¡¾Ç徲ͨ¸æ¡¿LinuxÄÚºËȨÏÞÌáÉýÎó²î£¨CVE-2020-14386£©Í¨¸æ
2020-09-24
Ò». Îó²î¸ÅÊö
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²â·¢Ã÷Linux kernel ±£´æÒ»¸öȨÏÞÌáÉýÎó²î£¨CVE-2020-14386£©£¬ÓÉÓÚnet/packet/af_packet.cÔÚ´¦Öóͷ£AF_PACKETʱ±£´æÕûÊýÒç³ö£¬µ¼Ö¿ɾÙÐÐÔ½½çд´Ó¶øÊµÏÖȨÏÞÌáÉý£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î´Ó·ÇÌØÈ¨Àú³Ì»ñµÃϵͳrootȨÏÞ¡£Ê¹ÓÃÁËLinux KernelµÄopenshift/docker/kubernetesµÈÐéÄ⻯²úÆ·¿ÉÄÜ»áÊܵ½¸ÃÎó²îÓ°Ï죬µ¼ÖÂÐéÄ⻯ÌÓÒÝ£¬ÇëÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
²Î¿¼Á´½Ó£º
https://www.openwall.com/lists/oss-security/2020/09/03/3
https://access.redhat.com/security/cve/cve-2020-14386
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
4.6<= Linux kernel < 5.9-rc4
CentOS = 8
Ubuntu => 18.04
RHEL = 8
Debian = 9-10
²»ÊÜÓ°Ïì°æ±¾
Linux kernel => 5.9-rc4
Èý. Îó²î¼ì²â
3.1 °æ±¾¼ì²â
LinuxϵͳÓû§¿ÉÒÔͨ¹ýÉó²é°æÔÀ´ÅжÏÄ¿½ñϵͳÊÇ·ñÔÚÊÜÓ°Ïì¹æÄ£ÄÚ£¬Éó²é²Ù×÷ϵͳ°æ±¾ÐÅÏ¢ÏÂÁîÈçÏ£º
|
cat /proc/version |
ËÄ. Îó²î·À»¤
4.1 ¹Ù·½·À»¤²½·¥
ÒªÁìÒ»¡¢Í¨¹ýÉý¼¶LinuxϵͳÄں˵ķ½·¨¾ÙÐзÀ»¤¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/torvalds/linux/releases
ÒªÁì¶þ¡¢Linux´úÂë¿âÒÑÐû²¼²¹¶¡£¬ÇëÏà¹ØÓû§¾¡¿ìÓ¦Óô˲¹¶¡¡£
commit id£ºacf69c946233259ab4d64f8869d4037a198c7f06
ÏêϸÐÅÏ¢¿É°Ý¼û£º
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=acf69c946233259ab4d64f8869d4037a198c7f06
4.2 ÆäËû·À»¤²½·¥
Ò»¡¢¹Ø±ÕCAP_NET_RAW¹¦Ð§
RHEL8µÄ²Ù×÷°ì·¨ÈçÏ£º
|
# echo"user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf |
µ¥¸ö¿ÉÖ´ÐгÌÐò²Ù×÷°ì·¨ÈçÏ£º
|
# Éó²é³ÌÐòµÄ cap ȨÏÞ getcap /bin/ping /bin/ping cap_net_raw=ep # ɾ³ý cap_net_raw ȨÏÞ setcap cap_net_raw-ep /bin/ping # ¼ì²é getcap /bin/ping /bin/ping = |
¶þ¡¢ÊÜÓ°ÏìµÄÈÝÆ÷²úÆ·Ò²¿Éͨ¹ý¹Ø±ÕCAP_NET_RAW¹¦Ð§¾ÙÐзÀ»¤£º
Kubernetes£ºÉèÖÃPodÇå¾²Õ½ÂÔÒÔɾ³ýÔËÐÐÈÝÆ÷ÖеÄCAP_NET_RAW¹¦Ð§£¬²Î¿¼Á´½Ó£ºhttps://cloud.google.com/kubernetes-engine/docs/security-bulletins¡£
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ40¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







