ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ vhost-net ื•ื•ืึธืก ืึทืœืึทื•ื– ื‘ื™ื™ืคึผืึทืก ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ืื™ืŸ ืกื™ืกื˜ืขืžืขืŸ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ QEMU-KVM

ืื ื˜ืคืœืขืงื˜ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (CVE-2019-14835), ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื’ื™ื™ืŸ ื•ื•ื™ื™ึทื˜ืขืจ ืคื•ืŸ ื“ื™ ื’ืึทืกื˜ ืกื™ืกื˜ืขื ืื™ืŸ KVM (qemu-kvm) ืื•ืŸ ืœื•ื™ืคืŸ ื“ื™ื™ืŸ ืงืึธื“ ืื•ื™ืฃ ื“ื™ ื–ื™ื™ึทื˜ ืคื•ืŸ ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืกื•ื•ื™ื•ื•ืข ืื™ืŸ ื“ืขื ืงืึธื ื˜ืขืงืกื˜ ืคื•ืŸ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืงืึธื“ืขื ืึทืžืขื“ V-gHost. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืึทืœืึทื•ื– ื“ื™ ื’ืึทืกื˜ ืกื™ืกื˜ืขื ืฆื• ืฉืึทืคึฟืŸ ื˜ื ืึธื™ื ืคึฟืึทืจ ืึท ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ืื™ืŸ ื“ื™ vhost-net ืงืขืจืŸ ืžืึธื“ื•ืœืข (ื ืขืฅ ื‘ืึทืงืขื ื“ ืคึฟืึทืจ ื•ื•ื™ืจื˜ื™ืึธ), ืขืงืกืึทืงื™ื•ื˜ืึทื“ ืื•ื™ืฃ ื“ื™ ื–ื™ื™ึทื˜ ืคื•ืŸ ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืกื•ื•ื™ื•ื•ืข. ื“ื™ ื‘ืึทืคืึทืœืŸ ืงืขืŸ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ื“ื•ืจืš ืึท ืึทื˜ืึทืงืขืจ ืžื™ื˜ ืคึผืจื™ื•ื•ืœื™ื“ื–ืฉื“ ืึทืงืกืขืก ืฆื• ื“ื™ ื’ืึทืกื˜ ืกื™ืกื˜ืขื ื‘ืขืฉืึทืก ืึท ื•ื•ื™ืจื˜ื•ืึทืœ ืžืึทืฉื™ืŸ ืžื™ื™ื’ืจื™ื™ืฉืึทืŸ ืึธืคึผืขืจืึทืฆื™ืข.

ืคื™ืงืกื™ืจ ื“ื™ ืคึผืจืึธื‘ืœืขื ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ืŸ ื“ื™ Linux 5.3 ืงืขืจืŸ. ื•ื•ื™ ื•ื•ืึธืจืงืึทืจืึธื•ื ื“ืก ืคึฟืึทืจ ื‘ืœืึทืงื™ื ื’ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, ืื™ืจ ืงืขื ืขืŸ ื“ื™ืกื™ื™ื‘ืึทืœ ืœื™ื™ื•ื• ืžื™ื™ื’ืจื™ื™ืฉืึทืŸ ืคื•ืŸ ื’ืึทืกื˜ ืกื™ืกื˜ืขืžืขืŸ ืึธื“ืขืจ ื“ื™ืกื™ื™ื‘ืึทืœ ื“ื™ vhost-net ืžืึธื“ื•ืœืข (ืœื™ื™ื’ "ื‘ืœืึทืงืœื™ืกื˜ vhost-net" ืฆื• /etc/modprobe.d/blacklist.conf). ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ืกื˜ืึทืจื˜ื™ื ื’ ืคึฟื•ืŸ ืœื™ื ื•ืงืก ืงืขืจืŸ 2.6.34. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื•ื‘ื•ื ื˜ื• ะธ ืคืขื“ืึธืจืึท, ืึธื‘ืขืจ ื ืึธืš ื‘ืœื™ื™ื‘ื˜ ืึทื ืงืขืจืขืงื˜ื™ื“ ืื™ืŸ ื“ืขื‘ื™ืึทืŸ, ืึทืจื˜ืฉ ืœื™ื ื•ืงืก, sususe ะธ rhel.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’