงื•ืžืขืŸ ืงืึธื ื˜ืจืึธืœ ืคื•ืŸ ืงื™ื™ืŸ ื ืึธื“ืข ืื™ืŸ ื“ื™ Kubernetes ืงื ื•ื™ืœ. ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ืึท ื‘ืึทืคืึทืœืŸ, ืื™ืจ ื ืึธืจ ื”ืึธื‘ืŸ ื’ืขื ื•ื’ ืจืขื›ื˜ ืฆื• ืœื•ื™ืคืŸ ื“ื™ื™ืŸ ืงืึทื ื˜ื™ื™ื ืขืจ ืื™ืŸ ื“ื™ Kubernetes ืงื ื•ื™ืœ.

ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ื“ื™ ืžืขื’ืœืขื›ืงื™ื™ื˜ ืคื•ืŸ ื˜ืฉืึทื ื’ื™ื ื’ ื“ื™ ืงืขืจืŸ sysctl ืคึผืึทืจืึทืžืขื˜ืขืจ "kernel.core_pattern" ("/proc/sys/kernel/core_pattern"), ืึทืงืกืขืก ืฆื• ื•ื•ืึธืก ืื™ื– ื ื™ืฉื˜ ืืคื’ืขืฉื˜ืขืœื˜, ื˜ืจืึธืฅ ื“ืขืจ ืคืึทืงื˜ ืึทื– ืขืก ืื™ื– ื ื™ืฉื˜ ืฆื•ื•ื™ืฉืŸ ื“ื™ ืคึผืึทืจืึทืžืขื˜ืขืจืก ื–ื™ื›ืขืจ ืฆื• ื˜ื•ื™ืฉืŸ, ื’ื™ืœื˜ื™ืง ื‘ืœื•ื™ื– ืื™ืŸ ื ืึทืžืขืกืคึผื™ื™ืก ืคื•ืŸ ื“ืขื ืงืจืึทื ื˜ ืงืึทื ื˜ื™ื™ื ืขืจ. ื ื™ืฆืŸ ื“ืขื ืคึผืึทืจืึทืžืขื˜ืขืจ, ืึท ื‘ืึทื ื™ืฆืขืจ ืคึฟื•ืŸ ืึท ืงืึทื ื˜ื™ื™ื ืขืจ ืงืขื ืขืŸ ื˜ื•ื™ืฉืŸ ื“ื™ ื ืึทื˜ื•ืจ ืคื•ืŸ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ ืžื™ื˜ ืึทื›ื˜ื•ื ื’ ืฆื• ืคึผืจืึทืกืขืกื™ื ื’ ื”ืึทืจืฅ ื˜ืขืงืขืก ืื•ื™ืฃ ื“ื™ ื–ื™ื™ึทื˜ ืคื•ืŸ ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืกื•ื•ื™ื•ื•ืข ืื•ืŸ ืึธืจื’ืึทื ื™ื–ื™ืจืŸ ื“ื™ ืงืึทื˜ืขืจ ืคื•ืŸ ืึท ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ื‘ืึทืคึฟืขืœ ืžื™ื˜ ื•ื•ืึธืจืฆืœ ืจืขื›ื˜ ืื•ื™ืฃ ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ื–ื™ื™ึทื˜ ื“ื•ืจืš ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืึท ื”ืึทื ื“ืœืขืจ ื•ื•ื™. "|/bin/sh -c 'ืงืึทืžืึทื ื“ื–'" .

ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขื•ื•ืขืŸ ืคืึธืจืฉื˜ืขืœืŸ ื–ื™ื ื˜ ื“ื™ ืžืขืœื“ื•ื ื’ ืคื•ืŸ CRI-O 1.19.0 ืื•ืŸ ืื™ื– ื’ืขื•ื•ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ 1.19.6, 1.20.7, 1.21.6, 1.22.3, 1.23.2 ืื•ืŸ 1.24.0. ืฆื•ื•ื™ืฉืŸ ื“ื™ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื–, ื“ื™ ืคึผืจืึธื‘ืœืขื ืื™ื– ืืจื•ื™ืก ืื™ืŸ ื“ื™ Red Hat OpenShift Container Platform ืื•ืŸ openSUSE / SUSE ืคึผืจืึธื“ื•ืงื˜ืŸ, ื•ื•ืึธืก ื”ืึธื‘ืŸ ื“ื™ ืงืจื™-ืึธ ืคึผืขืงืœ ืื™ืŸ ื–ื™ื™ืขืจ ืจื™ืคึผืึทื–ืึทื˜ืึธืจื™ื–.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’