ืงืขืจื ืขืœ ืฉื•ื•ืึทื›ืงื™ื™ื˜ืŸ Linux, ื•ื•ืึธืก ืึทืคืขืงื˜ื™ืจื˜ ksmbd, ktls, uio ืื•ืŸ ื“ืขื ื ืขื˜ื•ื•ืึธืจืง ืกื˜ืึทืง

ืื™ืŸ ื“ืขื ksmbd ืžืึธื“ื•ืœ, ื•ื•ืึธืก ืึธืคืคืขืจื˜ ืึทืŸ ืื™ื™ื ื’ืขื‘ื•ื™ื˜ืŸ ืงืขืจื ืขืœ Linux ืฆื•ื•ื™ื™ ืฉื•ื•ืึทื›ืงื™ื™ื˜ืŸ ื–ืขื ืขืŸ ืื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจื˜ ื’ืขื•ื•ืึธืจืŸ ืื™ืŸ ื“ืขืจ SMB-ื‘ืึทื–ื™ืจื˜ืขืจ ื˜ืขืงืข ืกืขืจื•ื•ืขืจ ืื™ืžืคึผืœืขืžืขื ื˜ืึทืฆื™ืข. ื“ื™ ืฉื•ื•ืึทื›ืงื™ื™ื˜ืŸ ืœืึธื–ืŸ ื•ื•ื™ื™ื˜ืข, ื ื™ืฉื˜-ืื•ื™ื˜ืขื ื˜ื™ืคึฟื™ืฆื™ืจื˜ืข ืึทื˜ืึทืงื™ืจืขืจ ืื•ื™ืกืคึฟื™ืจืŸ ืงืขืจื ืขืœ-ืœืขื•ื•ืขืœ ืงืึธื“ ืึธื“ืขืจ ื‘ืึทืฉื˜ื™ืžืขืŸ ืงืขืจื ืขืœ ื–ื›ึผืจื•ืŸ ืื™ื ื”ืึทืœื˜ ืื•ื™ืฃ ืกื™ืกื˜ืขืžืขืŸ ืžื™ื˜ืŸ ksmbd ืžืึธื“ื•ืœ ืขื ื™ื™ื‘ืึทืœื“. ื“ื™ ืคึผืจืึธื‘ืœืขืžืขืŸ ื–ืขื ืขืŸ ืฉื•ื™ืŸ ื“ืึธ ื–ื™ื ื˜ ืงืขืจื ืขืœ 5.15, ื•ื•ืึธืก ื”ืึธื˜ ืึทืจื™ื™ึทื ื’ืขื ื•ืžืขืŸ ื“ืขื ksmbd ืžืึธื“ื•ืœ. ื“ื™ ืฉื•ื•ืึทื›ืงื™ื™ื˜ืŸ ื–ืขื ืขืŸ ื’ืขืคื™ืงืกื˜ ื’ืขื•ื•ืึธืจืŸ ืื™ืŸ ืงืขืจื ืขืœ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ 6.7.2, 6.6.14, 6.1.75, ืื•ืŸ 5.15.145. ืื™ืจ ืงืขื ื˜ ืคึฟืึทืจืคึฟืึธืœื’ืŸ ื“ื™ ืคึผืึทื˜ืฉืึทื– ืื™ืŸ ื“ื™ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– ืื•ื™ืฃ ื“ื™ ืคึฟืึธืœื’ื ื“ื™ืงืข ื‘ืœืขื˜ืขืจ: Debian, Ubuntu, ื“ื–ืฉืขื ื˜ื•, RHEL, ืกื•ืกืข, ืคืขื“ืึธืจืึท, ืึทืจื˜ืฉ.

