ืืื ืืขื ksmbd ืืึธืืื, ืืืึธืก ืึธืคืคืขืจื ืึทื ืืืื ืืขืืืืื ืงืขืจื ืขื Linux ืคืขืจืฆื ืฉืืืืืงืืืื ืืขื ืขื ืืืืขื ืืืคืืฆืืจื ืืขืืืืจื ืืื ืืขืจ SMB-ืืืืืจืืขืจ ืืขืงืข ืกืขืจืืืขืจ ืืืืคืืขืืขื ืืืฆืืข, ืคืืจ ืคืื ืืืขืืืข ืขืจืืืืื ืืืืืืขืจ ืงืืื ืืืืกืคืืจืื ื ืืื ืงืขืจื ืขื ืคืจืืืืืืขืืืขืก. ืื ืืืืงืข ืงืขื ืืืจืืืขืคืืจื ืืืขืจื ืื ืืืืืขื ืืืคืืงืืฆืืข; ืืขืจ ksmbd ืืืืื ืืื ืืืื ืขื ืืืืึทืื ืืืืคื ืกืืกืืขื. ืื ืคืจืืืืขืืขื ืืขื ืขื ืคืืจืื ืืื ื ืงืขืจื ืขื 5.15, ืืืืก ืืื ืืจืืื ืืขื ืืืขื ืืขื ksmbd ืืืืื. ืื ืฉืืืืืงืืืื ืืขื ืขื ืคืืจืจืืืื ืืขืืืืจื ืืื ืงืขืจื ืขื ืืคืืขืืืก 6.3.2, 6.2.15, 6.1.28, ืืื 5.15.112. ืืืจ ืงืขื ื ื ืืืคืืืื ืื ืคึผืึทืืฉืขืก ืืื ืื ืืืกืืจืืืืืฉืึทื ื ืืืืฃ ืื ืคืืืืขื ืืข ืืืขืืขืจ: Debian, Ubuntu, ืืืฉืขื ืื, RHEL, ืกืืกืข, ืคืขืืึธืจืึท, ืืืฉืขื ืื, ืึทืจืืฉ.
ืืืืขื ืึทืคืืื ืืฉืื:
- CVE-2023-32254, CVE-2023-32250, CVE-2023-32257, CVE-2023-32258 - ืืืจืืคืืจืื ื ืคืื ืืืืึทื ืงืึธื ืืื ืงืขืจื ืจืขืื ืจืขืื ืฆื ืืขืจ ืคืขืื ืคืื ืืขืืขืจืืง ืึทืืืืฉืขืงืฅ ืืึทืงืื ื ืืืขื ืคึผืจืึทืกืขืกืื ื ืคืื ืืจืืืกื ืืืง ืจืืงืืืขืก ืืื ืื SMB2_TREE_DISCON , SMB2_TREE_DISCON, SMB2_TREE_DISCON, SMB2_TREE_DISCON, SMBXNUMX_TREE_DISCON SMBXNUMX_CLOSE, ืืืึธืก ืจืขืืืืืึทืื ืืื ืึท ืขืงืกืคึผืืืืืึทืืึทื ืจืึทืกืข ืฆืืฉืืึทื ื. ืื ืืึทืคืึทืื ืงืขื ืขื ืืืื ืืืจืืืขืงืึธืื ืึธื ืึธืืขื ืืึทืงืืืฉืึทื.
- CVE-2023-32256 - ืืืงืื ื ืื ืืื ืืึทืื ืคืื ืงืขืจื ืืึผืจืื ืืงืืืืช ืจืขืื ืฆื ืึท ืจืึทืกืข ืฆืืฉืืึทื ื ืืขืฉืึทืก ืื ืคึผืจืึทืกืขืกืื ื ืคืื SMB2_QUERY_INFO ืืื SMB2_LOGOFF ืงืึทืืึทื ืื. ืื ืืึทืคืึทืื ืงืขื ืขื ืืืื ืืืจืืืขืงืึธืื ืึธื ืึธืืขื ืืึทืงืืืฉืึทื.
- CVE-2023-32252, CVE-2023-32248 - ืืืืึทื ืึธืคึผืืืืงืขื ืื ื ืคืื ืืื ืกื ืจืขืื ืฆื ืึท NULL ืืืึทืื ืืขืจืคืขืจืึทื ืก ืืืขื ืคึผืจืึทืกืขืกืื ื ืื SMB2_LOGOFF, SMB2_TREE_CONNECT ืืื SMB2_QUERY_INFO ืงืึทืืึทื ืื. ืื ืืึทืคืึทืื ืงืขื ืขื ืืืื ืืืจืืืขืงืึธืื ืึธื ืึธืืขื ืืึทืงืืืฉืึทื.
- CVE-2023-32249 - ืืขืืืขืืงืืื ืคืื ืกืขืกืืข ืืืืืืฉืึทืงืื ื ืืื ืึท ืืึทื ืืฆืขืจ ืจืขืื ืฆื ืคืขืื ืคืื ืืขืืขืจืืง ืืคืืขืืื ืืขืจืืงืืื ืืืขื ืืึทื ืืืื ื ืึท ืกืขืกืืข ืฉืืึทื ืืื ืืืืื-ืงืึทื ืึทื ืืึธืืข.
