¡¾Íþвͨ¸æ¡¿Linux Kernelí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-3490£©Í¨¸æ
2021-08-02
Ò». Îó²î¸ÅÊö
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½ÓÐÑо¿Ö°Ô±¹ûÕæÅû¶ÁËeBPFÖеÄÒ»¸öí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-3490£©µÄϸ½ÚÐÅÏ¢ºÍPoC£¬²¢ÑÝʾʹÓôËÎó²îÔÚUbuntu 20.10 ºÍ 21.04ÉÏʵÏÖÍâµØÈ¨ÏÞÌáÉý£¬¸ÃÎó²îÊÇÓÉÓÚLinuxÄÚºËÖа´Î»²Ù×÷£¨AND¡¢OR ºÍ XOR£©µÄ eBPF ALU32 ½çÏ߸ú×ÙûÓÐ׼ȷ¸üР32 λ½çÏߣ¬Ôì³É Linux ÄÚºËÖеÄÔ½½ç¶ÁÈ¡ºÍдÈ룬´Ó¶øµ¼ÖÂí§Òâ´úÂëÖ´ÐС£¹Ù·½ÒÑÓÚ5ÔÂ11ºÅÐû²¼ÐÞ¸´°æ±¾£¬ÇëÏà¹ØÓû§ÊµÊ±½ÓÄɲ½·¥·À»¤¡£
ExtendedBerkeley Packet Filter£¨eBPF£©ÊÇÒ»ÖÖÄÚºËÊÖÒÕ£¨´ÓLinux 4.x×îÏÈ£©£¬ÔÊÐí³ÌÐòÔËÐжøÎÞÐè¸Ä±äÄÚºËÔ´´úÂë»òÌí¼ÓÌØÁíÍâÄ£¿é¡£ËüÊÇLinuxÄÚºËÖеÄÒ»ÖÖÇáÁ¿¼¶µÄɳºÐÐéÄâ»ú£¨VM£©£¬¿ÉÒÔÔÚÆäÖÐÔËÐÐʹÓÃÌØ¶¨ÄÚºË×ÊÔ´µÄBPF×Ö½ÚÂë¡£
²Î¿¼Á´½Ó£º
https://www.openwall.com/lists/oss-security/2021/05/11/11
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
Linux kernel < 5.13-rc4
Èý. Îó²î¼ì²â
3.1 °æ±¾¼ì²â
LinuxϵͳÓû§¿ÉÒÔͨ¹ýÉó²é°æÔÀ´ÅжÏÄ¿½ñϵͳÊÇ·ñÔÚÊÜÓ°Ïì¹æÄ£ÄÚ£¬Éó²é²Ù×÷ϵͳ°æ±¾ÐÅÏ¢ÏÂÁîÈçÏ£º
|
cat /proc/version |
ËÄ. Îó²î·À»¤
4.1 ¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÔÚа汾ÖÐÐÞ¸´Á˸ÃÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£ºhttps://www.kernel.org
ÒªÁìÒ»¡¢Í¨¹ýÉý¼¶LinuxϵͳÄں˵ķ½·¨¾ÙÐзÀ»¤¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/torvalds/linux/releases
ÒªÁì¶þ¡¢Linux´úÂë¿âÒÑÐû²¼²¹¶¡£¬ÇëÏà¹ØÓû§¾¡¿ìÓ¦Óô˲¹¶¡¡£
ÏêϸÐÅÏ¢¿É°Ý¼û£º
https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=049c4e13714ecbca567b4d5f6d563f05d431c80e
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







