ืื™ืŸ ื“ื™ Futex ืกื™ืกื˜ืขื ืจื•ืคืŸ, ื“ื™ ืžืขื’ืœืขื›ืงื™ื™ื˜ ืคื•ืŸ ืขืงืกืึทืงื™ื•ื˜ื™ื ื’ ื‘ืึทื ื™ืฆืขืจ ืงืึธื“ ืื™ืŸ ื“ืขื ืงืึธื ื˜ืขืงืกื˜ ืคื•ืŸ ื“ื™ ืงืขืจืŸ ืื™ื– ื“ื™ืกืงืึทื•ื•ืขืจื“ ืื•ืŸ ื™ืœื™ืžืึทื ื™ื™ื˜ืึทื“

ืื™ืŸ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ Futex (ืฉื ืขืœ Userspace Mutex) ืกื™ืกื˜ืขื ืจื•ืคืŸ, ืึธื ืœื™ื™ื’ืŸ ื–ื›ึผืจื•ืŸ ื‘ืึทื ื™ืฅ ื ืึธืš ืคืจื™ื™ ืื™ื– ื“ื™ื˜ืขืงื˜ืึทื“ ืื•ืŸ ื™ืœื™ืžืึทื ื™ื™ื˜ืึทื“. ื“ืึธืก, ืื™ืŸ ืงืขืจ, ื“ืขืจืœื•ื™ื‘ื˜ ื“ื™ ืึทื˜ืึทืงืขืจ ืฆื• ื•ื™ืกืคื™ืจืŸ ื–ื™ื™ืŸ ืงืึธื“ ืื™ืŸ ื“ืขื ืงืึธื ื˜ืขืงืกื˜ ืคื•ืŸ ื“ื™ ืงืขืจืŸ, ืžื™ื˜ ืึทืœืข ื“ื™ ืงืึทื ืกืึทืงื•ื•ืขื ืกืึทื– ืคื•ืŸ ืึท ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคื•ื ื˜ ืคื•ืŸ ืžื™ื™ื ื•ื ื’. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื’ืขื•ื•ืขืŸ ืื™ืŸ ื“ื™ ื˜ืขื•ืช ื”ืึทื ื“ืœืขืจ ืงืึธื“.

ืงืขืจืขืงืฉืึทืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืืจื•ื™ืก ืื™ืŸ ื“ื™ ืœื™ื ื•ืงืก ื”ื•ื™ืคึผื˜ ืœื™ื ื™ืข ืื•ื™ืฃ 28 ื™ืื ื•ืืจ ืื•ืŸ ื“ืขื ื˜ืึธื’ ืคืจื™ืขืจ ื ืขื›ื˜ืŸ ืขืก ืื™ื– ืืจื™ื™ืŸ ืื™ืŸ ืงืขืจื ืึทืœื– 5.10.12, 5.4.94, 4.19.172, 4.14.218.

ื‘ืขืฉืึทืก ื“ื™ ื“ื™ืกืงื•ืกื™ืข ืคื•ืŸ โ€‹โ€‹ื“ืขื ืคืึทืจืจื™ื›ื˜ืŸ, ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ืกืึทื’ื“ื–ืฉืขืกื˜ื™ื“ ืึทื– ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ื™ื’ื–ื™ืกืฅ ืื™ืŸ ืึทืœืข ืงืขืจื ืึทืœื– ื–ื™ื ื˜ 2008:

https://www.openwall.com/lists/oss-security/2021/01/29/3

FWIW, this commit has: Fixes: 1b7558e457ed ("futexes: fix fault handling in futex_lock_pi") and that other commit is from 2008. So probably all currently maintained Linux distros and deployments are affected, unless something else mitigated the issue in some kernel versions.

ืžืงื•ืจ: linux.org.ru