ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ OpenSSL, Glibc, util-linux, i915 ืื•ืŸ vmwgfx ื“ืจื™ื•ื•ืขืจืก

ื ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื“ื™ืกืงืœืึธื•ื–ื“ (CVE-2021-4160) ืื™ืŸ ื“ื™ OpenSSL ืงืจื™ืคึผื˜ืึธื’ืจืึทืคื™ืง ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืจืขื›ื˜ ืฆื• ืึท ื˜ืขื•ืช ืื™ืŸ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ืึทื“ืขืจ ืื™ืŸ ื“ื™ BN_mod_exp ืคื•ื ืงืฆื™ืข, ืจื™ื–ืึทืœื˜ื™ื ื’ ืื™ืŸ ื“ื™ ืฆื•ืจื™ืงืงื•ืžืขืŸ ืคื•ืŸ ืึท ืคืึทืœืฉ ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ื“ื™ ืกืงื•ื•ืขืจื™ื ื’ ืึธืคึผืขืจืึทืฆื™ืข. ื“ื™ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึทืงืขืจื– ื‘ืœื•ื™ื– ืื•ื™ืฃ ื™ื™ึทื–ื ื•ื•ืึทืจื’ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ MIPS32 ืื•ืŸ MIPS64 ืึทืจืงืึทื˜ืขืงื˜ืฉืขืจื–, ืื•ืŸ ืงืขื ืขืŸ ืคื™ืจืŸ ืฆื• ืงืึธืžืคึผืจืึธืžื™ืก ืคื•ืŸ ื™ืœื™ืคึผื˜ื™ืง ื•ื™ืกื‘ื™ื™ื’ ืึทืœื’ืขืจื™ื“ืึทืžื–, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ื“ื™ ื’ืขื ื™ืฆื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ ืื™ืŸ TLS 1.3. ื“ื™ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืื™ื– ื’ืขื•ื•ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื“ื™ ื“ืขืฆืขืžื‘ืขืจ OpenSSL 1.1.1m ืื•ืŸ 3.0.1 ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ.

ืขืก ืื™ื– ื‘ืืžืขืจืงื˜ ืึทื– ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ืคืึทืงื˜ื™ืฉ ืื ืคืืœืŸ ืฆื• ื‘ืึทืงื•ืžืขืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืคึผืจื™ื•ื•ืึทื˜ ืฉืœื™ืกืœืขืŸ ื ื™ืฆืŸ ื“ื™ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืคึผืจืึธื‘ืœืขื ืื™ื– ืงืึทื ืกื™ื“ืขืจื“ ืคึฟืึทืจ RSA, DSA ืื•ืŸ ื“ื™ Diffie-Hellman ืึทืœื’ืขืจื™ื“ืึทื (DH, Diffie-Hellman) ื•ื•ื™ ืžืขื’ืœืขืš, ืึธื‘ืขืจ ืึทื ืœื™ื™ืงืœื™, ืฆื• ืงืึธืžืคึผืœื™ืฆื™ืจื˜ ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ืื•ืŸ ืจื™ืงื•ื•ื™ื™ืจื™ื ื’ ืจื™ื–ื™ืง ืงืึทืžืคึผื™ื•ื˜ื™ื ื’ ืจืขืกื•ืจืกืŸ. ืื™ืŸ ื“ืขื ืคืึทืœ, ืึท ื‘ืึทืคืึทืœืŸ ืื•ื™ืฃ TLS ืื™ื– ื™ืงืกืงืœื•ื“ื™ื“, ื•ื•ื™ื™ึทืœ ืื™ืŸ 2016, ื•ื•ืขืŸ ื™ืœื™ืžืึทื ื™ื™ื˜ื™ื ื’ ื“ื™ CVE-2016-0701 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, ื™ื™ึทื ื˜ื™ื™ืœื•ื ื’ ืคื•ืŸ ืื™ื™ืŸ DH ืคึผืจื™ื•ื•ืึทื˜ ืฉืœื™ืกืœ ืฆื•ื•ื™ืฉืŸ ืงืœื™ื™ืึทื ืฅ ืื™ื– ื’ืขื•ื•ืขืŸ ืคึผืจืึธื•ื›ื™ื‘ืึทื˜ืึทื“.

