ืฉื•ื•ืึทื›ืงื™ื™ื˜ืŸ ืื™ืŸ ื“ื™ ksmbd ืงืขืจื ืขืœ ืžืึธื“ื•ืœ Linux, ืึทืœืึทื•ื™ื ื’ ืื™ืจ ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ื“ื™ื™ืŸ ืงืึธื“ ื•ื•ื™ื™ึทื˜

ืื™ืŸ ื“ืขื ksmbd ืžืึธื“ื•ืœ, ื•ื•ืึธืก ืึธืคืคืขืจื˜ ืึทืŸ ืื™ื™ื ื’ืขื‘ื•ื™ื˜ืŸ ืงืขืจื ืขืœ Linux ืคืขืจืฆืŸ ืฉื•ื•ืื›ืงื™ื™ื˜ืŸ ื–ืขื ืขืŸ ืื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจื˜ ื’ืขื•ื•ืืจืŸ ืื™ืŸ ื“ืขืจ SMB-ื‘ืื–ื™ืจื˜ืขืจ ื˜ืขืงืข ืกืขืจื•ื•ืขืจ ืื™ืžืคืœืขืžืขื ื˜ืืฆื™ืข, ืคื™ืจ ืคื•ืŸ ื•ื•ืขืœื›ืข ืขืจืœื•ื™ื‘ืŸ ื•ื•ื™ื™ื˜ืขืจ ืงืื•ื“ ืื•ื™ืกืคื™ืจื•ื ื’ ืžื™ื˜ ืงืขืจื ืขืœ ืคืจื™ื•ื•ื™ืœืขื’ื™ืขืก. ื“ื™ ืื˜ืืงืข ืงืขืŸ ื“ื•ืจื›ื’ืขืคื™ืจื˜ ื•ื•ืขืจืŸ ืืŸ ืื•ื™ื˜ืขื ื˜ื™ืคื™ืงืืฆื™ืข; ื“ืขืจ ksmbd ืžืื“ื•ืœ ืžื•ื– ื–ื™ื™ืŸ ืขื ื™ื™ื‘ืึทืœื“ ืื•ื™ืคืŸ ืกื™ืกื˜ืขื. ื“ื™ ืคืจืื‘ืœืขืžืขืŸ ื–ืขื ืขืŸ ืคืืจืืŸ ื–ื™ื ื˜ ืงืขืจื ืขืœ 5.15, ื•ื•ืืก ื”ืื˜ ืืจื™ื™ื ื’ืขื ื•ืžืขืŸ ื“ืขื ksmbd ืžืื“ื•ืœ. ื“ื™ ืฉื•ื•ืื›ืงื™ื™ื˜ืŸ ื–ืขื ืขืŸ ืคืืจืจืื›ื˜ืŸ ื’ืขื•ื•ืืจืŸ ืื™ืŸ ืงืขืจื ืขืœ ืืคื“ืขื™ื˜ืก 6.3.2, 6.2.15, 6.1.28, ืื•ืŸ 5.15.112. ืื™ืจ ืงืขื ื˜ ื ืื›ืคืืœื’ืŸ ื“ื™ ืคึผืึทื˜ืฉืขืก ืื™ืŸ ื“ื™ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– ืื•ื™ืฃ ื“ื™ ืคืืœื’ืขื ื“ืข ื‘ืœืขื˜ืขืจ: Debian, Ubuntu, ื“ื–ืฉืขื ื˜ื•, RHEL, ืกื•ืกืข, ืคืขื“ืึธืจืึท, ื“ื–ืฉืขื ื˜ื•, ืึทืจื˜ืฉ.

ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื™ืฉื•ื–:

