ืืืืขืจืืืืืก-ืคืืจืฉืขืจ ืคืื ืืืื ืืืื ืืืืขื ืืืคืืฆืืจื ื ืฉืืืืืงืืื (CVE-2025-38236) ืืื ืืขื ืืื ืืงืก ืงืขืจื ืขื ืืืืก ืขืจืืขืืืืื ืคืจืืืืืืขืืืข ืขืกืงืืืืฆืืข. ืฆืืืืฉื ืื ืืขืจืข ืืืื, ืขืจืืขืืืืื ืื ืฉืืืืืงืืื ืฆื ืืืืคึผืึทืกื ืืขื ืืึทืืืงืึทืกืื ืืืืึธืืึทืฆืืข ืืขืงืึทื ืืื ืืขื ืืฆื ืืื ืืืื ืงืจืึธืื ืืื ืืขืจืืจืืืื ืงืขืจื ืขื-ืืขืืืขื ืงืึธื ืืืืกืคืืจืื ื ืืืขื ืืืืกืคืืจื ืืืง ืงืึธื ืืื ืืขื ืงืึธื ืืขืงืกื ืคืื ืึทื ืืืืึธืืืจืื ืงืจืึธืื ืจืขื ืืขืจืื ื ืคึผืจืึธืฆืขืก (ืืืฉื, ืืืขื ืืขื ืขืงืกืคึผืืืืืืจื ืึทื ืึทื ืืขืจ ืฉืืืืืงืืื ืืื ืงืจืึธืื). ืื ืคึผืจืึธืืืขื ืืขืจืฉืืื ื ืึธื ืืืืื ืืืง ืืืื ืืื ืืงืก ืงืขืจื ืขื 6.9 ืืื ืืื ืืขืืืึธืจื ืคืึทืจืจืืื ืืื ืืื ืืงืก ืงืขืจื ืขื ืืขืจืืืึทื ืืืงืื ืืขื 6.1.143, 6.6.96, 6.12.36, ืืื 6.15.5. ื ืคึผืจืึธืืึธืืืคึผ ืคืื ืืขื ืขืงืกืคึผืืืื ืืื ืคืึทืจืึทื ืฆื ืืึทืื ืืึธืืื.
ืื ืฉืืืึทืืงืืื ืืืขืจื ืืขืคึฟืืจื ืืืจื ืึทื ืืืืคึผืืขืืขื ืืึทืฆืืข ืืขืืช ืืื ืืขื MSG_OOB ืคืึธื, ืืืึธืก ืงืขื ืืขืฉืืขืื ืืืขืจื ืคึฟืึทืจ AF_UNIX ืกืึธืงืขืืก. ืืขืจ MSG_OOB ("out-of-band") ืคืึธื ืขืจืืืืื ืึทื ื ืึธื ืืืื ืฆื ืืืื ืึทืืึทืืฉื ืฆื ืื ืืึทืื ืืืึธืก ืืืขืจื ืืขืฉืืงื, ืืืึธืก ืืขืจ ืืคื ืขืืขืจ ืงืขื ืืืืขื ืขื ืืืืืขืจ ืื ืจืขืฉื ืคืื ืื ืืึทืื ืืืขืจื ืืึทืงืืืขื. ืืขืจ ืคืึธื ืืื ืฆืืืขืืขืื ืืขืืืึธืจื ืืื ืืขื ืืื ืืงืก 5.15 ืงืขืจื ืขื ืืืืฃ ืืขืจ ืืงืฉื ืคืื ืึธืจืึทืงื ืืื ืืื ืคืืจืืขืฉืืึธืื ืืขืืืึธืจื ืคึฟืึทืจ ืืขืคึผืจืขืงืึทืฆืืข ืืขืฆืื ืืึธืจ ืืืืื ืขืก ืืื ื ืืฉื ืืจืืื ืืขื ืืฆื ืืขืืืึธืจื.
ืงืจืึธืื'ืก ืืึทืืืงืึทืกืื ืืืืคึผืืขืืขื ืืึทืฆืืข ืืึธื ืขืจืืืืื UNIX ืกืึธืงืขื ืึธืคึผืขืจืึทืฆืืขืก ืืื send()/recv() ืกืืกืืขื ืจืืคื, ืืืื ืืขืจ MSG_OOB ืคืึธื ืืื ืขืจืืืืื ืืขืืืึธืจื ืฆืืืึทืืขื ืืื ืึทื ืืขืจืข ืึธืคึผืฆืืขืก ืืื ืืื ื ืืฉื ืืึทืืื ืืขืจ ืืขืคืืืืขืจื ืืขืืืึธืจื. ื ืืึทื ืืื ืืขืจ MSG_OOB ืืืืคึผืืขืืขื ืืึทืฆืืข ืืึธื ืขืจืืืืื ืึท "use-after-free" ืืึทืืื ืืื ื ืฆื ืคึผืึทืกืืจื ื ืึธื ืืืจืืคืืจื ืึท ืืขืืืืกืข ืกืืงืืืึทื ืก ืคืื ืกืืกืืขื ืจืืคื: char dummy; int socks[2]; socketpair(AF_UNIX, SOCK_STREAM, 0, socks); send(socks[1], "A", 1, MSG_OOB); recv(socks[0], &dummy, 1, MSG_OOB); send(socks[1], "A", 1, MSG_OOB); recv(socks[0], &dummy, 1, MSG_OOB); send(socks[1], "A", 1, MSG_OOB); recv(socks[0], "A", 1, MSG_OOB); recv(socks[0], &dummy, 0, 1); ืจืขืงืฐ(ืืืงื[XNUMX], &ืืึทืื, XNUMX, MSG_OOB);
ืืงืืจ: opennet.ru