- CVE-2023-32247, CVE-2023-32255 - ื ืึธืคึผืืืืงืขื ืื ื ืคืื ืืื ืกื ืจืขืื ืฆื ืึท ืืึผืจืื ืจืื ืขื ืืืขื ืคึผืจืึทืกืขืกืื ื ืื SMB2_SESSION_SETUP ืืึทืคึฟืขื. ืื ืืึทืคืึทืื ืงืขื ืขื ืืืื ืืืจืืืขืงืึธืื ืึธื ืึธืืขื ืืึทืงืืืฉืึทื.
- CVE-2023-2593 ืืื ืึท ืึธืคึผืืืืงืขื ืื ื ืคืื ืืื ืกื ืจืขืื ืฆื ืืืืึธืกืืฉืึทื ืคืื ืื ืืืฆื ืืึผืจืื, ืืขืคึฟืืจื ืืืจื ืึท ืืึผืจืื ืืืจืืคืึทื ืืืขื ืคึผืจืึทืกืขืกืื ื ื ืืึท ืืงืคึผ ืงืึทื ืขืงืฉืึทื ื. ืื ืืึทืคืึทืื ืงืขื ืขื ืืืื ืืืจืืืขืงืึธืื ืึธื ืึธืืขื ืืึทืงืืืฉืึทื.
- CVE-2023-32253 ื ืึธืคึผืืืืงืขื ืื ื ืคืื ืืื ืกื ืจืขืื ืฆื ืึท ืืขืืืึทืง ืึทืงืขืจื ืืืขื ืคึผืจืึทืกืขืกืื ื ืื SMB2_SESSION_SETUP ืืึทืคึฟืขื. ืื ืืึทืคืึทืื ืงืขื ืขื ืืืื ืืืจืืืขืงืึธืื ืึธื ืึธืืขื ืืึทืงืืืฉืึทื.
- CVE-2023-32251 - ืคืขืื ืคืื ืฉืืฅ ืงืขืื ืืจืื ืงืจืึทืคื ืื ืคืืื.
- CVE-2023-32246 - ื ืืืงืืืขืจ ืกืืกืืขื ืืื ืืฆืขืจ ืืืื ืจืขืื ืฆื ืืคืืืื ืืขื ksmbd ืืืืื ืงืขื ืืขืจืืจืืืื ืงืขืจื ืขื ืงืืื ืืืืกืคืืจืื ื. Linux.
ืืื ืึทืืืฉืึทื, 5 ืืขืจ ืืืึทืื ืขืจืึทืืืืืืื ืืขื ืขื ืืืืขื ืึทืคืืื ืืื ืื ksmbd-tools ืคึผืขืงื, ืืืึธืก ืืืื ืืืืืืึทืืื ืคึฟืึทืจ ืึธื ืคืืจืื ื ืืื ืืจืืขืื ืืื ksmbd, ืขืงืกืึทืงืืืืึทื ืืื ืืึทื ืืฆืขืจ ืคึผืืึทืฅ. ืื ืืขืจืกื ืืขืคืขืจืืขื ืืืึทืื ืขืจืึทืืืืืืื (ZDI-CAN-17822, ZDI-CAN-17770, ZDI-CAN-17820, CVE ื ืึธื ื ืืฉื ืึทืกืืื ื) ืืึธืื ืึท ืืืืึทื, ืึทื ืึธืืขื ืืืงืืืืื ืึทืืึทืงืขืจ ืฆื ืืืกืคืืจื ืืืืขืจ ืงืึธื ืืื ืืืึธืจืฆื ืจืขืื. ืื ืืืึทืื ืขืจืึทืืืืืืื ืืขื ืขื ืืขืคึฟืืจื ืืืจื ืื ืคืขืื ืคืื ืงืึธื ืืจืึธืืืจืื ื ืื ืืจืืืก ืคืื ืืืงืืืขื ืคืื ืืจืืืกื ืืืง ืืึทืื ืืืืืขืจ ืงืึทืคึผืืื ื ืขืก ืฆื ืื ืืึทืคืขืจ ืืื ืื WKSSVC ืกืขืจืืืืก ืงืึธื ืืื ืืื ืื LSARPC_OPNUM_LOOKUP_SID2 ืืื SAMR_OPNUM_QUERY_USER_INFO ืึธืคึผืงืึธืืข ืืึทื ืืืขืจืก. ืฆืืืื ืืขืจ ืืืึทืื ืขืจืึทืืืืืืื (ZDI-CAN-17823, ZDI-CAN-17821) ืงืขื ืขื ืคืืจื ืฆื ืืืืึทื ืึธืคึผืืืืงืขื ืื ื ืคืื ืืื ืกื ืึธื ืึธืืขื ืืึทืงืืืฉืึทื.
