Ukuba sengozini ku-Linux perf kernel subsystem evumela ukukhuphuka kwamalungelo

Ukuba sengozini (CVE-2022-1729) kukhonjwe ku-Linux kernel, okuvumela umsebenzisi wendawo ukuthi athole ukufinyelela kwezimpande ohlelweni. Ukuba sengozini kubangelwa isimo somjaho kusistimu engaphansi ye-perf, engasetshenziswa ukuqalisa ukusetshenziswa kwangemuva kokufinyelela kwamahhala endaweni esivele ikhululiwe yememori ye-kernel. Inkinga ibilokhu ivela selokhu kwakhululwa i-kernel 4.0-rc1. Amandla okusebenza aqinisekisiwe ekukhishweni okungu-5.4.193+.

Ukulungisa okwamanje kutholakala kuphela nge-patch form. Ingozi yokuba sengozini incishiswa iqiniso lokuthi ukusabalalisa okuningi ngokuzenzakalela kukhawulela ukufinyelela ku-perf kubasebenzisi abangenamalungelo. Njengomsebenzi wokuvikela, ungasetha ipharamitha ye-sysctl i-kernel.perf_event_paranoid ibe ngu-3.

Source: opennet.ru

Engeza amazwana