ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ ื•ื•ืึธืก ืงืขื ืขืŸ ืึธื ืžืึทื›ืŸ ืึท ืงืจืึทืš ื“ื•ืจืš ืฉื™ืงืŸ ืึท UDP ืคึผืึทืงืึทื˜

ืื™ืŸ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2019-11683), ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืจื™ืžืึธื•ื˜ืœื™ ืคืึทืจืฉืึทืคืŸ ืึท ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ ื“ื•ืจืš ืฉื™ืงื˜ ืกืคึผืขืฉืœื™ ื“ื™ื–ื™ื™ื ื“ UDP ืคึผืึทืงื™ืฅ (ืคึผืขืงืœ-ืคื•ืŸ-ื˜ื•ื™ื˜). ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืึท ื˜ืขื•ืช ืื™ืŸ ื“ื™ udp_gro_receive_segment ื”ืึทื ื“ืœืขืจ (net/ipv4/udp_offload.c) ืžื™ื˜ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ GRO (ื’ืขื ืขืจื™ืง ื‘ืึทืงื•ืžืขืŸ ืึธืคืœืึธืึทื“) ื˜ืขื›ื ืึธืœืึธื’ื™ืข ืื•ืŸ ืงืขื ืขืŸ ืคื™ืจืŸ ืฆื• ืฉืขื“ื™ืงืŸ ืฆื• ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ืงืขืจืŸ ื–ื›ึผืจื•ืŸ ื’ืขื‘ื™ื˜ืŸ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ื•ื“ืคึผ ืคึผืึทืงื™ืฅ ืžื™ื˜ ื ื•ืœ ื•ื•ืึทื˜ืŸ. (ืœื™ื™ื“ื™ืง ืคึผื™ื™ืœืึธื•ื“).

ื“ืขืจ ืคึผืจืึธื‘ืœืขื ื ืึธืจ ืึทืคืขืงืฅ ื“ื™ ืงืขืจืŸ 5.0ื–ื™ื ื˜ GRO ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ UDP ืกืึทืงืึทืฅ ืื™ื– ื’ืขื•ื•ืขืŸ ื™ืžืคึผืœืึทืžืขื ืึทื“ ืื™ืŸ ื ืื•ื•ืขืžื‘ืขืจ ืœืขืฆื˜ืข ื™ืึธืจ ืื•ืŸ ื‘ืœื•ื™ื– ื’ืขืจืื˜ืŸ ืฆื• ื‘ืึทืงื•ืžืขืŸ ืื™ืŸ ื“ื™ ืœืขืฆื˜ืข ืกื˜ืึทื‘ื™ืœ ืงืขืจืŸ ืžืขืœื“ื•ื ื’. GRO ื˜ืขื›ื ืึธืœืึธื’ื™ืข ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืคืึทืจื’ื™ื›ืขืจืŸ ื“ื™ ืคึผืจืึทืกืขืกื™ื ื’ ืคื•ืŸ ืึท ื’ืจื•ื™ืก ื ื•ืžืขืจ ืคื•ืŸ ื™ื ืงืึทืžื™ื ื’ ืคึผืึทืงื™ืฅ ื“ื•ืจืš ืึทื’ื’ืจืขื’ื™ื™ื˜ื™ื ื’ ืงื™ื™ืคืœ ืคึผืึทืงื™ืฅ ืื™ืŸ ื’ืจืขืกืขืจืข ื‘ืœืึทืงืก ื•ื•ืึธืก ื˜ืึธืŸ ื ื™ื˜ ื“ืึทืจืคืŸ ื‘ืึทื–ื•ื ื“ืขืจ ืคึผืจืึทืกืขืกื™ื ื’ ืคื•ืŸ ื™ืขื“ืขืจ ืคึผืึทืงืึทื˜.
ืคึฟืึทืจ TCP, ื“ื™ ืคึผืจืึธื‘ืœืขื ืงืขืŸ ื ื™ืฉื˜ ืคึผืึทืกื™ืจืŸ, ื•ื•ื™ื™ึทืœ ื“ืขืจ ืคึผืจืึธื˜ืึธืงืึธืœ ืฉื˜ื™ืฆื˜ ื ื™ืฉื˜ ืคึผืึทืงืึทื˜ ืึทื’ื’ืจืขื’ืึทื˜ื™ืึธืŸ ืึธืŸ ืคึผื™ื™ืœืึธื•ื“.

ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื‘ื™ื– ืื™ืฆื˜ ืคืึทืจืคืขืกื˜ื™ืงื˜ ื‘ืœื•ื™ื– ืื™ืŸ ื“ื™ ืคืึธืจืขื ืœืึทื˜ืข, ื“ื™ ืงืขืจืขืงื˜ื™ื•ื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืื™ื– ื ืึธืš ื ื™ืฉื˜ ืืจื•ื™ืก (ื ืขื›ื˜ืŸ ืก ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ 5.0.11 ืคืึทืจืจื™ื›ื˜ืŸ ื ื™ื˜ ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜). ืคึฟื•ืŸ ื“ื™ ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’ ืงื™ืฅ, ืงืขืจื ืขืœ 5.0 ื’ืขืจืื˜ืŸ ืฆื• ื–ื™ื™ืŸ ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ืŸ ืคืขื“ืึธืจืึท ืงืกื ื•ืžืงืก, Ubuntu 19.04, ืึทืจื˜ืฉ ืœื™ื ื•ืงืก, Gentoo ืื•ืŸ ืื ื“ืขืจืข ืงืึทื ื˜ื™ื ื™ื•ืึทืกืœื™ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื–. ื“ืขื‘ื™ืึทืŸ, Ubuntu 18.10 ืื•ืŸ ืคืจื™ืขืจ, RHEL / CentOS ะธ SUSE/openSUSE ื“ื™ ืคึผืจืึธื‘ืœืขื ื˜ื•ื˜ ื ื™ืฉื˜ ื•ื•ื™ืจืงืŸ.

ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขืคื•ื ืขืŸ ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜ ื ื•ืฆืŸ ืึธื˜ืึทืžื™ื™ื˜ื™ื“ ืคื™ื•ื–ื™ื ื’ ื˜ืขืกื˜ื™ื ื’ ืกื™ืกื˜ืขื ื‘ืืฉืืคืŸ ื“ื•ืจืš Google syzbot ืื•ืŸ ืึทื ืึทืœื™ื–ืขืจ ืงืึทืกืึทืŸ (KernelAddressSanitizer), ืึทื™ืžืขื“ ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ืขืจืจืึธืจืก ื•ื•ืขืŸ ืืจื‘ืขื˜ืŸ ืžื™ื˜ ื–ื™ืงืึธืจืŸ ืื•ืŸ ืคืืงื˜ืŸ ืคื•ืŸ ืคืึทืœืฉ ื–ื™ืงืึธืจืŸ ืึทืงืกืขืก, ืึทื–ืึท ื•ื•ื™ ืึทืงืกืขืกื™ื ื’ ืคืจื™ื™ ื–ื™ืงืึธืจืŸ ื’ืขื‘ื™ื˜ืŸ ืื•ืŸ ืคึผืœื™ื™ืกื™ื ื’ ืงืึธื“ ืื™ืŸ ื–ื™ืงืึธืจืŸ ื’ืขื‘ื™ื˜ืŸ ื•ื•ืึธืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ื‘ื“ืขื” ืคึฟืึทืจ ืึทื–ืึท ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทื ื–.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’