ÔÚÏß×Éѯ
ÎÒ¿ÉÒÔΪÄúÌṩÄÄЩ×ÊÖú?
ÁªÏµyl6776ÓÀÀû¼¯ÍÅ
²éÕÒÁªÏµ·½·¨?
Inspur in Future
δÀ´£¬£¬£¬Òò³±ÐÚÓ¿
ÓÉÓÚLinuxÄں˵Änetfilter£ºnf_tables×é¼þ±£´æÊͷźóÖØÊ¹ÓÃÎó²î£¬£¬£¬nft_verdict_init()º¯ÊýÔÊÐíÔÚ¹³×ÓÅжÏÖÐʹÓÃÕýÖµ×÷ΪÑïÆú¹ýʧ£¬£¬£¬µ±NF_DROP·¢³öÀàËÆÓÚNF_ACCEPTµÄÑïÆú´ínf_hook_slow() º¯Êý»áµ¼ÖÂË«ÖØÊÍ·ÅÎó²î£¬£¬£¬ÍâµØ¹¥»÷ÕßʹÓôËÎó²î¿É½«Í¨Ë×Óû§È¨ÏÞÌáÉýÖÁrootȨÏÞ¡£¡£¡£¡£¡£
Glibc±£´æÍâµØÌáȨÎó²î(CVE-2023-4911)£¬£¬£¬¸ÃÎó²îÔ´ÓÚGNU C ¿âµÄ¶¯Ì¬¼ÓÔØÆ÷ ld.so ÔÚ´¦Öóͷ£ GLIBC_TUNABLES ÇéÐαäÁ¿Ê±±£´æ»º³åÇøÒç³ö£¬£¬£¬¿ÉÄÜÔÊÐíÍâµØ¹¥»÷ÕßÔÚÔËÐоßÓÐSUIDȨÏ޵Ķþ½øÖÆÎļþʱͨ¹ý¶ñÒâµÄ GLIBC_TUNABLES ÇéÐαäÁ¿À´ÌáÉýϵͳȨÏÞ¡£¡£¡£¡£¡£
HTTP/2 ÐÒé±£´æ¾Ü¾øÐ§ÀÍÎó²î(CVE-2023-44487)£¬£¬£¬´ËÎó²îÔÊÐí¶ñÒâ¹¥»÷ÕßÌᳫÕë¶ÔHTTP/2 ЧÀÍÆ÷µÄDDoS¹¥»÷£¬£¬£¬Ê¹Óà HEADERS ºÍ RST_STREAM·¢ËÍÒ»×éHTTPÇëÇ󣬣¬£¬²¢Öظ´´ËģʽÒÔÔÚÄ¿µÄ HTTP/2 ЧÀÍÆ÷ÉÏÌìÉú´ó×ÚÁ÷Á¿¡£¡£¡£¡£¡£Í¨¹ýÔÚµ¥¸öÅþÁ¬Öдò°ü¶à¸öHEADERSºÍRST_STREAMÖ¡£¡£¡£¡£¡£¬£¬£¬¿ÉÄܵ¼ÖÂÿÃëÇëÇóÁ¿ÏÔÖøÔöÌí£¬£¬£¬²¢µ¼ÖÂЧÀÍÆ÷ÉϵÄCPU ʹÓÃÂʽϸߣ¬£¬£¬×îÖÕµ¼ÖÂ×ÊÔ´ºÄ¾¡£¡£¡£¡£¡£¬£¬£¬Ôì³É¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£¡£
Îó²î±àºÅCVE-2023-35001£º¸ÃÎó²îÔ´ÓÚLinux ÄÚºË Netfilter Ä£¿£¿£¿£¿£¿é nft_byteorder_evalº¯Êý±£´æÔ½½çдÈëÎó²î¡£¡£¡£¡£¡£¾ßÓÐ CAP_NET_ADMIN ȨÏÞµÄÍâµØ¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î½«È¨ÏÞÌáÉýÖÁROOTȨÏÞ¡£¡£¡£¡£¡£Îó²î±àºÅCVE-2023-42753£º¸ÃÎó²îÔ´ÓÚLinuxÄں˵ÄnetfilterÖÐipset×ÓÄ£¿£¿£¿£¿£¿é±£´æÊý×éÒýÓÃÔ½½çÎó²î£¬£¬£¬ÔÚip_set_hash_netportnetÖкêIP_SET_HASH_WITH_NET0ȱʧ»áµ¼ÖÂÅÌËãÊý×éÆ«ÒÆÊ±Ê¹ÓùýʧµÄCIDR_POS(c)ºê¡£¡£¡£¡£¡£¸ÃÎó²îÔÊÐí¹¥»÷Õßͨ¹ý¼Ó¼õ·½·¨»á¼ûí§ÒâÄڴ棬£¬£¬¿ÉÄÜÔì³ÉÍâµØÌáȨ¡£¡£¡£¡£¡£