ื“ื™ ืขืจืฉื˜ืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2024-26592) ืงืขืŸ ืคื™ืจืŸ ืฆื• ืื˜ืืงื™ืจืขืจ ืงืื•ื“ ืื•ื™ืกืคื™ืจื•ื ื’ ืžื™ื˜ ืงืขืจื ืขืœ ืคืจื™ื•ื•ื™ืœืขื’ื™ืขืก ื•ื•ืขืŸ ื–ื™ื™ ืฉื™ืงืŸ ืกืคืขืฆื™ืขืœ ื’ืขืžืื›ื˜ืข ื ื™ืฉื˜-ืื•ื™ื˜ืขื ื˜ื™ืคื™ืฆื™ืจื˜ืข TCP ืคืืจืœืื ื’ืขืŸ ืฆื• ืกืขืจื•ื•ืขืจ ksmbd. ื“ื™ ืฉื•ื•ืื›ืงื™ื™ื˜ ื•ื•ืขืจื˜ ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืื•ืžืจื™ื›ื˜ื™ืงืข ืื‘ื™ืขืงื˜-ืฉืœืืกื•ื ื’ ืื™ืŸ ื“ืขื ืงืื“ ื•ื•ืืก ืื™ื ืกื˜ืืœื™ืจื˜ ืื•ืŸ ืขื ื“ื™ืงื˜ ื“ื™ TCP ืคืืจื‘ื™ื ื“ื•ื ื’ ืฆื• ksmbd, ืื•ืŸ ื“ืืก ืขืจืžืขื’ืœื™ื›ื˜ ื“ื™ ืฉืึทืคื•ื ื’ ืคื•ืŸ ื‘ืื“ื™ื ื’ื•ื ื’ืขืŸ ืคืืจ ืฆื•ื˜ืจื™ื˜ ืฆื• ืฉื•ื™ืŸ-ื‘ืืคืจื™ื™ื˜ืข ื–ื›ึผืจื•ืŸ (ื ื™ืฆืŸ-ื ืืš-ื‘ืืคืจื™ื™ื˜).

ื“ื™ ืฆื•ื•ื™ื™ื˜ืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2024-26594) ืคื™ืจื˜ ืฆื• ืึท ืงืขืจืŸ ื–ื›ึผืจื•ืŸ ืจื™ื ืขืŸ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืึท ืคืึทืœืฉ ืžืขืง ื˜ืึธืงืขืŸ ืื™ืŸ ืึท ืกืขืกื™ืข ืกืขื˜ืึทืคึผ ื‘ืขื˜ืŸ ื’ืขืฉื™ืงื˜ ื“ื•ืจืš ืึท ืงืœื™ืขื ื˜. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืคืึทืœืฉ ืคึผืจืึทืกืขืกื™ื ื’ ืคื•ืŸ ื“ืึทื˜ืŸ ืžื™ื˜ ื“ื™ SMB2 Mech ื˜ืึธืงืขืŸ ืื•ืŸ ืคื™ืจื˜ ืฆื• ืœื™ื™ืขื ืขืŸ ื“ืึทื˜ืŸ ืคึฟื•ืŸ ืึท ื’ืขื’ื ื˜ ืึทืจื•ื™ืก ื“ื™ ืึทืœืึทืงื™ื™ื˜ื™ื“ ื‘ืึทืคืขืจ.

ื“ืขืจืฆื•, ืงืขืŸ ืžืขืŸ ื‘ืึทืžืขืจืงืŸ ืขื˜ืœืขื›ืข ืžืขืจ ืฉื•ื•ืึทื›ืงื™ื™ื˜ืŸ ืื™ืŸ ื“ื™ ืงืขืจื ืขืœ. Linux:

