I-OpenSSH yengeza isivikelo ekuhlaselweni kwesiteshi eseceleni

U-Damien Miller (djm@) kungeziwe kukhona ukuthuthuka kwe-OpenSSH okufanele kusize ukuvikela ekuhlaselweni kwesiteshi eseceleni okuhlukahlukene okufana I-Specter, i-Meltdown, I-RowHammer и I-RAMBleed. Ukuvikela okungeziwe kuklanyelwe ukuvimbela ukutholwa kokhiye oyimfihlo otholakala ku-RAM kusetshenziswa ukuvuza kwedatha ngamashaneli ezinkampani zangaphandle.

Ingqikithi yokuvikela ukuthi okhiye abayimfihlo, uma bengasetshenziswa, babethelwa kusetshenziswa ukhiye we-symmetric, osuselwe “kukhiye wangaphambili” omkhulu ohlanganisa idatha engahleliwe (okwamanje usayizi wayo ungu-16 KB) .
Ngokombono wokusebenzisa, okhiye abayimfihlo bayabethelwa uma belayishwa kumemori bese kususwa ukubethela ngokuzenzakalelayo nangokusobala uma kusetshenziselwa amasiginesha noma uma kugcinwa/ kwenziwa uchungechunge.

Ukuze kube nokuhlasela okuyimpumelelo, abahlaseli kufanele babuyisele wonke ukhiye wangaphambili ngokunemba okuphezulu ngaphambi kokuthi bazame ukususa ukubethela ukhiye oyimfihlo ovikelwe. Kodwa-ke, isizukulwane samanje sokuhlasela sinesilinganiso sephutha sokutakula kancane kangangokuthi isamba lalawa maphutha senza ukutholwa okulungile kokhiye owabiwe kungenzeki.

Source: opennet.ru

Engeza amazwana