Sudo±£´æÈ¨ÏÞÌáÉýÎó²î£¨CVE-2023-22809£©£¬£¬£¬¸ÃÎó²î±£´æÓÚSudoµÄ-eÑ¡ÏÓÖÃûsudoedit£©¹¦Ð§¶ÔÓû§ÌṩµÄÇéÐαäÁ¿£¨Sudo_EDITOR¡¢VISUALºÍEDITOR£©ÖÐת´ïµÄÌØÊâ²ÎÊý´¦Öóͷ£²»µ±£¬£¬£¬¾ßÓÐsudoedit»á¼ûȨÏÞµÄÍâµØÓû§¿ÉÒÔͨ¹ýÔÚÒª´¦Öóͷ£µÄÎļþÁбíÖÐÌí¼Óí§ÒâÌõÄ¿ºó±à¼Î´¾ÊÚȨµÄÎļþÀ´´¥·¢¸ÃÎó²î£¬£¬£¬¿ÉÄܵ¼ÖÂȨÏÞÌáÉý¡£¡£¡£¡£¡£ÈôÊÇÖ¸¶¨µÄ±à¼Æ÷°üÀ¨Ê¹±£»£»£»£»£»¤»úÖÆÊ§Ð§µÄ¡°--¡±²ÎÊý£¨ÈƹýsudoersÕ½ÂÔ£©£¬£¬£¬ÔòÒ×ÊܸÃÎó²îÓ°Ïì¡£¡£¡£¡£¡£
Linux kernelÌØ¶¨°æ±¾Öб£´æÒ»´¦È¨ÏÞÌáÉýÎó²î£¨CVE-2022-2588£©£¬£¬£¬ÔÚLinuxÄÚºËµÄ net/sched/cls_route.c¹ýÂËÆ÷ʵÏÖÖпÉÒÔÖØÓÃÒÑÊͷŵÄÄڴ棬£¬£¬Èô±»ÍâµØ¾ÓÉÉí·ÝÈÏÖ¤µÄ¹¥»÷ÕßʹÓ㬣¬£¬¿ÉÄܻᵼÖÂϵͳÍ߽⡢ȨÏÞÌáÉýµÈ¡£¡£¡£¡£¡£
Linux Kernel·¢Ã÷ÁËÒ»¸öÄÚºËÌáȨºÍÈÝÆ÷ÌÓÒÝÎó²î£¬£¬£¬Îó²î±àºÅΪCVE-2022-0492£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îͨ¹ýCgroups Release Agent ÈÆ¹ýLinuxÄں˵ÄÏÞÖÆ£¬£¬£¬ÒÔÌáÉýȨÏÞ»òÔì³ÉÈÝÆ÷ÌÓÒÝ¡£¡£¡£¡£¡£
Linux Kernel±£´æÈ¨ÏÞÌáÉýÎó²îCVE-2022-27666£¬£¬£¬net/ipv4/esp4.c ºÍ net/ipv6/esp6.c ÖÐµÄ IPsec ESP ת»»´úÂëÖб£´æ¶Ñ»º³åÇøÒç³öÎÊÌ⣬£¬£¬ÀÖ³ÉʹÓôËÎó²îÔÊÐí¾ßÓÐͨË×Óû§È¨ÏÞµÄÍâµØ¹¥»÷ÕßÁýÕÖÄں˶ѹ¤¾ß£¬£¬£¬¿ÉÒÔʵÏÖÍâµØÈ¨ÏÞÌáÉý¡£¡£¡£¡£¡£
Çå¾²¸üÐÂÔÚFastjson 1.2.80¼°ÒÔϰ汾Öб£´æ·´ÐòÁл¯Îó²î(CVE-2022-25845)£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÌØ¶¨Ìõ¼þÏÂÈÆ¹ýautoType¹Ø±Õ£¨Ä¬ÈÏ£©ÏÞÖÆ£¬£¬£¬´Ó¶ø·´ÐòÁл¯ÓÐÇ徲Σº¦µÄÀà¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬OpenSSL¹Ù·½Ðû²¼Çå¾²¸üУ¬£¬£¬ÐÞ¸´ÁËOpenSSL¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2022-0778£©¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚÖ¤ÊéÆÊÎöʱʹÓÃµÄ BN_mod_sqrt() º¯Êý±£´æÒ»¸ö¹ýʧ£¬£¬£¬Ëü»áµ¼ÖÂÔÚ·ÇÖÊÊýµÄÇéÐÎÏÂÓÀÔ¶Ñ»·¡£¡£¡£¡£¡£¿£¿£¿£¿£¿Éͨ¹ýÌìÉú°üÀ¨ÎÞЧµÄÏÔʽÇúÏß²ÎÊýµÄÖ¤ÊéÀ´´¥·¢ÎÞÏÞÑ»·¡£¡£¡£¡£¡£ÓÉÓÚÖ¤ÊéÆÊÎöÊÇÔÚÑéÖ¤Ö¤ÊéÊðÃû֮ǰ¾ÙÐе쬣¬£¬Òò´ËÈÎºÎÆÊÎöÍⲿÌṩµÄÖ¤ÊéµÄ³ÌÐò¶¼¿ÉÄÜÊܵ½¾Ü¾øÐ§À͹¥»÷¡£¡£¡£¡£¡£