ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ vhost-net ื“ืจื™ื™ื•ื•ืขืจ ืคึฟื•ืŸ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ

ืื™ืŸ ื“ื™ vhost-net ื“ืจื™ื™ื•ื•ืขืจ, ื•ื•ืึธืก ื™ื ืฉื•ืจื– ื“ื™ ืึธืคึผืขืจืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื•ื•ื™ืจื˜ื™ืึธ ื ืขืฅ ืื•ื™ืฃ ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืกื•ื•ื™ื•ื•ืข ื–ื™ื™ึทื˜, ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2020-10942), ืึทืœืึทื•ื™ื ื’ ืึท ื”ื™ื’ืข ื‘ืึทื ื™ืฆืขืจ ืฆื• ืึธื ื”ื™ื™ื‘ืŸ ืึท ืงืขืจืŸ ืกื˜ืึทืง ืึธื•ื•ื•ืขืจืคืœืึธื• ื“ื•ืจืš ืฉื™ืงืŸ ืึท ืกืคึผืขืฆื™ืขืœ ืคืึธืจืžืึทื˜ื˜ืขื“ ioctl (VHOST_NET_SET_BACKEND) ืฆื• ื“ื™ /dev/vhost-net ืžื™ื˜ืœ. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ื“ื™ ืคืขืœืŸ ืคื•ืŸ ื’ืขื”ืขืจื™ืง ื•ื•ืึทืœืึทื“ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ื“ื™ sk_family ืคืขืœื“ ืื™ืŸ ื“ื™ get_raw_socket () ืคื•ื ืงืฆื™ืข ืงืึธื“.

ืœื•ื™ื˜ ืคึผืจื™ืœื™ืžืึทื ืขืจื™ ื“ืึทื˜ืŸ, ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขื ืขืŸ ื•ื•ืขืจืŸ ื’ืขื ื•ืฆื˜ ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ืึท ื”ื™ื’ืข ื“ืึธืก ื‘ืึทืคืึทืœืŸ ื“ื•ืจืš ืงืึธื–ื™ื ื’ ืึท ืงืขืจืŸ ืงืจืึทืš (ืขืก ืื™ื– ืงื™ื™ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ืกื˜ืึทืง ืึธื•ื•ื•ืขืจืคืœืึธื• ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืฆื• ืึธืจื’ืึทื ื™ื–ื™ืจืŸ ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’).
ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ื™ืœื™ืžืึทื ื™ื™ื˜ืึทื“ ืื™ืŸ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ 5.5.8 ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ. ืคึฟืึทืจ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื–, ืื™ืจ ืงืขื ืขืŸ ืฉืคึผื•ืจ ื“ื™ ืžืขืœื“ื•ื ื’ ืคื•ืŸ ืคึผืขืงืœ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืื•ื™ืฃ ื“ื™ ื‘ืœืขื˜ืขืจ ื“ืขื‘ื™ืึทืŸ, ื•ื‘ื•ื ื˜ื•, rhel, SUSE/openSUSE, ืคืขื“ืึธืจืึท, ืึทืจื˜ืฉ.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’