Ukuba sengozini kusitaki senethiwekhi ye-Linux kernel

Ukuba sengozini kukhonjwe kukhodi yesibambi sephrothokholi ye-RDS esekwe ku-TCP (Isokhethi Yedatha Ethembekile, net/rds/tcp.c) (I-CVE-2019-11815), okungaholela ekufinyeleleni endaweni yememori evele ikhululiwe kanye nokwenqatshwa kwenkonzo (okungenzeka, ukuthi kungenzeka ukuthi kusetshenziswe inkinga ukuhlela ukukhishwa kwekhodi akufakiwe). Inkinga ibangelwa isimo somjaho esingase sibe khona uma kwenziwa umsebenzi we-rds_tcp_kill_sock ngenkathi kusula amasokhethi endaweni yamagama yenethiwekhi.

Esicacisweni I-NVD inkinga imakwe njengokusebenziseka ukude kunethiwekhi, kodwa uma kubhekwa incazelo ukulungiswa, ngaphandle kokuba khona kwendawo kusistimu nokusetshenziswa kwezikhala zamagama, ngeke kwenzeke ukuhlela ukuhlasela ukude. Ikakhulukazi, ngokusho umbono Onjiniyela be-SUSE, ukuba sengozini kuxhashazwa endaweni kuphela; ukuhlela ukuhlasela kuyinkimbinkimbi futhi kudinga amalungelo angeziwe ohlelweni. Uma ku-NVD izinga lengozi lihlolwa kumaphuzu angu-9.3 (CVSS v2) kanye nangu-8.1 (CVSS v2), bese ngokwesilinganiso se-SUSE ingozi ihlolwa ngamaphoyinti angu-6.4 kwangu-10.

Abamele Ubuntu futhi baziswa ingozi yenkinga ibhekwa njengokulinganisela. Ngesikhathi esifanayo, ngokuhambisana nokucaciswa kwe-CVSS v3.0, inkinga inikezwa izinga eliphezulu lobunzima bokuhlasela futhi ukuxhashazwa kunikezwa amaphuzu angu-2.2 kuphela kwangu-10.

Ukwahlulela umbiko kusuka ku-Cisco, ubungozi buxhashazwa kude ngokuthumela amaphakethe e-TCP kumasevisi enethiwekhi asebenzayo RDS futhi sekuvele kukhona i-prototype yokuxhashazwa. Izinga lolu lwazi oluhambisana ngalo neqiniso alikacaci kahle; mhlawumbe umbiko ufaka ngobuciko kuphela ukuqagela kwe-NVD. Ngu ulwazi Ukuxhaphaza kwe-VulDB akukakadalwa futhi inkinga isetshenziswa endaweni kuphela.

Inkinga ivela ezinhlamvini ngaphambi kuka-5.0.8 futhi ivinjwe ngoNdasa ukulungiswa, kufakwe ku-kernel 5.0.8. Ekusakazweni okuningi inkinga ihlala ingaxazululiwe (Debian, RHEL, Ubuntu, SUSE). Ukulungiswa kukhishwe i-SLE12 SP3, i-openSUSE 42.3 kanye Fedora.

Source: opennet.ru

Engeza amazwana