  • CVE-2023-52439 - ื ื ื•ืฆืŸ-ื ืึธืš-ืคืจื™ื™ ื–ื›ึผืจื•ืŸ ืึทืงืกืขืก ืื™ืŸ ื“ื™ uio_open ืคื•ื ืงืฆื™ืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹ื“ื™ uio ืกืึทื‘ืกื™ืกื˜ืึทื, ื•ื•ืึธืก ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืึทืœืึทื•ื™ื ื’ ืึท ื”ื™ื’ืข ื‘ืึทื ื™ืฆืขืจ ืฆื• ื•ื™ืกืคื™ืจืŸ ื–ื™ื™ืขืจ ืงืึธื“ ืžื™ื˜ ืงืขืจืŸ ืจืขื›ื˜.
  • CVE-2024-26582 ื ื ื•ืฆืŸ-ื ืึธืš-ืคืจื™ื™ ื–ื™ืงืึธืจืŸ ืจื•ืฃ ืื™ืŸ ื“ื™ ืงืขืจืŸ-ืžื“ืจื’ื” TLS (ktls) ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ื”ืื˜ ื“ื™ ืคึผืึธื˜ืขื ืฆื™ืขืœ ืฆื• ืขืกืงืึทืœื™ื™ื˜ ื–ื™ื™ืŸ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ื•ื•ืขืŸ ืื™ืจ ื“ื•ืจื›ืคื™ืจืŸ ื“ืขืงืจื™ืคึผื˜ื™ืึธืŸ ืึทืคึผืขืจื™ื™ืฉืึทื ื–.
  • CVE-2024-0646 ืึทืŸ ืึทืจื•ื™ืก-ืคื•ืŸ-ื‘ืึทื•ื ื“ ื–ื™ืงืึธืจืŸ ืฉืจื™ื™ึทื‘ืŸ ืื™ืŸ ื“ื™ ืงื˜ืœืก ืกืึทื‘ืกื™ืกื˜ืึทื ืึทืงืขืจื– ืจืขื›ื˜ ืฆื• ื–ื™ื›ืขืจ ื”ื™ื’ืข ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทืŸ ืคื•ืŸ ืึท ืงื˜ืœืก ื›ืึธืœืขืœ ื“ื•ืจืš ื“ื™ ืกืคึผืœื™ื™ืก ืคื•ื ืงืฆื™ืข. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืขืกืงืึทืœื™ื™ื˜ ื“ื™ื™ืŸ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืื™ืŸ ื“ื™ ืกื™ืกื˜ืขื.
  • CVE-2023-6932 ืื™ื– ืึท ืจืึทืกืข ืฆื•ืฉื˜ืึทื ื“ ืื™ืŸ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ IGMP (Internet Group Management Protoco) ืคึผืจืึธื˜ืึธืงืึธืœ ืื™ืŸ ื“ื™ IPv4 ืึธื ืœื™ื™ื’ืŸ, ื•ื•ืึธืก ืคื™ืจืŸ ืฆื• ืึทืงืกืขืก ืฆื• ืฉื•ื™ืŸ ื‘ืืคืจื™ื™ื˜ ื–ื›ึผืจื•ืŸ (ื ื•ืฆืŸ-ื ืึธืš-ืคืจื™ื™). ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืึทืœืึทื•ื– ืึท ื”ื™ื’ืข ื‘ืึทื ื™ืฆืขืจ ืฆื• ืขืกืงืึทืœื™ื™ื˜ ื–ื™ื™ืขืจ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืื•ื™ืฃ ื“ื™ ืกื™ืกื˜ืขื.
  • CVE-2023-52435 - MSS ืึธื•ื•ื•ืขืจืคืœืึธื• ืื™ืŸ ื“ื™ skb_segment() ืคึฟื•ื ืงืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืงืขืจืŸ ื ืขืฅ ืึธื ืœื™ื™ื’ืŸ.
  • CVE-2024-26601 - ืึท ื˜ืขื•ืช ืื™ืŸ ื“ื™ ื‘ืœืึทืง ืžืขืœื“ื•ื ื’ ืงืึธื“ ืื™ืŸ ื“ื™ ืขืงืกื˜4 ื˜ืขืงืข ืกื™ืกื˜ืขื ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ืคืึทืจื“ืึธืจื‘ืŸ ื“ื™ ื‘ืึทื“ื™ ื‘ื™ื˜ืžืึทืคึผ.
  • CVE-2024-26598 โ€“ ื ื•ืฆืŸ-ื ืืš-ืคืจื™ื™ ืฉื•ื•ืื›ืงื™ื™ื˜ ืื™ืŸ ื”ื™ืคึผืขืจื•ื•ื™ื™ื–ืขืจ ืงื•ื•ื.

ืžืงื•ืจ: opennet.ru

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster