ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ swhkd, ืึท ื“ื•ืจื›ื•ื•ืขื’ ืคืึทืจื•ื•ืึทืœื˜ืขืจ ืคึฟืึทืจ Wayland

ื ืกืขืจื™ืข ืคื•ืŸ โ€‹โ€‹ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ swhkd (Simple Wayland HotKey Daemon) ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืคืึทืœืฉ ืึทืจื‘ืขื˜ ืžื™ื˜ ืฆื™ื™ึทื˜ื•ื•ื™ื™ึทืœื™ืง ื˜ืขืงืขืก, ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื” ืคึผืึทืจืึทืžืขื˜ืขืจืก ืื•ืŸ ื™ื•ื ื™ืงืก ืกืึทืงืึทืฅ. ื“ืขืจ ืคึผืจืึธื’ืจืึทื ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ ืจื•ืกื˜ ืื•ืŸ ื›ืึทื ื“ืึทืœื– ื”ืึธื˜ืงื™ื™ ื“ืจื™ื ื’ืœืขืš ืื™ืŸ ื™ื ื•ื•ื™ื™ืจืึทื ืžืึทื ืฅ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ Wayland ืคึผืจืึธื˜ืึธืงืึธืœ (ืึท ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ-ื˜ืขืงืข-ืงืึทืžืคึผืึทื˜ืึทื‘ืึทืœ ืึทื ืึทืœืึธื’ ืคื•ืŸ ื“ื™ sxhkd ืคึผืจืึธืฆืขืก ื’ืขื ื™ืฆื˜ ืื™ืŸ X11-ื‘ืื–ื™ืจื˜ ื™ื ื•ื•ื™ื™ืจืึทื ืžืึทื ืฅ).

ื“ืขืจ ืคึผืขืงืœ ื™ื ืงืœื•ื“ื– ืึทืŸ ืึทื ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉื“ ืกื•ื•ืงื– ืคึผืจืึธืฆืขืก ื•ื•ืึธืก ืคึผืขืจืคืึธืจืžื– ื”ืึธื˜ืงื™ื™ ืึทืงืฉืึทื ื–, ืื•ืŸ ืึท ื”ื™ื ื˜ืขืจื’ืจื•ื ื˜ ืกื•ื•ื”ืงื“ ืคึผืจืึธืฆืขืก ื•ื•ืึธืก ืœื•ื™ืคื˜ ื•ื•ื™ ื•ื•ืึธืจืฆืœ ืื•ืŸ ื™ื ื˜ืขืจืึทืงืฅ ืžื™ื˜ ืึทืจื™ื™ึทื ืฉืจื™ื™ึทื‘ ื“ืขื•ื•ื™ืกืขืก ืื•ื™ืฃ ื“ื™ ื•ื™ื ืคึผื•ื˜ ืึทืคึผื™ ืžื“ืจื’ื”. ื ื™ื•ื ื™ืงืก ื›ืึธืœืขืœ ืื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ืึธืจื’ืึทื ื™ื–ื™ืจืŸ ื“ื™ ื™ื ื˜ืขืจืึทืงืฉืึทืŸ ืฆื•ื•ื™ืฉืŸ swhks ืื•ืŸ swhkd. ื ื™ืฆืŸ Polkit ื›ึผืœืœื™ื, ืงื™ื™ืŸ ื”ื™ื’ืข ื‘ืึทื ื™ืฆืขืจ ืงืขื ืขืŸ ืœื•ื™ืคืŸ ื“ื™ /usr/bin/swhkd ืคึผืจืึธืฆืขืก ื•ื•ื™ ื•ื•ืึธืจืฆืœ ืื•ืŸ ืคืึธืจืŸ ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ืคึผืึทืจืึทืžืขื˜ืขืจืก ืฆื• ืขืก.

ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–:

  • CVE-2022-27815 - ืฉืคึผืึธืจืŸ ืึท ืคึผืจืึธืฆืขืก PID ืฆื• ืึท ื˜ืขืงืข ืžื™ื˜ ืึท ืคึผืจื™ื“ื™ืงื˜ืึทื‘ืึทืœ ื ืึธืžืขืŸ ืื•ืŸ ืื™ืŸ ืึท ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ื•ื•ืึธืก ืื™ื– ืจื™ื™ื˜ืึทื‘ืึทืœ ื“ื•ืจืš ืื ื“ืขืจืข ื™ื•ื–ืขืจื– (/tmp/swhkd.pid). ื™ืขื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืงืขื ืขืŸ ืžืึทื›ืŸ ืึท ื˜ืขืงืข /tmp/swhkd.pid ืื•ืŸ ืฉื˜ืขืœืŸ ื“ื™ ืคึผื™ื“ ืคื•ืŸ ืึท ื™ื’ื–ื™ืกื˜ื™ื ื’ ืคึผืจืึธืฆืขืก ืื™ืŸ ืขืก, ื•ื•ืึธืก ื•ื•ืขื˜ ืžืึทื›ืŸ swhkd ื ื™ืฉื˜ ืงืขื ืขืŸ ืฆื• ืึธื ื”ื™ื™ื‘ืŸ. ืื•ื™ื‘ ืขืก ืื™ื– ืงื™ื™ืŸ ืฉื•ืฅ ืงืขื’ืŸ ืฉืืคืŸ ืกื™ืžื‘ืึธืœื™ืฉ ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ืขืŸ ืื™ืŸ / tmp, ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขื ืขืŸ ื•ื•ืขืจืŸ ื’ืขื ื•ืฆื˜ ืฆื• ืฉืึทืคึฟืŸ ืึธื“ืขืจ ืึธื•ื•ื•ืขืจืจื™ื™ื˜ ื˜ืขืงืขืก ืื™ืŸ ืงื™ื™ืŸ ืกื™ืกื˜ืขื ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ (ื“ื™ PID ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ืฆื• ื“ืขืจ ื˜ืขืงืข) ืึธื“ืขืจ ื‘ืึทืฉื˜ื™ืžืขืŸ ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ืงื™ื™ืŸ ื˜ืขืงืข ืื•ื™ืฃ ื“ื™ ืกื™ืกื˜ืขื (swhkd ืคึผืจื™ื ืฅ ื“ื™ ื˜ืขืงืข) ื’ืึทื ืฅ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ื“ื™ PID ื˜ืขืงืข ืฆื• ืกื˜ื“ืึธื•ื˜). ืขืก ืื™ื– ื ืึธื•ื˜ื•ื•ืขืจื“ื™ ืึทื– ืื™ืŸ ื“ื™ ืจืขืœืขืึทืกืขื“ ืคืึทืจืจื™ื›ื˜ืŸ ื“ื™ PID ื˜ืขืงืข ืื™ื– ืืจื™ื‘ืขืจื’ืขืคืืจืŸ ื ื™ืฉื˜ ืฆื• ื“ื™ /run ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ, ืึธื‘ืขืจ ืฆื• ื“ื™ /etc ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ (/etc/swhkd/runtime/swhkd_{uid}.pid), ื•ื•ื• ืขืก ืื•ื™ืš ื’ืขื”ืขืจื˜ ื ื™ืฉื˜.
  • CVE-2022-27814 - ื“ื•ืจืš ืžืึทื ื™ืคึผื™ืึทืœื™ื™ื˜ื™ื ื’ ื“ื™ "-C" ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื” ืึธืคึผืฆื™ืข ื’ืขื ื™ืฆื˜ ืฆื• ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืึท ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข, ืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ื‘ืึทืฉื˜ื™ืžืขืŸ ื“ื™ ืขืงื–ื™ืกื˜ืขื ืฅ ืคื•ืŸ ืงื™ื™ืŸ ื˜ืขืงืข ืื•ื™ืฃ ื“ื™ ืกื™ืกื˜ืขื. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ /root/.somefile ืื™ืจ ืงืขื ืขืŸ ืœื•ื™ืคืŸ "pkexec /usr/bin/swhkd -d -c /root/.somefile" ืื•ืŸ ืื•ื™ื‘ ื“ื™ ื˜ืขืงืข ืื™ื– ืคืขืœื ื“ื™ืง, ื“ืขืจ ื˜ืขื•ืช "/root/.somefile ืงืขืŸ ื ื™ืฉื˜ ืขืงืกื™ืกื˜ื™ืจืŸ. " ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื–ืŸ. ื•ื•ื™ ืื™ืŸ ื“ืขื ืคืึทืœ ืคื•ืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, ืคื™ืงืกื™ืจ ื“ื™ ืคึผืจืึธื‘ืœืขื ืื™ื– ืคึผืึทื–ืœื™ื ื’ - ืคื™ืงืกื™ืจ ื“ื™ ืคึผืจืึธื‘ืœืขื ื‘ื•ื™ืœื– ืึทืจืึธืคึผ ืฆื• ื“ืขื ืคืึทืงื˜ ืึทื– ื“ื™ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ื ื•ืฆืŸ "ืงืึทืฅ" ('Command::new(โ€œ/bin/catโ€)).arg(path) ืื™ื– ืื™ืฆื˜ ืœืึธื ื˜ืฉื˜ ืฆื• ืœื™ื™ืขื ืขืŸ ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข. output ()').
  • CVE-2022-27819 - ื“ื™ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืื™ื– ืื•ื™ืš ืฉื™ื™ึทื›ื•ืช ืฆื• ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ื“ื™ "-c" ืึธืคึผืฆื™ืข, ื•ื•ืึธืก ื– ื“ื™ ื’ืื ืฆืข ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข ืฆื• ื–ื™ื™ืŸ ืœืึธื•ื“ื™ื“ ืื•ืŸ ืคึผืึทืจืกืขื“ ืึธืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ื’ืจื™ื™ืก ืื•ืŸ ื˜ื™ืคึผ ืคื•ืŸ ื“ืขืจ ื˜ืขืงืข. ืฆื•ื ื‘ื™ื™ืฉืคึผื™ืœ, ืฆื• ืคืึทืจืฉืึทืคืŸ ืึท ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ ื“ื•ืจืš ืคืœื™ืกื ื“ื™ืง ืื•ื™ืก ืคื•ืŸ ืคืจื™ื™ ื–ื›ึผืจื•ืŸ ืื•ืŸ ืงืจื™ื™ื™ื˜ื™ื ื’ ืคืึทืœืฉ I/O, ืื™ืจ ืงืขื ืขืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืึท ื‘ืœืึธืง ืžื™ื˜ืœ ื‘ื™ื™ ืกื˜ืึทืจื˜ืึทืคึผ ("pkexec /usr/bin/swhkd -d -c /dev/sda") ืึธื“ืขืจ ืึท ื›ืึทืจืึทืงื˜ืขืจ ืžื™ื˜ืœ ื•ื•ืึธืก ื˜ืจืื’ื˜ ืึท ื™ื ืคืึทื ืึทื˜ ื˜ื™ื™ึทืš ืคื•ืŸ ื“ืึทื˜ืŸ. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ืกืึทืœื•ื•ื“ ื“ื•ืจืš ื‘ืึทืฉื˜ืขื˜ื™ืง ื“ื™ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืื™ื™ื“ืขืจ ืขืคืŸ ื“ื™ ื˜ืขืงืข, ืึธื‘ืขืจ ื“ื™ ืคืึทืจืจื™ื›ื˜ืŸ ืื™ื– ื ื™ืฉื˜ ื’ืึทื ืฅ, ื•ื•ื™ื™ึทืœ ื‘ืœื•ื™ื– ื“ื™ ื‘ืึทื ื™ืฆืขืจ ืฉื™ื™ึทืŸ (UID) ืื™ื– ื‘ืึทืฉื˜ืขื˜ื™ืง, ืึธื‘ืขืจ ื“ื™ ื’ืจื•ืคึผืข ืฉื™ื™ึทืŸ (GID) ื‘ืœื™ื™ื‘ื˜ ื“ื™ ื–ืขืœื‘ืข.
  • CVE-2022-27818 - ื ื™ื•ื ื™ืงืก ื›ืึธืœืขืœ ืื™ื– ื‘ืืฉืืคืŸ ืžื™ื˜ ื“ื™ / tmp/swhkd.sock ื˜ืขืงืข ื‘ืืฉืืคืŸ ืื™ืŸ ืึท ืจื™ื™ื˜ืึทื‘ืึทืœ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ, ื•ื•ืึธืก ืคื™ืจื˜ ืฆื• ืขื ืœืขืš ื™ืฉื•ื– ื•ื•ื™ ื“ืขืจ ืขืจืฉื˜ืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (ื™ืขื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืงืขื ืขืŸ ืฉืึทืคึฟืŸ / tmp/swhkd.sock ืื•ืŸ ื“ื–ืฉืขื ืขืจื™ื™ื˜ ืึธื“ืขืจ ื™ื ื˜ืขืจืกืขืคึผื˜ ืงื™ื™ืคึผืจืขืกืก ื’ืขืฉืขืขื ื™ืฉืŸ).
  • CVE-2022-27817 - ืึทืจื™ื™ึทื ืฉืจื™ื™ึทื‘ ื’ืขืฉืขืขื ื™ืฉืŸ ื–ืขื ืขืŸ ืื ื’ืขื ื•ืžืขืŸ ืคื•ืŸ ืึทืœืข ื“ืขื•ื•ื™ืกืขืก ืื•ืŸ ืื™ืŸ ืึทืœืข ืกืขืฉืึทื ื–, ื“.ื”. ืึท ื‘ืึทื ื™ืฆืขืจ ืคื•ืŸ ืืŸ ืื ื“ืขืจ Wayland ืกืขืกื™ืข ืึธื“ืขืจ ืคึฟื•ืŸ ื“ื™ ืงืึทื ืกืึธื•ืœ ืงืขื ืขืŸ ื™ื ื˜ืขืจืกืขืคึผื˜ ื’ืขืฉืขืขื ื™ืฉืŸ ื•ื•ืขืŸ ื”ืึธื˜ืงื™ื™ืก ื–ืขื ืขืŸ ื’ืขื“ืจื™ืงื˜ ื“ื•ืจืš ืื ื“ืขืจืข ื™ื•ื–ืขืจื–.
  • CVE-2022-27816 ื“ืขืจ swhks ืคึผืจืึธืฆืขืก, ื•ื•ื™ swhkd, ื ื™ืฆื˜ ื“ื™ PID ื˜ืขืงืข /tmp/swhks.pid ืื™ืŸ ื“ื™ ืจื™ื™ื˜ืึทื‘ืึทืœ / tmp ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ืขื ืœืขืš ืฆื• ื“ืขืจ ืขืจืฉื˜ืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, ืึธื‘ืขืจ ืื™ื– ื ื™ืฉื˜ ื•ื•ื™ ื’ืขืคืขืจืœืขืš ื•ื•ื™ื™ึทืœ swhks ืื™ื– ืคืœื™ืกื ื“ื™ืง ืื•ื ื˜ืขืจ ืึท ืึทื ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉื“ ื‘ืึทื ื™ืฆืขืจ.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’