I-Floppy Driver Ishiywe Ingagcinwanga ku-Linux Kernel

Kufakwe ku-Linux 5.3 kernel kwamukelwe izinguquko zokwengeza ukuvikeleka okwengeziwe kwezingcingo ze-ioctl ezihlobene nomshayeli we-floppy, futhi umshayeli ngokwakhe umakwa njengonganakekelwa
(β€œintandane”), okusho ukuqedwa kokuhlolwa kwayo.

Umshayeli ubhekwa njengophelelwe yisikhathi, ngoba kunzima ukuthola imishini yokusebenza ukuze uyihlole - wonke amadrayivu angaphandle amanje, njengomthetho, sebenzisa isixhumi esibonakalayo se-USB. Ngesikhathi esifanayo, ukukhishwa komshayeli ku-kernel kuphazamiseka ukuthi abalawuli be-floppy disk basalingiswa ezinhlelweni ze-virtualization. Ngakho-ke, umshayeli usagcinwe ku-kernel, kodwa ukusebenza kwayo okulungile akuqinisekisiwe.

Futhi, kumshayeli we-floppy kuqedwe ukuba sengozini (I-CVE-2019-14283), okuvumela, ngokukhohlisa i-ioctl, umsebenzisi ongenalungelo onekhono lokufaka i-floppy disk yakhe, ukufunda idatha evela ezindaweni zememori ngaphandle kwemingcele ye-copy buffer (isibonelo, izindawo eziseduze zingaqukatha idatha eyinsalela evela kudiski i-cache ne-buffer yokufaka). Ngakolunye uhlangothi, ubungozi buhlala bubalulekile njengoba umshayeli wefloppy elayishwa ngokuzenzakalelayo uma kukhona isilawuli esilingisiwe esihambisanayo ezinhlelweni ze-virtualization (isibonelo, sisetshenziswa ngokuzenzakalelayo ku-QEMU), kodwa ngakolunye uhlangothi, ukuxhaphaza inkinga, kuyadingeka ukuthi isithombe se-floppy disk esilungiselelwe umhlaseli sixhunywe.

Source: opennet.ru

Engeza amazwana