Glibc 2.30 ืกื™ืกื˜ืขื ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืžืขืœื“ื•ื ื’

ื ืึธืš ื–ืขืงืก ื—ื“ืฉื™ื ืคื•ืŸ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ืืจื•ื™ืก ืžืขืœื“ื•ื ื’ ืคื•ืŸ ืกื™ืกื˜ืขื ื‘ื™ื‘ืœื™ืึธื˜ืขืง GNU C ื‘ื™ื‘ืœื™ืึธื˜ืขืง (ื’ืœื™ื‘ืง) 2.30, ื•ื•ืึธืก ื’ืึธืจ ื ืึธื›ืงื•ืžืขืŸ ืžื™ื˜ ื“ื™ ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ ืคื•ืŸ ISO C11 ืื•ืŸ POSIX.1-2008 ืกื˜ืึทื ื“ืึทืจื“ืก. ื“ื™ ื ื™ื™ึทืข ืžืขืœื“ื•ื ื’ ื›ื•ืœืœ ืคื™ืงืกื™ื– ืคื•ืŸ 48 ื“ืขื•ื•ืขืœืึธืคึผืขืจืก.

ืคึฟื•ืŸ ื“ื™ ื™ืžืคึผืœืึทืžืขื ืึทื“ ืื™ืŸ Glibc 2.30 ื™ืžืคึผืจื•ื•ื•ืžืึทื ืฅ ืื™ืจ ืงืขื ื˜ ื‘ืืžืขืจืงืŸ:

  • ื“ื™ ื“ื™ื ืึทืžื™ืฉ ืœื™ื ืงืขืจ ื’ื™ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื“ื™ "--ืคึผืจืขืœืึธืึทื“" ืึธืคึผืฆื™ืข ืคึฟืึทืจ ืคึผืจืขืœืึธืึทื“ื™ื ื’ ืฉืขืจื“ ืึทื‘ื“ื–ืฉืขืงืฅ (ืึทื ืึทืœืึธื’ ืฆื• ื“ื™ LD_PRELOAD ืกื•ื•ื™ื•ื•ืข ื‘ื™ื™ึทื˜ืขื•ื•ื“ื™ืง);
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ twalk_r ืคื•ื ืงืฆื™ืข, ืขื ืœืขืš ืฆื• ื“ื™ ืฉื•ื™ืŸ ื™ื’ื–ื™ืกื˜ื™ื ื’ ื˜ื•ื•ืึทืœืง ืคื•ื ืงืฆื™ืข, ืึธื‘ืขืจ ืึทืœืึทื•ื™ื ื’ ืื™ืจ ืฆื• ืคืึธืจืŸ ืึทืŸ ื ืึธืš ืึทืจื’ื•ืžืขื ื˜ ืฆื• ืึท ื’ืขื’ืขื‘ืŸ ืงืึทืœืœื‘ืึทืง ืคื•ื ืงืฆื™ืข;
  • ื ื™ื• ืคืึทื ื’ืงืฉืึทื ื– getdents64, gettid ืื•ืŸ tgkill ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืขื‘ืŸ ืคึฟืึทืจ ืœื™ื ื•ืงืก;
  • ืคืึทืจื–ื™ื›ืขืจืŸ ืึทื– ื“ื™ ื–ื™ืงืึธืจืŸ ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’ ืคืึทื ื’ืงืฉืึทื ื– malloc, calloc, realloc, reallocarray, valloc, pvalloc, memalign, ืื•ืŸ posix_memalign ืึทืจื•ื™ืกื’ืึทื ื’ ืžื™ื˜ ืึท ื˜ืขื•ืช ืงืึธื“ ื•ื•ืขืŸ ื“ื™ ื’ืึทื ืฅ ื›ื™ื™ืคืขืฅ ื’ืจื™ื™ืก ื™ืงืกื™ื“ื– ื“ื™ PTRDIFF_MAX ื•ื•ืขืจื˜. ื“ืขืจ ืขื ื“ืขืจื•ื ื’ ืึทื•ื•ื•ื™ื“ื– ืึทื ื“ื™ืคื™ื™ื ื“ ื ืึทื˜ื•ืจ ื•ื•ืขืŸ ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ื˜ื™ื™ึทื˜ืœ ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทืŸ ืคื™ืจื˜ ืฆื• ืึท ืึธื•ื•ื•ืขืจืคืœืึธื• ืคื•ืŸ ื“ื™ ื˜ื™ืคึผ ืคึผื˜ืจื“ื™ืคืฃ_ื˜;
  • ืฆื•ื’ืขื’ืขื‘ืŸ POSIX ืคืึทื ื’ืงืฉืึทื ื– pthread_cond_clockwait, pthread_mutex_clocklock,
    pthread_rwlock_clockrdlock, pthread_rwlock_clockwrlock ืื•ืŸ sem_clockwait, ืขื ืœืขืš ืฆื• ื“ื™ "ื˜ื™ื™ืžื“" ื™ืงื•ื•ื™ื•ื•ืึทืœืึทื ืฅ, ืึธื‘ืขืจ ืึทื“ื™ืฉื ืึทืœื™ ืึทืงืกืขืคึผื˜ื™ื ื’ ืึท clockid_t ืคึผืึทืจืึทืžืขื˜ืขืจ ืฆื• ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ื“ื™ ื˜ื™ื™ึทืžืขืจ;

  • ืงืึธื“ื™ืจื•ื ื’ ื“ืึทื˜ืŸ, ื›ืึทืจืึทืงื˜ืขืจ ื˜ื™ืคึผ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืื•ืŸ ื˜ืจืึทื ืกืœื™ื˜ืขืจืึทื˜ื™ืึธืŸ ื˜ื™ืฉืŸ ื–ืขื ืขืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ ืฆื• ืฉื˜ื™ืฆืŸ ื“ื™ ืื•ื ื™ืงืึธื“ 12.1.0 ื‘ืึทืฉืจื™ื™ึทื‘ื•ื ื’;
  • ื“ื™ ื‘ื™ื‘ืœื™ืึธื˜ืขืง ื‘ื™ื‘ืœื™ืึธื˜ืขืง ื ื™ื˜ ืžืขืจ ื’ื™ื˜ ื“ื™ clock_gettime, clock_getres, clock_settime, clock_getcpuclockid ืื•ืŸ clock_nanosleep ืคืึทื ื’ืงืฉืึทื ื– ืคึฟืึทืจ ื ื™ื™ึทืข ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–, ืึธื‘ืขืจ ืึทื ืฉื˜ืึธื˜ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื ื™ืฆื˜ ื“ื™ ื–ื•ืš ืื™ืŸ libc;
  • ื“ื™ "ื™ื ืขื˜6" ืึธืคึผืฆื™ืข ืื™ื– ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ ืคื•ืŸ /etc/resolv.conf. ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ ืคืึทืจืขืœื˜ืขืจื˜ ืคืœืึทื’ืก RES_USE_INET6, RES_INSECURE1 ืื•ืŸ RES_INSECURE2 ืคึฟื•ืŸ resolv.h;
  • ื•ื•ืขืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ "--enable-bind-now" ืึธืคึผืฆื™ืข, ืื™ื ืกื˜ืึทืœื™ืจืŸ ืžื’ื™ืœื” ื–ืขื ืขืŸ ืื™ืฆื˜ ื’ืขื‘ื•ื ื“ืŸ ื ื™ืฆืŸ ื“ื™ BIND_NOW ืคืึธืŸ;
  • ื“ื™ ืœื™ื ื•ืงืก-ืกืคึผืขืฆื™ืคื™ืฉ sys/sysctl.h ื›ืขื“ืขืจ ื˜ืขืงืข ืื•ืŸ sysctl ืคึฟื•ื ืงืฆื™ืข ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ื“ื™ืคึผืจื™ืฉื™ื™ื™ื˜ื™ื“, ืื•ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื–ืึธืœ ื ื•ืฆืŸ ื“ื™ /proc pseudo-FS ืึทื ืฉื˜ืึธื˜;
  • ื‘ื™ืœื“ื™ื ื’ Glibc ืื™ืฆื˜ ืจื™ืงื•ื•ื™ื™ืขืจื– GCC 6.2 ืึธื“ืขืจ ื ื™ื™ึทืขืจ (ืงื™ื™ืŸ ืงืึทืžืคึผื™ื™ืœืขืจ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ื‘ื•ื™ืขืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–);
  • ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืคืึทืจืคืขืกื˜ื™ืงื˜ CVE-2019-7309 ืื™ืŸ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ memcmp ืคื•ื ืงืฆื™ืข ืคึฟืึทืจ ืึทื•ื˜ื“ื™ื™ื˜ื™ื“ x32 ืกื•ื‘ืึทืจื˜ืฉื™ื˜ืขืงื˜ื•ืจืข (ื ื™ื˜ ืฆื• ื–ื™ื™ืŸ ืฆืขืžื™ืฉื˜ ืžื™ื˜ x86 IA-32), ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ื•ื•ืึธืก ื“ื™ ืคึฟื•ื ืงืฆื™ืข ืงืขืŸ ืคืึทืœืฉ ืฆื•ืจื™ืงืงื•ืžืขืŸ ื“ื™ ื•ื•ืขืจื˜ 0 ืคึฟืึทืจ ื ื™ื˜-ื•ื•ืึธืก ืจื™ื›ื˜ืŸ ืกื˜ืจื™ื ื’ืก;
  • ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืคืึทืจืคืขืกื˜ื™ืงื˜ CVE-2019-9169, ื•ื•ืึธืก ืงืขื ืขืŸ ืึธื ืžืึทื›ืŸ ื“ืึทื˜ืŸ ืฆื• ืœื™ื™ืขื ืขืŸ ืคึฟื•ืŸ ืึท ื’ืขื’ื ื˜ ืึทืจื•ื™ืก ื“ื™ ื‘ืึทืคืขืจ ืก ื’ืจืขื ืขืฆืŸ ื•ื•ืขืŸ ื–ื™ื›ืขืจ ืจืขื’ื•ืœืขืจ ืื•ื™ืกื“ืจื•ืงืŸ ื–ืขื ืขืŸ ืคึผืจืึทืกืขืกื˜.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’