ÔÚÏß×Éѯ
ÎÒ¿ÉÒÔΪÄúÌṩÄÄЩ×ÊÖú?
ÁªÏµpgµç×Ó¹ÙÍø
²éÕÒÁªÏµ·½·¨?
Inspur in Future
δÀ´£¬Òò³±ÅìÅÈ
ÓÉÓÚLinuxÄں˵Änetfilter£ºnf_tables×é¼þ±£´æÊͷźóÖØÀûÓé¶´£¬nft_verdict_init()º¯ÊýÔÊÐíÔÚ¹³×ÓÅж¨ÖÐʹÓÃÕýÖµ×÷ΪÅׯú¹ýʧ£¬µ±NF_DROP·¢³öÀàËÆÓÚNF_ACCEPTµÄÅׯú´ínf_hook_slow() º¯Êý»áµ¼ÖÂË«ÖØÊÍ·Å©¶´£¬ÍâµØ¹¥»÷ÕßÀûÓôË©¶´¿É½«ÆÕͨÓû§È¨ÏÞÌáÉýÖÁrootȨÏÞ¡£
Glibc±£´æÍâµØÌáȨ©¶´(CVE-2023-4911)£¬¸Ã©¶´Ô´ÓÚGNU C ¿âµÄ¶¯Ì¬¼ÓÔØÆ÷ ld.so ÔÚ´¦Àí GLIBC_TUNABLES Çé¿ö±äÁ¿Ê±±£´æ»º³åÇøÒç³ö£¬¿ÉÄÜÔÊÐíÍâµØ¹¥»÷ÕßÔÚÔËÐоßÓÐSUIDȨÏ޵Ķþ½øÖÆÎļþʱͨ¹ý¶ñÒâµÄ GLIBC_TUNABLES Çé¿ö±äÁ¿À´ÌáÉýϵͳȨÏÞ¡£
HTTP/2 ÐÒé±£´æ¾Ü¾øÐ§ÀÍ©¶´(CVE-2023-44487)£¬´Ë©¶´ÔÊÐí¶ñÒâ¹¥»÷ÕßÌᳫÕë¶ÔHTTP/2 ЧÀÍÆ÷µÄDDoS¹¥»÷£¬Ê¹Óà HEADERS ºÍ RST_STREAM·¢ËÍÒ»×éHTTPÇëÇ󣬲¢Öظ´´ËģʽÒÔÔÚÄ¿±ê HTTP/2 ЧÀÍÆ÷ÉÏÉú³É´ó×ÚÁ÷Á¿¡£Í¨¹ýÔÚµ¥¸öÁ¬½ÓÖдò°ü¶à¸öHEADERSºÍRST_STREAMÖ¡£¬¿ÉÄܵ¼ÖÂÿÃëÇëÇóÁ¿ÏÔÖøÔö¼Ó£¬²¢µ¼ÖÂЧÀÍÆ÷ÉϵÄCPU ÀûÓÃÂʽϸߣ¬×îÖÕµ¼ÖÂ×ÊÔ´ºÄ¾¡£¬Ôì³É¾Ü¾øÐ§ÀÍ¡£
©¶´±àºÅCVE-2023-35001£º¸Ã©¶´Ô´ÓÚLinux ÄÚºË Netfilter Ä£¿é nft_byteorder_evalº¯Êý±£´æÔ½½çдÈë©¶´¡£¾ßÓÐ CAP_NET_ADMIN ȨÏÞµÄÍâµØ¹¥»÷Õß¿ÉÒÔÀûÓøÃ©¶´½«È¨ÏÞÌáÉýÖÁROOTȨÏÞ¡£Â©¶´±àºÅCVE-2023-42753£º¸Ã©¶´Ô´ÓÚLinuxÄں˵ÄnetfilterÖÐipset×ÓÄ£¿é±£´æÊý×éÒýÓÃÔ½½ç©¶´£¬ÔÚip_set_hash_netportnetÖкêIP_SET_HASH_WITH_NET0ȱʧ»áµ¼ÖÂÅÌËãÊý×éÆ«ÒÆÊ±Ê¹ÓùýʧµÄCIDR_POS(c)ºê¡£¸Ã©¶´ÔÊÐí¹¥»÷Õßͨ¹ý¼Ó¼õ·½·¨»á¼ûÈÎÒâÄڴ棬¿ÉÄÜÔì³ÉÍâµØÌáȨ¡£
