Ukuba sengozini ku-systemd okungase kukuvumele ukuthi ukhuphule amalungelo akho

Kumphathi wesistimu ye-systemd ikhonjiwe ubungozi (I-CVE-2020-1712), okungenzeka ikuvumela ukuthi usebenzise ikhodi yakho ngamalungelo aphakeme ngokuthumela isicelo esiklanywe ngokukhethekile ngebhasi le-DBus. Inkinga ilungisiwe ekukhishweni kokuhlola uhlelo 245-rc1 (iziqephu ezixazulula inkinga: 1, 2, 3). Ukuba sengozini kulungisiwe ekusabalaliseni Ubuntu, Fedora, RHEL (ivela ku-RHEL 8, kodwa ayithinti i-RHEL 7), CentOS ΠΈ SUSE/openSUSE, kodwa ngesikhathi sokubhala izindaba zihlala zingalungiswanga Debian ΠΈ I-Arch Linux.

Ukuba sengozini kubangelwa ukufinyelela endaweni yenkumbulo esivele ikhululiwe (ukusebenzisa ngemva-kwamahhala), okwenzeka lapho kufakwa izicelo ngokulinganayo ku-Polkit ngenkathi kucutshungulwa imilayezo ye-DBus. Ezinye izixhumi ezibonakalayo ze-DBus zisebenzisa inqolobane yokugcina izinto isikhathi esifushane futhi zisule okufakiwe kwenqolobane ngokushesha nje lapho ibhasi le-DBus selikhululekile ukucubungula ezinye izicelo. Uma isibambi sendlela ye-DBus sisebenzisa i-bus_verify_polkit_async(), kungase kudingeke ukuthi silinde isenzo se-Polkit ukuthi siqede. Ngemva kokuthi i-Polkit isilungile, isibambi siyabizwa futhi futhi sifinyelela idatha evele isabalalisiwe kumemori. Uma isicelo ku-Polkit sithatha isikhathi eside kakhulu, izinto ezikunqolobane zizosulwa ngaphambi kokuthi isibambi sendlela ye-DBus sibizwe okwesibili.

Phakathi kwezinsizakalo ezivumela ukuxhashazwa kokuba sengozini, i-systemd-machined iyaphawulwa, ehlinzeka nge-DBus API org.freedesktop.machine1.Image.Clone, okuholela ekugcinweni kwesikhashana kwedatha kunqolobane nokufinyelela okuvumelanayo ku-Polkit. Isixhumi esibonakalayo
org.freedesktop.machine1.Image.Image.Clone itholakala kubo bonke abasebenzisi abangenamalungelo besistimu, engaphahlaza amasevisi esistimu noma ibangele ukuthi ikhodi isetshenziswe njengempande (isibonelo sokuxhaphaza asikakaboniswa). Ikhodi evumela ukuxhashazwa kokuba sengozini kwaba kungezwe ku-systemd-machined in 2015 version uhlelo lwe-220 (I-RHEL 7.x isebenzisa i-systemd 219).

Source: opennet.ru

Engeza amazwana