ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ IPv6 ืึธื ืœื™ื™ื’ืŸ ืคื•ืŸ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ ื•ื•ืึธืก ืึทืœืึทื•ื– ื•ื•ื™ื™ึทื˜ ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’

ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืื™ื– ื“ื™ืกืงืœืึธื•ื–ื“ ื•ื•ืขื’ืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ CVE-2023-6200) ืื™ืŸ ื“ื™ ื ืขืฅ ืึธื ืœื™ื™ื’ืŸ ืคื•ืŸ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ, ื•ื•ืึธืก, ืื•ื ื˜ืขืจ ื–ื™ื›ืขืจ ืฆื•ืฉื˜ืื ื“ืŸ, ืึทืœืึทื•ื– ืึท ืึทื˜ืึทืงืขืจ ืคื•ืŸ ืึท ื”ื™ื’ืข ื ืขืฅ ืฆื• ื“ืขืจื’ืจื™ื™ื›ืŸ ื“ื™ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื–ื™ื™ืŸ ืงืึธื“ ื“ื•ืจืš ืฉื™ืงืŸ ืึท ืกืคึผืขืฆื™ืขืœ ื“ื™ื–ื™ื™ื ื“ ICMPv6 ืคึผืึทืงืึทื˜ ืžื™ื˜ ืึท RA (ืจืึธื•ื˜ืขืจ ื’ืึทื ืฆืข) ืึธื ื–ืึธื’ ื‘ื“ืขื” ืฆื• ืžืขืœื“ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ืจืึทื•ื˜ืขืจ.

ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืขืงืกืคึผืœื•ื™ื˜ืึทื“ ื‘ืœื•ื™ื– ืคึฟื•ืŸ ื“ื™ ื”ื™ื’ืข ื ืขืฅ ืื•ืŸ ืื™ื– ืืจื•ื™ืก ืื•ื™ืฃ ืกื™ืกื˜ืขืžืขืŸ ืžื™ื˜ IPv6 ืฉื˜ื™ืฆืŸ ืขื ื™ื™ื‘ืึทืœื“ ืื•ืŸ ื“ื™ sysctl ืคึผืึทืจืึทืžืขื˜ืขืจ "net.ipv6.conf.<network_interface_name>.accept_ra" ืึทืงื˜ื™ื•ื• (ืงืขื ืขืŸ ื–ื™ื™ืŸ ืึธืคึผื’ืขืฉื˜ืขืœื˜ ืžื™ื˜ ื“ื™ ื‘ืึทืคึฟืขืœ "sysctl net.ipv6.conf" | grep accept_ra") , ื•ื•ืึธืก ืื™ื– ืคืึทืจืงืจื™ืคึผืœื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ ืื™ืŸ RHEL ืื•ืŸ Ubuntu ืคึฟืึทืจ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–, ืึธื‘ืขืจ ืขื ื™ื™ื‘ืึทืœื“ ืคึฟืึทืจ ื“ื™ ืœื•ืคึผื‘ืึทืงืง ืฆื•ื‘ื™ื ื“, ื•ื•ืึธืก ืึทืœืึทื•ื– ืึทืŸ ื‘ืึทืคืึทืœืŸ ืคื•ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืกื™ืกื˜ืขื.

ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืึท ืจืึทืกืข ืฆื•ืฉื˜ืึทื ื“ ื•ื•ืขืŸ ื“ื™ ืžื™ืกื˜ ืงืึทืœืขืงื˜ืขืจ ืคึผืจืึทืกืขืกืึทื– ืึทืœื˜ - ื’ืขื‘ืึทืงืŸ fib6_info ืจืขืงืึธืจื“ืก, ื•ื•ืึธืก ืงืขื ืขืŸ ืคื™ืจืŸ ืฆื• ืึทืงืกืขืก ืฆื• ืึท ืฉื•ื™ืŸ ื‘ืืคืจื™ื™ื˜ ื–ื›ึผืจื•ืŸ ื’ืขื’ื ื˜ (ื ื•ืฆืŸ-ื ืึธืš-ืคืจื™ื™). ื•ื•ืขืŸ ืื™ืจ ื‘ืึทืงื•ืžืขืŸ ืึท ICMPv6 ืคึผืึทืงืึทื˜ ืžื™ื˜ ืึท ืจืึทื•ื˜ืขืจ ืึทื“ื•ื•ืขืจื˜ื™ื™ื–ืžืึทื ื˜ ืึธื ื–ืึธื’ (RA, Router Advertisement), ื“ืขืจ ื ืขืฅ ืกื˜ืึทืง ืจื•ืคื˜ ื“ื™ ndisc_router_discovery () ืคึฟื•ื ืงืฆื™ืข, ื•ื•ืึธืก, ืื•ื™ื‘ ื“ื™ RA ืึธื ื–ืึธื’ ื›ึผื•ืœืœ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ืžืึทืจืฉืจื•ื˜ ืœืขื‘ืŸ, ืจื•ืคื˜ ื“ื™ fib6_set_expires () ืคึฟื•ื ืงืฆื™ืข ืื•ืŸ ืคึผืœืึธืžื‘ื™ืจืŸ ื“ื™ gc_link ืกื˜ืจื•ืงื˜ื•ืจ. ืฆื• ืจื™ื™ืŸ ืึทืจื•ื™ืฃ ืคืึทืจืขืœื˜ืขืจื˜ ืื™ื™ื ืกืŸ, ื ื•ืฆืŸ ื“ื™ fib6_clean_expires() ืคึฟื•ื ืงืฆื™ืข, ื•ื•ืึธืก ื“ื™ื˜ืึทื˜ืฉื™ื– ื“ื™ ืคึผืึธื–ื™ืฆื™ืข ืื™ืŸ gc_link ืื•ืŸ ืงืœื™ืจื– ื“ื™ ื–ื›ึผืจื•ืŸ ื’ืขื ื™ืฆื˜ ื“ื•ืจืš ื“ื™ fib6_info ืกื˜ืจื•ืงื˜ื•ืจ. ืื™ืŸ ื“ืขื ืคืึทืœ, ืขืก ืื™ื– ืึท ื–ื™ื›ืขืจ ืžืึธืžืขื ื˜ ื•ื•ืขืŸ ื“ืขืจ ื–ื›ึผืจื•ืŸ ืคึฟืึทืจ ื“ื™ fib6_info ืกื˜ืจื•ืงื˜ื•ืจ ืื™ื– ืฉื•ื™ืŸ ื‘ืืคืจื™ื™ื˜, ืึธื‘ืขืจ ื“ื™ ืœื™ื ืง ืฆื• ืขืก ื”ืืœื˜ ืฆื• ื–ื™ื™ืŸ ืื™ืŸ ื“ื™ gc_link ืกื˜ืจื•ืงื˜ื•ืจ.

ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืืจื•ื™ืก ืคึฟื•ืŸ ืฆื•ื•ื™ื™ึทื’ 6.6 ืื•ืŸ ืื™ื– ื’ืขื•ื•ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื•ื•ืขืจืกื™ืขืก 6.6.9 ืื•ืŸ 6.7. ื“ื™ ืกื˜ืึทื˜ื•ืก ืคื•ืŸ ืคื™ืงืกื™ืจ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– ืงืขื ืขืŸ ื–ื™ื™ืŸ ืึทืกืกืขืกืกืขื“ ืื•ื™ืฃ ื“ื™ ื‘ืœืขื˜ืขืจ: Debian, Ubuntu, SUSE, RHEL, Fedora, Arch Linux, Gentoo, Slackware. ืฆื•ื•ื™ืฉืŸ ื“ื™ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– ื•ื•ืึธืก ืฉื™ืงืŸ ืคึผืึทืงืึทื“ื–ืฉืึทื– ืžื™ื˜ ื“ื™ 6.6 ืงืขืจืŸ, ืžื™ืจ ืงืขื ืขืŸ ื˜ืึธืŸ Arch Linux, Gentoo, Fedora, Slackware, OpenMandriva ืื•ืŸ Manjaro; ืื™ืŸ ืื ื“ืขืจืข ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื–, ืขืก ืื™ื– ืžืขื’ืœืขืš ืึทื– ื“ื™ ืขื ื“ืขืจื•ื ื’ ืžื™ื˜ ืึท ื˜ืขื•ืช ืื™ื– ื‘ืึทืงืคึผืึธืจื˜ืขื“ ืื™ืŸ ืคึผืึทืงืึทื“ื–ืฉืึทื– ืžื™ื˜ ืขืœื˜ืขืจืข ืงืขืจืŸ ืฆื•ื•ื™ื™ื’ืŸ (ืคึฟืึทืจ ืœืžืฉืœ, ืื™ืŸ ื“ืขื‘ื™ืึทืŸ ืขืก ืื™ื– ื“ืขืจืžืื ื˜ ืึทื– ื“ืขืจ ืคึผืขืงืœ ืžื™ื˜ ืงืขืจืŸ 6.5.13 ืื™ื– ืฉืคึผื™ืจืขื•ื•ื“ื™ืง, ื‘ืฉืขืช ื“ื™ ืคึผืจืึธื‘ืœืขืžืึทื˜ื™ืง ืขื ื“ืขืจื•ื ื’ ืื™ื– ืืจื•ื™ืก ืื™ืŸ ื“ื™ 6.6 ืฆื•ื•ื™ื™ึทื’). ื•ื•ื™ ืึท ื–ื™ื›ืขืจื”ื™ื™ื˜ ื•ื•ืึธืจืงืึทืจืึธื•ื ื“, ืื™ืจ ืงืขื ืขืŸ ื“ื™ืกื™ื™ื‘ืึทืœ IPv6 ืึธื“ืขืจ ืฉื˜ืขืœืŸ ื“ื™ "net.ipv0.conf.*.accept_ra" ืคึผืึทืจืึทืžืขื˜ืขืจืก ืฆื• 6.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’