Sudo±£´æÈ¨ÏÞÌáÉý©¶´£¨CVE-2023-22809£©£¬¸Ã©¶´±£´æÓÚSudoµÄ-eÑ¡ÏÓÖÃûsudoedit£©¹¦Ð§¶ÔÓû§ÌṩµÄÇé¿ö±äÁ¿£¨Sudo_EDITOR¡¢VISUALºÍEDITOR£©ÖÐͨ±¨µÄÌØ±ð²ÎÊý´¦Àí²»µ±£¬¾ßÓÐsudoedit»á¼ûȨÏÞµÄÍâµØÓû§¿ÉÒÔͨ¹ýÔÚÒª´¦ÀíµÄÎļþÁбíÖÐÌí¼ÓÈÎÒâÌõÄ¿ºó±à¼Î´¾ÊÚȨµÄÎļþÀ´´¥·¢¸Ã©¶´£¬¿ÉÄܵ¼ÖÂȨÏÞÌáÉý¡£Èç¹ûÖ¸¶¨µÄ±à¼Æ÷°üÀ¨Ê¹ÑÚ»¤»úÖÆÊ§Ð§µÄ¡°--¡±²ÎÊý£¨ÈƹýsudoersÕ½ÂÔ£©£¬ÔòÒ×Êܸé¶´Ó°Ïì¡£
Linux kernelÌØ¶¨°æ±¾Öб£´æÒ»´¦È¨ÏÞÌáÉý©¶´£¨CVE-2022-2588£©£¬ÔÚLinuxÄÚºËµÄ net/sched/cls_route.c¹ýÂËÆ÷ʵÏÖÖпÉÒÔÖØÓÃÒÑÊͷŵÄÄڴ棬Èô±»ÍâµØ¾¹ýÉí·ÝÈÏÖ¤µÄ¹¥»÷ÕßÀûÓ㬿ÉÄܻᵼÖÂϵͳÍ߽⡢ȨÏÞÌáÉýµÈ¡£
Linux Kernel·¢Ã÷ÁËÒ»¸öÄÚºËÌáȨºÍÈÝÆ÷ÌÓÒÝ©¶´£¬Â©¶´±àºÅΪCVE-2022-0492£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´Í¨¹ýCgroups Release Agent ÈÆ¹ýLinuxÄں˵ÄÏÞÖÆ£¬ÒÔÌáÉýȨÏÞ»òÔì³ÉÈÝÆ÷ÌÓÒÝ¡£
Linux Kernel±£´æÈ¨ÏÞÌáÉý©¶´CVE-2022-27666£¬net/ipv4/esp4.c ºÍ net/ipv6/esp6.c ÖÐµÄ IPsec ESP ת»»´úÂëÖб£´æ¶Ñ»º³åÇøÒç³öÎÊÌ⣬ÀÖ³ÉÀûÓôË©¶´ÔÊÐí¾ßÓÐÆÕͨÓû§È¨ÏÞµÄÍâµØ¹¥»÷ÕßÁýÕÖÄں˶ѹ¤¾ß£¬¿ÉÒÔʵÏÖÍâµØÈ¨ÏÞÌáÉý¡£
Äþ¾²¸üÐÂÔÚFastjson 1.2.80¼°ÒÔϰ汾Öб£´æ·´ÐòÁл¯Â©¶´(CVE-2022-25845)£¬¹¥»÷Õß¿ÉÒÔÔÚÌØ¶¨Ìõ¼þÏÂÈÆ¹ýautoType¹Ø±Õ£¨Ä¬ÈÏ£©ÏÞÖÆ£¬´Ó¶ø·´ÐòÁл¯ÓÐÄþ¾²Î£º¦µÄÀà¡£
½üÈÕ£¬OpenSSL¹Ù·½Ðû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËOpenSSL¾Ü¾øÐ§ÀÍ©¶´£¨CVE-2022-0778£©¡£¸Ã©¶´ÊÇÓÉÓÚÖ¤Êé½âÎöʱʹÓÃµÄ BN_mod_sqrt() º¯Êý±£´æÒ»¸ö¹ýʧ£¬Ëü»áµ¼ÖÂÔÚ·ÇÖÊÊýµÄÇé¿öÏÂÓÀÔ¶Ñ»·¡£¿Éͨ¹ýÉú³É°üÀ¨ÎÞЧµÄÏÔʽÇúÏß²ÎÊýµÄÖ¤ÊéÀ´´¥·¢ÎÞÏÞÑ»·¡£ÓÉÓÚÖ¤Êé½âÎöÊÇÔÚÑéÖ¤Ö¤ÊéÇ©Ãû֮ǰ½øÐеģ¬Òò´ËÈκνâÎöÍⲿÌṩµÄÖ¤ÊéµÄ³ÌÐò¶¼¿ÉÄÜÊܵ½¾Ü¾øÐ§À͹¥»÷¡£