ืื™ืŸ ื“ืขืจืฆื•, ืขื˜ืœืขื›ืข ืœืขืฆื˜ื ืก ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ืึธืคึฟืŸ ืžืงื•ืจ ืคึผืจืึทื“ื–ืฉืขืงืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื‘ืืžืขืจืงื˜:

  • ืงื™ื™ืคืœ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (CVE-2022-0330) ืื™ืŸ ื“ื™ i915 ื’ืจืึทืคื™ืงืก ืฉืึธืคืขืจ ืจืขื›ื˜ ืฆื• ืึท ืคืขืœืŸ ืคื•ืŸ GPU TLB ื‘ืึทืฉื˜ืขื˜ื™ืง. ืื•ื™ื‘ IOMMU (ืึทื“ืจืขืก ืื™ื‘ืขืจื–ืขืฆื•ื ื’) ืื™ื– ื ื™ืฉื˜ ื’ืขื ื™ืฆื˜, ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืึทืœืึทื•ื– ืึทืงืกืขืก ืฆื• ื˜ืจืึทืค ื–ื™ืงืึธืจืŸ ื‘ืœืขื˜ืขืจ ืคึฟื•ืŸ ื‘ืึทื ื™ืฆืขืจ ืคึผืœืึทืฅ. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืงืขื ืขืŸ ื•ื•ืขืจืŸ ื’ืขื ื•ืฆื˜ ืฆื• ืคืึทืจื“ืึธืจื‘ืŸ ืึธื“ืขืจ ืœื™ื™ืขื ืขืŸ ื“ืึทื˜ืŸ ืคื•ืŸ ื˜ืจืึทืค - ื–ื™ืงืึธืจืŸ ื’ืขื‘ื™ื˜ืŸ. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืึทืงืขืจื– ืื•ื™ืฃ ืึทืœืข ื™ื ืึทื’ืจื™ื™ื˜ื™ื“ ืื•ืŸ ื“ื™ืกืงืจืขื˜ืข ื™ื ื˜ืขืœ ื’ืคึผื•ืก. ื“ื™ ืคืึทืจืจื™ื›ื˜ืŸ ืื™ื– ื™ืžืคึผืœืึทืžืขื ืึทื“ ื“ื•ืจืš ืึทื“ื™ื ื’ ืึท ืžืึทื ื“ืึทื˜ืึธืจื™ TLB ื’ืœื™ื™ึทืš ืื™ื™ื“ืขืจ ืคึผืขืจืคืึธืจืžื™ื ื’ ื™ืขื“ืขืจ ื’ืคึผื• ื‘ืึทืคืขืจ ืฆื•ืจื™ืงืงื•ืžืขืŸ ืึธืคึผืขืจืึทืฆื™ืข ืฆื• ื“ื™ ืกื™ืกื˜ืขื, ื•ื•ืึธืก ื•ื•ืขื˜ ืคื™ืจืŸ ืฆื• ืจื™ื“ื•ืกื˜ ืคืึธืจืฉื˜ืขืœื•ื ื’. ื“ื™ ืคืึธืจืฉื˜ืขืœื•ื ื’ ืคึผืจืึทืœ ื“ืขืคึผืขื ื“ืก ืื•ื™ืฃ ื“ื™ ื’ืคึผื•, ื“ื™ ืึทืคึผืขืจื™ื™ืฉืึทื ื– ื’ืขื˜ืืŸ ืื•ื™ืฃ ื“ื™ ื’ืคึผื• ืื•ืŸ ื“ื™ ืกื™ืกื˜ืขื ืžืึทืกืข. ื“ืขืจ ืคืึทืจืจื™ื›ื˜ืŸ ืื™ื– ื“ืขืจื•ื•ื™ื™ึทืœ ื‘ืœื•ื™ื– ื‘ื ื™ืžืฆื ื•ื•ื™ ืึท ืœืึทื˜ืข.
  • ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2022-22942) ืื™ืŸ ื“ื™ vmwgfx ื’ืจืึทืคื™ืงืก ื“ืจื™ื™ื•ื•ืขืจ, ื’ืขื ื™ืฆื˜ ืฆื• ื™ื ืกื˜ืจื•ืžืขื ื˜ 3 ื“ ืึทืงืกืขืœืขืจื™ื™ืฉืึทืŸ ืื™ืŸ VMware ื™ื ื•ื•ื™ื™ืจืึทื ืžืึทื ืฅ. ื“ืขืจ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึทืœืึทื•ื– ืึท ืึทื ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉื“ ื‘ืึทื ื™ืฆืขืจ ืฆื• ืึทืงืกืขืก ื˜ืขืงืขืก ื’ืขืขืคื ื˜ ื“ื•ืจืš ืื ื“ืขืจืข ืคึผืจืึทืกืขืกืึทื– ืื•ื™ืฃ ื“ื™ ืกื™ืกื˜ืขื. ื“ื™ ื‘ืึทืคืึทืœืŸ ืจื™ืงื•ื•ื™ื™ืขืจื– ืึทืงืกืขืก ืฆื• ื“ื™ ืžื™ื˜ืœ /dev/dri/card0 ืึธื“ืขืจ /dev/dri/rendererD128, ื•ื•ื™ ืื•ื™ืš ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึท ioctl() ืจื•ืคืŸ ืžื™ื˜ ื“ื™ ืจื™ื–ืึทืœื˜ื™ื ื’ ื˜ืขืงืข ื“ื™ืกืงืจื™ืคึผื˜ืึธืจ.
  • ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (CVE-2021-3996, CVE-2021-3995) ืื™ืŸ ื“ื™ ืœื™ื‘ืžืึธื•ื ื˜ ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืฆื•ื’ืขืฉื˜ืขืœื˜ ืื™ืŸ ื“ื™ util-linux ืคึผืขืงืœ ืœืึธื–ืŸ ืึทืŸ ืึทื ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื“ ื‘ืึทื ื™ืฆืขืจ ืฆื• ืึทื ืžืึธื•ื ื˜ ื“ื™ืกืง ืคึผืึทืจื˜ื™ืฉืึทื ื– ืึธืŸ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืฆื• ื˜ืึธืŸ ื“ืึธืก. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขื•ื•ืขืŸ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื‘ืขืฉืึทืก ืึท ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืคื•ืŸ ื“ื™ SUID ื•ื•ืึธืจืฆืœ ืžื’ื™ืœื” ื•ืžืึธื•ื ื˜ ืื•ืŸ ืคื•ืกืขืจืžืึธื•ื ื˜.
  • ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ื™ ืกื˜ืึทื ื“ืึทืจื˜ C ื‘ื™ื‘ืœื™ืึธื˜ืขืง Glibc ื•ื•ืึธืก ืึทืคืขืงืฅ ื“ื™ ืคืึทืงื˜ื™ืฉ ืคึผืึทื˜ (CVE-2021-3998) ืื•ืŸ getcwd (CVE-2021-3999) ืคืึทื ื’ืงืฉืึทื ื–.
    • ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ืŸ realpath () ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืฆื•ืจื™ืงืงื•ืžืขืŸ ืึท ืคืึทืœืฉ ื•ื•ืขืจื˜ ืื•ื ื˜ืขืจ ื–ื™ื›ืขืจ ื˜ื ืึธื™ื, ืžื™ื˜ ืึทื ืจื™ื–ืึทืœื•ื•ื“ ืจื™ื–ื™ื“ื–ืฉื•ืึทืœ ื“ืึทื˜ืŸ ืคื•ืŸ ื“ืขื ืึธื ืœื™ื™ื’ืŸ. ืคึฟืึทืจ ื“ื™ SUID-root fusermount ืคึผืจืึธื’ืจืึทื, ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขื ืขืŸ ื•ื•ืขืจืŸ ื’ืขื ื•ืฆื˜ ืฆื• ื‘ืึทืงื•ืžืขืŸ ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ืคึผืจืึธืฆืขืก ื–ื›ึผืจื•ืŸ, ืœืžืฉืœ, ืฆื• ื‘ืึทืงื•ืžืขืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืคึผื•ื™ื ื˜ืขืจื–.
    • ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ืŸ getcwd () ืึทืœืึทื•ื– ืึท ืื™ื™ืŸ-ื‘ื™ื˜ืข ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื•. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืึท ื–ืฉื•ืง ื•ื•ืึธืก ืื™ื– ื’ืขื•ื•ืขืŸ ืคืึธืจืฉื˜ืขืœืŸ ื–ื™ื ื˜ 1995. ืฆื• ืคืึทืจืฉืึทืคืŸ ืึท ืึธื•ื•ื•ืขืจืคืœืึธื•, ืคืฉื•ื˜ ืจื•ืคืŸ chdir () ืื™ืŸ ื“ื™ "/" ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืื™ืŸ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืึธื ืงืœืึทืคึผืŸ ืคื•ื ื˜ ื ืึธืžืขืŸ. ืขืก ืื™ื– ืงื™ื™ืŸ ื•ื•ืึธืจื˜ ืื•ื™ืฃ ืฆื™ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืœื™ืžื™ื˜ืขื“ ืฆื• ืคึผืจืึธืฆืขืก ืงืจืึทืฉื™ื–, ืึธื‘ืขืจ ืขืก ื–ืขื ืขืŸ ื’ืขื•ื•ืขืŸ ืงืึทืกืขืก ืคื•ืŸ ืืจื‘ืขื˜ืŸ ืขืงืกืคึผืœื•ื™ืฅ ื‘ืืฉืืคืŸ ืคึฟืึทืจ ืขื ืœืขืš ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ืขืจ ืคืึทืจื’ืึทื ื’ืขื ื”ื™ื™ื˜, ื˜ืจืึธืฅ ื“ืขื•ื•ืขืœืึธืคึผืขืจ ืกืงืขืคึผื˜ื™ืกื™ื–ืึทื.
  • ื ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2022-23220) ืื™ืŸ ื“ื™ usbview ืคึผืขืงืœ ืึทืœืึทื•ื– ื”ื™ื’ืข ื™ื•ื–ืขืจื– ืœืึธื’ื“ ืื™ืŸ ื“ื•ืจืš SSH ืฆื• ื•ื™ืกืคื™ืจืŸ ืงืึธื“ ื•ื•ื™ ื•ื•ืึธืจืฆืœ ืจืขื›ื˜ ืฆื• ืึท ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ืŸ ื“ื™ PolKit ื›ึผืœืœื™ื (allow_any = ื™ืึธ) ืคึฟืึทืจ ืคืœื™ืกื ื“ื™ืง ื“ื™ usbview ื ื•ืฆืŸ ื•ื•ื™ ื•ื•ืึธืจืฆืœ ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ. ืึธืคึผืขืจืึทืฆื™ืข ืงื•ืžื˜ ืึทืจืึธืคึผ ืฆื• ื ื™ืฆืŸ ื“ื™ "--gtk-ืžืึธื“ื•ืœืข" ืึธืคึผืฆื™ืข ืฆื• ืœืึธื“ืŸ ื“ื™ื™ืŸ ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืื™ืŸ usbview. ื“ื™ ืคึผืจืึธื‘ืœืขื ืื™ื– ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ usbview 2.2.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’