ื“ื™ ืœื™ื ื•ืงืก 5.4 ืงืขืจืŸ ื”ืื˜ ื‘ืืงื•ืžืขืŸ ืคึผืึทื˜ืฉืึทื– ืฆื• ื‘ืึทื’ืจืขื ืขืฆืŸ ื•ื•ืึธืจืฆืœ ืึทืงืกืขืก ืฆื• ื“ื™ ืงืขืจืŸ ื™ื ื˜ืขืจื ืึทืœืก

ืœื™ื ื•ืก ื˜ืึธืจื•ื•ืึทืœื“ืก ืื ื’ืขื ื•ืžืขืŸ ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ืŸ ื“ื™ ืึทืคึผืงืึทืžื™ื ื’ ืžืขืœื“ื•ื ื’ ืคื•ืŸ ื“ื™ Linux 5.4 ืงืขืจืŸ ืื™ื– ืึท ืกื›ื•ื ืคื•ืŸ ืคึผืึทื˜ืฉืึทื– "lockdownยซ ืคืืจื’ืขืœื™ื™ื’ื˜ David Howells (Red Hat) ืื•ืŸ Matthew Garrett (ืžืชื™ื ื’ืึทืจื™ื˜, ืึทืจื‘ืขื˜ ื‘ื™ื™ Google) ืฆื• ื‘ืึทื’ืจืขื ืขืฆืŸ ื•ื•ืึธืจืฆืœ ื‘ืึทื ื™ืฆืขืจ ืึทืงืกืขืก ืฆื• ื“ื™ ืงืขืจืŸ. ืœืึทืงื“ืึทื•ืŸ-ืคึฟืึทืจื‘ื•ื ื“ืขื ืข ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™ ืื™ื– ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ืŸ ืึท ืึธืคึผื˜ื™ืึธื ืึทืœืœื™ ืœืึธื•ื“ื™ื“ LSM ืžืึธื“ื•ืœืข (ืœื™ื ื•ืงืก ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžืึธื“ื•ืœืข), ื•ื•ืึธืก ืฉื˜ืขืœืŸ ืึท ืฉืœืึทื‘ืึทืŸ ืฆื•ื•ื™ืฉืŸ UID 0 ืื•ืŸ ื“ื™ ืงืขืจืŸ, ืจื™ืกื˜ืจื™ืงื˜ื™ื ื’ ื–ื™ื›ืขืจ ื ื™ื“ืขืจื™ืง-ืžื“ืจื’ื” ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™.

ืื•ื™ื‘ ืึท ืึทื˜ืึทืงืขืจ ืึทื˜ืฉื™ื•ื•ื– ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืžื™ื˜ ื•ื•ืึธืจืฆืœ ืจืขื›ื˜, ืขืจ ืงืขื ืขืŸ ื•ื™ืกืคื™ืจืŸ ื–ื™ื™ืŸ ืงืึธื“ ืื•ื™ืฃ ื“ื™ ืงืขืจืŸ ืžื“ืจื’ื”, ืœืžืฉืœ, ื“ื•ืจืš ืจื™ืคึผืœื™ื™ืกื™ื ื’ ื“ื™ ืงืขืจืŸ ื ื™ืฆืŸ ืงืขืงืกืขืง ืึธื“ืขืจ ืœื™ื™ืขื ืขืŸ / ืฉืจื™ื™ื‘ืŸ ื–ื›ึผืจื•ืŸ ื“ื•ืจืš /dev/kmem. ื“ื™ ืžืขืจืกื˜ ืงืœืึธืจ ื•ื•ื™ ื“ืขืจ ื˜ืึธื’ ืงืึทื ืกืึทืงื•ื•ืึทื ืก ืคื•ืŸ ืึทื–ืึท ื˜ืขื˜ื™ืงื™ื™ื˜ ืงืขืŸ ื–ื™ื™ืŸ ืึธื ื•ื•ืขื’ UEFI Secure Boot ืึธื“ืขืจ ืจื™ื˜ืจื™ื•ื•ื™ื ื’ ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ื“ืึทื˜ืŸ ืกื˜ืึธืจื“ ืื•ื™ืฃ ื“ื™ ืงืขืจืŸ ืžื“ืจื’ื”.

ื˜ื›ื™ืœืขืก, ื•ื•ืึธืจืฆืœ ืจื™ืกื˜ืจื™ืงืฉืึทืŸ ืคืึทื ื’ืงืฉืึทื ื– ื–ืขื ืขืŸ ื“ืขื•ื•ืขืœืึธืคึผืขื“ ืื™ืŸ ื“ืขื ืงืึธื ื˜ืขืงืกื˜ ืคื•ืŸ ืคึฟืึทืจืฉื˜ืึทืจืงื•ื ื’ ื“ื™ ืฉื•ืฅ ืคื•ืŸ ื•ื•ืขืจืึทืคื™ื™ื“ ืฉื˜ื™ื•ื•ืœ, ืื•ืŸ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ื ื™ืฆืŸ ื“ืจื™ื˜-ืคึผืึทืจื˜ื™ื™ ืคึผืึทื˜ืฉืึทื– ืฆื• ืคืึทืจืฉืคึผืึทืจืŸ ื‘ื™ื™ืคึผืึทืก ืคื•ืŸ UEFI Secure Boot ืคึฟืึทืจ ื’ืึทื ืฅ ืขื˜ืœืขื›ืข ืžืึธืœ. ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ึทื˜, ืึทื–ืึท ืจื™ืกื˜ืจื™ืงืฉืึทื ื– ื–ืขื ืขืŸ ื ื™ืฉื˜ ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ืŸ ื“ื™ ื”ื•ื™ืคึผื˜ ื–ืึทืฅ ืคื•ืŸ ื“ื™ ืงืขืจืŸ ืจืขื›ื˜ ืฆื• ื“ื™ืกืึทื’ืจื™ืžืึทื ืฅ ืื™ืŸ ื–ื™ื™ืขืจ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืื•ืŸ ืคื™ืจื– ืคื•ืŸ ื“ื™ืกืจืึทืคึผืฉืึทืŸ ืฆื• ื™ื’ื–ื™ืกื˜ื™ื ื’ ืกื™ืกื˜ืขืžืขืŸ. ื“ื™ "ืœืึทืงื“ืึทื•ืŸ" ืžืึธื“ื•ืœืข ืึทื‘ื–ืึธืจื‘ื“ ืคึผืึทื˜ืฉืึทื– ืฉื•ื™ืŸ ื’ืขื ื™ืฆื˜ ืื™ืŸ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื–, ื•ื•ืึธืก ื–ืขื ืขืŸ ืจื™ื“ื™ื–ื™ื™ื ื“ ืื™ืŸ ื“ื™ ืคืึธืจืขื ืคื•ืŸ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืกืึทื‘ืกื™ืกื˜ืึทื ื ื™ื˜ ื˜ื™ื™ื“ ืฆื• UEFI Secure Boot.

ืœืึทืงื“ืึทื•ืŸ ืžืึธื“ืข ืจื™ืกื˜ืจื™ืงืฅ ืึทืงืกืขืก ืฆื• /dev/mem, /dev/kmem, /dev/port, /proc/kcore, debugfs, kprobes debug mode, mmiotrace, tracefs, BPF, PCMCIA CIS (Card Information Structure), ืขื˜ืœืขื›ืข ACPI ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืื•ืŸ ืงืคึผื• MSR ืจืขื“ื–ืฉื™ืกื˜ืขืจื–, kexec_file ืื•ืŸ kexec_load ืงืึทืœืœืก ื–ืขื ืขืŸ ืืคื’ืขืฉื˜ืขืœื˜, ืฉืœืึธืคืŸ ืžืึธื“ืข ืื™ื– ืคึผืจืึธื•ื›ื™ื‘ืึทื˜ืึทื“, DMA ื ื•ืฆืŸ ืคึฟืึทืจ PCI ื“ืขื•ื•ื™ืกืขืก ืื™ื– ืœื™ืžื™ื˜ืขื“, ACPI ืงืึธื“ ืึทืจื™ื™ึทื ืคื™ืจ ืคื•ืŸ EFI ื•ื•ืขืจื™ืึทื‘ืึทืœื– ืื™ื– ืคึผืจืึธื•ื›ื™ื‘ืึทื˜ืึทื“,
ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทื ื– ืžื™ื˜ ื™ / ืึธ ืคึผืึธืจืฅ ื–ืขื ืขืŸ ื ื™ืฉื˜ ืขืจืœื•ื™ื‘ื˜, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ื˜ืฉืึทื ื’ื™ื ื’ ื“ื™ ื™ื‘ืขืจืจื™ื™ึทืก ื ื•ืžืขืจ ืื•ืŸ ื™ / ืึธ ืคึผืึธืจื˜ ืคึฟืึทืจ ื“ื™ ืกื™ืจื™ืึทืœ ืคึผืึธืจื˜.

ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ื“ื™ ืœืึทืงื“ืึทื•ืŸ ืžืึธื“ื•ืœืข ืื™ื– ื ื™ืฉื˜ ืึทืงื˜ื™ื•ื•, ืขืก ืื™ื– ื’ืขื‘ื•ื™ื˜ ื•ื•ืขืŸ ื“ื™ SECURITY_LOCKDOWN_LSM ืึธืคึผืฆื™ืข ืื™ื– ืกืคึผืขืกื™ืคื™ืขื“ ืื™ืŸ kconfig ืื•ืŸ ืื™ื– ืึทืงื˜ื™ื•ื•ื™ื™ื˜ื™ื“ ื“ื•ืจืš ื“ื™ ืงืขืจืŸ ืคึผืึทืจืึทืžืขื˜ืขืจ "ืœืึทืงื“ืึทื•ืŸ =", ื“ื™ ืงืึธื ื˜ืจืึธืœ ื˜ืขืงืข "/sys/kernel/security/lockdown" ืึธื“ืขืจ ืคึฟืึทืจื–ืึทืžืœื•ื ื’ ืึธืคึผืฆื™ืขืก LOCK_DOWN_KERNEL_FORCE_*, ื•ื•ืึธืก ืงืขื ืขืŸ ื ืขืžืขืŸ ื“ื™ ื•ื•ืึทืœื•ืขืก "ืึธืจื ื˜ืœืขื›ืงื™ื™ึทื˜" ืื•ืŸ "ืงืึทื ืคืึทื“ืขื ืฉื™ืึทืœืึทื˜ื™". ืื™ืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ืคืึทืœ, ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ื•ื•ืึธืก ืœืึธื–ืŸ ืขื ื“ืขืจื•ื ื’ืขืŸ ืฆื• ื“ื™ ืคืœื™ืกื ื“ื™ืง ืงืขืจืŸ ืคึฟื•ืŸ ื‘ืึทื ื™ืฆืขืจ ืคึผืœืึทืฅ ื–ืขื ืขืŸ ืืคื’ืขืฉื˜ืขืœื˜, ืื•ืŸ ืื™ืŸ ื“ื™ ืฆื•ื•ื™ื™ื˜ืข ืคืึทืœ, ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™ ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ืขืงืกื˜ืจืึทืงื˜ ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืงืขืจืŸ ืื™ื– ืื•ื™ืš ืคืึทืจืงืจื™ืคึผืœื˜.

ืขืก ืื™ื– ื•ื•ื™ื›ื˜ื™ืง ืฆื• ื˜ืึธืŸ ืึทื– ืœืึทืงื“ืึทื•ืŸ ื‘ืœื•ื™ื– ืœื™ืžืึทืฅ ื ืึธืจืžืึทืœ ืึทืงืกืขืก ืฆื• ื“ื™ ืงืขืจืŸ, ืึธื‘ืขืจ ื˜ื•ื˜ ื ื™ืฉื˜ ื‘ืึทืฉื™ืฆืŸ ืงืขื’ืŸ ืžืึธื“ื™ืคื™ืงืึทื˜ื™ืึธื ืก ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ืขืงืกืคึผืœื•ื™ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–. ืฆื• ืคืึทืจืฉืคึผืึทืจืŸ ืขื ื“ืขืจื•ื ื’ืขืŸ ืฆื• ื“ื™ ืคืœื™ืกื ื“ื™ืง ืงืขืจืŸ ื•ื•ืขืŸ ืขืงืกืคึผืœื•ื™ืฅ ื–ืขื ืขืŸ ื’ืขื ื™ืฆื˜ ื“ื•ืจืš ื“ื™ Openwall ืคึผืจื•ื™ืขืงื˜ ืื™ื– ื“ืขื•ื•ืขืœืึธืคึผื™ื ื’ ื‘ืึทื–ื•ื ื“ืขืจ ืžืึธื“ื•ืœืข LKRG (ืœื™ื ื•ืงืก ืงืขืจื ืขืœ ืจื•ื ื˜ื™ืžืข ื’ืึทืจื“).

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’