Ksmbd ืืืขืจื ืคึผืจืึธืืึธืืืจื ืืื ืึท ืืืื-ืคึผืขืจืคืึธืจืืึทื ืก, ืขืืืขืืื-ืืจืืื ืขืงืกืืขื ืฉืึทื ืฆื ืกืึทืืืึท, ืืื ืืขืืจืืจื ืืืง ืืื ืกืึทืืืึท ืืืฉืืจืื ืืื ืืืืืจืขืจืื ืืื ื ืืืืืง. ืฉืืืฆืข ืคึฟืึทืจ ืืืืคื ืึทื SMB ืกืขืจืืืขืจ ื ืืฆื ืื ksmbd ืืึธืืื ืืื ืคืึธืจืฉืืขืื ืืื ืื ืกืึทืืืึท ืคึผืขืงื ืืื ื ืืขืืืื ื 4.16.0. ื ืื ืืื ืึท ืืึทื ืืฆืขืจ-ืกืคึผืืืก SMB ืกืขืจืืืขืจ, ืืื ksmbd ืืขืจ ืขืคืขืงืืืื ืืื ืืขืจืืื ืขื ืคืื ืคึผืขืจืคืึธืจืืึทื ืก, ืืึผืจืื ืงืึทื ืกืึทืืฉืึทื, ืืื ืืื ืืขืืจืึทืฆืืข ืืื ืึทืืืึทื ืกืืจืืข ืงืขืจื ืขื ืคึฟืขืึดืงืืืื. ืืขืจ ksmbd ืงืึธื ืืื ืืขืฉืจืืื ืืืจื ื ืึทืืืืฉืึทืข ืืืฉืขืึธื ืคืื ืกืึทืืกืื ื ืืื ืืืื ืืฉืื ืื ืคืื LG, ืืื ืืืื ืงืขืจื ืขื ืืืื ืืืื ืขืจ ืืื ืกืืืื ืคืจืขื ืืฉ ืคืื ืืืืงืจืึธืกืึธืคึฟื, ืืขืจ ืืืื ืืืื ืขืจ ืคืื ืื CIFS/SMB2/SMB3 ืกืืืกืืกืืขืืขื ืืื ืื ืงืขืจื ืขื. Linux ืืื ืึท ืืึทื ืืืขืจืืงืขืจ ืืืืืืื ืคืื ืืขืจ ืกืึทืืืึท ืึทื ืืืืืงืืื ื ืืึทื ืฉืึทืคึฟื, ืืืึธืก ืืึธื ืืขืืึทืื ืืึทืืืืื ืืืงืข ืืืืฉืืืืขืจืื ืืขื ืฆื ืืขืจ ืืืืคึผืืขืืขื ืืึทืฆืืข ืคืื โโSMB/CIFS ืคึผืจืึธืืึธืงืึธื ืฉืืืฆืข ืืื ืกืึทืืืึท ืืื Linux.
ืึทืืืืืืึธื ืึทืืื, ืฆืืืื ืืืึทืื ืขืจืึทืืืืืืื ืงืขื ืขื ืืืื ืืืืขืจืงื ืืื ืื vmwgfx ืืจืึทืคืืงืก ืืจืืืืืขืจ, ืืขื ืืฆื ืฆื ืื ืกืืจืืืขื ื 3 ื ืึทืงืกืขืืขืจืืืฉืึทื ืืื VMware ืื ืืืืืจืึทื ืืึทื ืฅ. ืืขืจ ืขืจืฉืืขืจ ืืืึทืื ืขืจืึทืืืืืื (ZDI-CAN-20292) ืึทืืึทืื ืึท ืืืืข ืืึทื ืืฆืขืจ ืฆื ืขืกืงืึทืืืื ืืืืขืจ ืคึผืจืืืืืืึทืืืฉืึทื ืืื ืื ืกืืกืืขื. ืื ืืืึทืื ืขืจืึทืืืืืื ืืื ืจืขืื ืฆื ืึท ืคืขืื ืคืื ืงืึธื ืืจืึธืืืจืื ื ืื ืฉืืึทื ืคืื ืึท ืืึทืคืขืจ ืืืืืขืจ ืคืจืื ืขืก ืืืขื ืคึผืจืึทืกืขืกืื ื ืึท vmw_buffer_object, ืืืึธืก ืงืขื ืจืขืืืืืึทื ืืื ืึท ืืึธืคึผื ืจืืคื ืฆื ืื ืคืจืื ืคืื ืงืฆืืข. ืื ืจืืข ืืืึทืื ืขืจืึทืืืืืื (ZDI-CAN-20110) ืคืืจื ืฆื ืึท ืจืื ืขื ืคืื ืงืขืจื ืืึผืจืื ืืื ืืึทืื ืจืขืื ืฆื ืขืจืจืึธืจืก ืืื ืึธืจืืึทื ืืืืื ื ืื ืืึทืงืื ื ืคืื ืืืืืฉืืืื ืึทืืืืฉืขืงืฅ.
ืืงืืจ: opennet.ru