  • CVE-2023-32254, CVE-2023-32250, CVE-2023-32257, CVE-2023-32258 - ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื•ื•ื™ื™ึทื˜ ืงืึธื“ ืžื™ื˜ ืงืขืจืŸ ืจืขื›ื˜ ืจืขื›ื˜ ืฆื• ื“ืขืจ ืคืขืœืŸ ืคื•ืŸ ื’ืขื”ืขืจื™ืง ืึทื‘ื“ื–ืฉืขืงืฅ ืœืึทืงื™ื ื’ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืจื™ืงื•ื•ืขืก ืžื™ื˜ ื“ื™ SMB2_TREE_DISCON , SMB2_TREE_DISCON, SMB2_TREE_DISCON, SMB2_TREE_DISCON, SMBXNUMX_TREE_DISCON SMBXNUMX_CLOSE, ื•ื•ืึธืก ืจืขื–ื•ืœื˜ืึทื˜ืŸ ืื™ืŸ ืึท ืขืงืกืคึผืœื•ื™ื˜ืึทื‘ืึทืœ ืจืึทืกืข ืฆื•ืฉื˜ืึทื ื“. ื“ื™ ื‘ืึทืคืึทืœืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ.
  • CVE-2023-32256 - ืœื™ืงื™ื ื’ ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ืงืขืจืŸ ื–ื›ึผืจื•ืŸ ืžืงื•ืžื•ืช ืจืขื›ื˜ ืฆื• ืึท ืจืึทืกืข ืฆื•ืฉื˜ืึทื ื“ ื‘ืขืฉืึทืก ื“ื™ ืคึผืจืึทืกืขืกื™ื ื’ ืคื•ืŸ SMB2_QUERY_INFO ืื•ืŸ SMB2_LOGOFF ืงืึทืžืึทื ื“ื–. ื“ื™ ื‘ืึทืคืึทืœืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ.
  • CVE-2023-32252, CVE-2023-32248 - ื•ื•ื™ื™ึทื˜ ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ ืจืขื›ื˜ ืฆื• ืึท NULL ื˜ื™ื™ึทื˜ืœ ื“ืขืจืคืขืจืึทื ืก ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ื“ื™ SMB2_LOGOFF, SMB2_TREE_CONNECT ืื•ืŸ SMB2_QUERY_INFO ืงืึทืžืึทื ื“ื–. ื“ื™ ื‘ืึทืคืึทืœืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ.
  • CVE-2023-32249 - ืžืขื’ืœืขื›ืงื™ื™ื˜ ืคื•ืŸ ืกืขืกื™ืข ื›ื™ื™ื“ื–ืฉืึทืงื™ื ื’ ืžื™ื˜ ืึท ื‘ืึทื ื™ืฆืขืจ ืจืขื›ื˜ ืฆื• ืคืขืœืŸ ืคื•ืŸ ื’ืขื”ืขืจื™ืง ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ื•ื•ืขืŸ ื”ืึทื ื“ืœื™ื ื’ ืึท ืกืขืกื™ืข ืฉื™ื™ึทืŸ ืื™ืŸ ืžื•ืœื˜ื™-ืงืึทื ืึทืœ ืžืึธื“ืข.
  • CVE-2023-32247, CVE-2023-32255 - ื ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ ืจืขื›ื˜ ืฆื• ืึท ื–ื›ึผืจื•ืŸ ืจื™ื ืขืŸ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ื“ื™ SMB2_SESSION_SETUP ื‘ืึทืคึฟืขืœ. ื“ื™ ื‘ืึทืคืึทืœืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ.
  • CVE-2023-2593 ืื™ื– ืึท ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ ืจืขื›ื˜ ืฆื• ื™ื’ื–ืึธืกื˜ืฉืึทืŸ ืคื•ืŸ ื‘ื ื™ืžืฆื ื–ื›ึผืจื•ืŸ, ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืึท ื–ื›ึผืจื•ืŸ ื“ื•ืจื›ืคืึทืœ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ื ื™ื™ึท ื˜ืงืคึผ ืงืึทื ืขืงืฉืึทื ื–. ื“ื™ ื‘ืึทืคืึทืœืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ.
  • CVE-2023-32253 ื ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ ืจืขื›ื˜ ืฆื• ืึท ื“ืขื“ืœืึทืง ืึทืงืขืจื– ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ื“ื™ SMB2_SESSION_SETUP ื‘ืึทืคึฟืขืœ. ื“ื™ ื‘ืึทืคืึทืœืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ.
  • CVE-2023-32251 - ืคืขืœืŸ ืคื•ืŸ ืฉื•ืฅ ืงืขื’ืŸ ื‘ืจื•ื˜ ืงืจืึทืคื˜ ืื ืคืืœืŸ.
  • CVE-2023-32246 - ื ืœืืงืืœืขืจ ืกื™ืกื˜ืขื ื‘ืื ื™ืฆืขืจ ืžื™ื˜ืŸ ืจืขื›ื˜ ืฆื• ืืคืœืื“ืŸ ื“ืขื ksmbd ืžืื“ื•ืœ ืงืขืŸ ื“ืขืจื’ืจื™ื™ื›ืŸ ืงืขืจื ืขืœ ืงืื•ื“ ืื•ื™ืกืคื™ืจื•ื ื’. Linux.

ืื™ืŸ ืึทื“ื™ืฉืึทืŸ, 5 ืžืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ ื“ื™ ksmbd-tools ืคึผืขืงืœ, ื•ื•ืึธืก ื›ื•ืœืœ ื™ื•ื˜ื™ืœืึทื˜ื™ื– ืคึฟืึทืจ ืึธื ืคื™ืจื•ื ื’ ืื•ืŸ ืืจื‘ืขื˜ืŸ ืžื™ื˜ ksmbd, ืขืงืกืึทืงื™ื•ื˜ืึทื“ ืื™ืŸ ื‘ืึทื ื™ืฆืขืจ ืคึผืœืึทืฅ. ื“ื™ ืžืขืจืกื˜ ื’ืขืคืขืจืœืขืš ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (ZDI-CAN-17822, ZDI-CAN-17770, ZDI-CAN-17820, CVE ื ืึธืš ื ื™ืฉื˜ ืึทืกื™ื™ื ื“) ืœืึธื–ืŸ ืึท ื•ื•ื™ื™ึทื˜, ืึทื ืึธื˜ืขื ื˜ื™ืงื™ื™ื˜ื™ื“ ืึทื˜ืึทืงืขืจ ืฆื• ื•ื™ืกืคื™ืจืŸ ื–ื™ื™ืขืจ ืงืึธื“ ืžื™ื˜ ื•ื•ืึธืจืฆืœ ืจืขื›ื˜. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ื“ื™ ืคืขืœืŸ ืคื•ืŸ ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ื“ื™ ื’ืจื™ื™ืก ืคื•ืŸ ื‘ืืงื•ืžืขืŸ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ื“ืึทื˜ืŸ ืื™ื™ื“ืขืจ ืงืึทืคึผื™ื™ื ื’ ืขืก ืฆื• ื“ื™ ื‘ืึทืคืขืจ ืื™ืŸ ื“ื™ WKSSVC ืกืขืจื•ื•ื™ืก ืงืึธื“ ืื•ืŸ ืื™ืŸ ื“ื™ LSARPC_OPNUM_LOOKUP_SID2 ืื•ืŸ SAMR_OPNUM_QUERY_USER_INFO ืึธืคึผืงืึธื“ืข ื”ืึทื ื“ืœืขืจืก. ืฆื•ื•ื™ื™ ืžืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (ZDI-CAN-17823, ZDI-CAN-17821) ืงืขื ืขืŸ ืคื™ืจืŸ ืฆื• ื•ื•ื™ื™ึทื˜ ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ.

Ksmbd ื•ื•ืขืจื˜ ืคึผืจืึธืžืึธื˜ื™ืจื˜ ื•ื•ื™ ืึท ื”ื•ื™ืš-ืคึผืขืจืคืึธืจืžืึทื ืก, ืขืžื‘ืขื“ื™ื“-ื’ืจื™ื™ื˜ ืขืงืกื˜ืขื ืฉืึทืŸ ืฆื• ืกืึทืžื‘ืึท, ืื™ื ื˜ืขื’ืจื™ืจื ื“ื™ืง ืžื™ื˜ ืกืึทืžื‘ืึท ืžื›ืฉื™ืจื™ื ืื•ืŸ ืœื™ื™ื‘ืจืขืจื™ื– ื•ื•ื™ ื ื•ื™ื˜ื™ืง. ืฉื˜ื™ืฆืข ืคึฟืึทืจ ืœื•ื™ืคืŸ ืึทืŸ SMB ืกืขืจื•ื•ืขืจ ื ื™ืฆืŸ ื“ื™ ksmbd ืžืึธื“ื•ืœ ืื™ื– ืคืึธืจืฉื˜ืขืœืŸ ืื™ืŸ ื“ื™ ืกืึทืžื‘ืึท ืคึผืขืงืœ ื–ื™ื ื˜ ืžืขืœื“ื•ื ื’ 4.16.0. ื ื™ื˜ ื•ื•ื™ ืึท ื‘ืึทื ื™ืฆืขืจ-ืกืคึผื™ื™ืก SMB ืกืขืจื•ื•ืขืจ, ืื™ื– ksmbd ืžืขืจ ืขืคืขืงื˜ื™ื•ื• ืื™ืŸ ื˜ืขืจืžื™ื ืขืŸ ืคื•ืŸ ืคึผืขืจืคืึธืจืžืึทื ืก, ื–ื›ึผืจื•ืŸ ืงืึทื ืกืึทืžืฉืึทืŸ, ืื•ืŸ ืื™ื ื˜ืขื’ืจืึทืฆื™ืข ืžื™ื˜ ืึทื•ื•ืึทื ืกื™ืจื˜ืข ืงืขืจื ืขืœ ืคึฟืขื™ึดืงื™ื™ื˜ืŸ. ื“ืขืจ ksmbd ืงืึธื“ ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ื“ื•ืจืš ื ืึทืžื“ื–ืฉืึทืข ื“ื–ืฉืขืึธืŸ ืคื•ืŸ ืกืึทืžืกื•ื ื’ ืื•ืŸ ื”ื™ื•ื ื˜ืฉื•ืœ ืœื™ ืคื•ืŸ LG, ืื•ืŸ ื–ื™ื™ืŸ ืงืขืจื ืขืœ ืžื™ื™ื ื˜ื™ื™ื ืขืจ ืื™ื– ืกื˜ื™ื•ื• ืคืจืขื ื˜ืฉ ืคื•ืŸ ืžื™ื™ืงืจืึธืกืึธืคึฟื˜, ื“ืขืจ ืžื™ื™ื ื˜ื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ CIFS/SMB2/SMB3 ืกื•ื‘ืกื™ืกื˜ืขืžืขืŸ ืื™ืŸ ื“ื™ ืงืขืจื ืขืœ. Linux ืื•ืŸ ืึท ืœืึทื ื’ื™ืขืจื™ืงืขืจ ืžื™ื˜ื’ืœื™ื“ ืคื•ืŸ ื“ืขืจ ืกืึทืžื‘ืึท ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ืžืึทื ืฉืึทืคึฟื˜, ื•ื•ืึธืก ื”ืึธื˜ ื’ืขืžืึทื›ื˜ ื‘ืึทื“ื™ื™ื˜ื ื“ื™ืงืข ื‘ื™ื™ืฉื˜ื™ื™ืขืจื•ื ื’ืขืŸ ืฆื• ื“ืขืจ ืื™ืžืคึผืœืขืžืขื ื˜ืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹SMB/CIFS ืคึผืจืึธื˜ืึธืงืึธืœ ืฉื˜ื™ืฆืข ืื™ืŸ ืกืึทืžื‘ืึท ืื•ืŸ Linux.

ืึทื“ื“ื™ื˜ื™ืึธื ืึทืœืœื™, ืฆื•ื•ื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืงืขื ืขืŸ ื–ื™ื™ืŸ ื‘ืืžืขืจืงื˜ ืื™ืŸ ื“ื™ vmwgfx ื’ืจืึทืคื™ืงืก ื“ืจื™ื™ื•ื•ืขืจ, ื’ืขื ื™ืฆื˜ ืฆื• ื™ื ืกื˜ืจื•ืžืขื ื˜ 3 ื“ ืึทืงืกืขืœืขืจื™ื™ืฉืึทืŸ ืื™ืŸ VMware ื™ื ื•ื•ื™ื™ืจืึทื ืžืึทื ืฅ. ื“ืขืจ ืขืจืฉื˜ืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (ZDI-CAN-20292) ืึทืœืึทื•ื– ืึท ื”ื™ื’ืข ื‘ืึทื ื™ืฆืขืจ ืฆื• ืขืกืงืึทืœื™ื™ื˜ ื–ื™ื™ืขืจ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืื™ืŸ ื“ื™ ืกื™ืกื˜ืขื. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืจืขื›ื˜ ืฆื• ืึท ืคืขืœืŸ ืคื•ืŸ ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ื“ื™ ืฉื˜ืึทื˜ ืคื•ืŸ ืึท ื‘ืึทืคืขืจ ืื™ื™ื“ืขืจ ืคืจื™ื™ ืขืก ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืึท vmw_buffer_object, ื•ื•ืึธืก ืงืขืŸ ืจืขื–ื•ืœื˜ืึทื˜ ืื™ืŸ ืึท ื˜ืึธืคึผืœ ืจื•ืคืŸ ืฆื• ื“ื™ ืคืจื™ื™ ืคื•ื ืงืฆื™ืข. ื“ื™ ืจื’ืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (ZDI-CAN-20110) ืคื™ืจื˜ ืฆื• ืึท ืจื™ื ืขืŸ ืคื•ืŸ ืงืขืจืŸ ื–ื›ึผืจื•ืŸ ืื™ื ื”ืึทืœื˜ ืจืขื›ื˜ ืฆื• ืขืจืจืึธืจืก ืื™ืŸ ืึธืจื’ืึทื ื™ื™ื–ื™ื ื’ ื“ื™ ืœืึทืงื™ื ื’ ืคื•ืŸ ื™ื™ื“ืœืฉื˜ื™ื™ืŸ ืึทื‘ื“ื–ืฉืขืงืฅ.

ืžืงื•ืจ: opennet.ru

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster