Ukuba sengozini kumshayeli we-vhost-net kusuka ku-Linux kernel

Kumshayeli we-vhost-net, oqinisekisa ukusebenza kwe-virtio net ohlangothini lwendawo yokusingatha, ikhonjiwe ubungozi (I-CVE-2020-10942), okuvumela umsebenzisi wasendaweni ukuthi aqalise ukuchichima kwesitaki se-kernel ngokuthumela ioctl(VHOST_NET_SET_BACKEND) efomethwe ngokukhethekile kudivayisi/dev/vhost-net. Inkinga ibangelwa ukuntuleka kokuqinisekiswa okufanele kokuqukethwe kwenkambu ye-sk_family kukhodi yokusebenza ye-get_raw_socket().

Ngokusho kwedatha yokuqala, ukuba sengozini kungasetshenziswa ukwenza ukuhlasela kwe-DoS yendawo ngokubangela ukuphahlazeka kwe-kernel (alukho ulwazi mayelana nokusetshenziswa kokuchichima kwesitaki okubangelwa ukuba sengozini kokuhlela ukwenziwa kwekhodi).
Ukuba sengozini kuqedwe kusibuyekezo se-Linux kernel 5.5.8. Ngokusatshalaliswa, ungakwazi ukulandelela ukukhishwa kwezibuyekezo zephakheji emakhasini Debian, Ubuntu, RHEL, SUSE/openSUSE, Fedora, Arch.

Source: opennet.ru

Engeza amazwana