
ãã®ãããªå Žåã®éåžžã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã¯ã圱é¿ãåãããªããžã§ã¯ãã®ã©ã€ããµã€ã¯ã«ãæ³šææ·±ã調ã¹ãããšã§ãããšã©ãŒãã¹ã«ç¹ã«æ³šæããŠãã¡ã¢ãªãã©ã®ããã«å²ãåœãŠãããŠããããã©ã®ããã«è§£æŸãããŠããããåç §ã«ãŠã³ã¿ãŒãã©ã®ããã«æ£ããååŸããã³è§£æŸãããŠãããã確èªããŸãããã ããç§ãã¡ã®å ŽåãããŸããŸãªãªããžã§ã¯ãããã£ããã£ããããããã®ã©ã€ããµã€ã¯ã«ããã§ãã¯ããŠããã°ã¯èŠã€ãããŸããã§ããã
kmalloc-192ãã£ãã·ã¥ã¯ã«ãŒãã«ã§éåžžã«äººæ°ããããæ°åã®ç°ãªããªããžã§ã¯ããçµã¿åãããŠããŸãããã®ãã¡ã®1ã€ã®ã©ã€ããµã€ã¯ã«ã®ãã°ãããã®çš®ã®ãã°ã®æãå¯èœæ§ã®é«ãçç±ã§ãããã®ãããªãªããžã§ã¯ãããã¹ãŠãªã¹ãããã ãã§ãéåžžã«åé¡ãããããã¹ãŠããã§ãã¯ããããšã«çåã®äœå°ã¯ãããŸããããã°ã¬ããŒãã¯åŒãç¶ãå±ããŸããããçŽæ¥èª¿æ»ããŠãåå ãç¹å®ããããšã¯ã§ããŸããã§ããããã³ããå¿ èŠã§ããã
ç§ãã¡ã®åŽããããããã®ãã°ã¯ãã¡ã¢ãªã¢ã¯ã»ã¹ãšã©ãŒããã£ããããããã®çŽ æŽããããã¯ãããžãŒã§ããKASANã®éçºè ãšããŠã«ãŒãã«éçºè ã®çããµãŒã¯ã«ã§åºãç¥ãããŠããã¡ã¢ãªç®¡çã¹ãã·ã£ãªã¹ãã§ããAndreyRyabininã«ãã£ãŠèª¿æ»ãããŸããã å®éãç§ãã¡ã®ãã°ã®åå ãçºèŠããã®ã«æãé©ããã®ã¯KASANã§ããã KASANã¯å ã®RHEL7ã«ãŒãã«ã«ã¯å«ãŸããŠããŸããã§ããããAndreyã¯å¿ èŠãªããããOpenVzã«ç§»æ€ããŸãããã«ãŒãã«ã®è£œåããŒãžã§ã³ã«ã¯KASANã¯å«ãŸããŠããŸããã§ããããã«ãŒãã«ã®ãããã°ããŒãžã§ã³ã«ã¯å«ãŸããŠãããQAããã°ãèŠã€ããã®ã«ç©æ¥µçã«åœ¹ç«ã¡ãŸãã

KASANã«å ããŠããããã°ã«ãŒãã«ã«ã¯ãRedHatããç¶æ¿ããä»ã®å€ãã®ãããã°æ©èœãå«ãŸããŠããŸãããããã°ã®çµæãã«ãŒãã«ã¯ããªãé ãããšã倿ããŸããã QAã«ãããšããããã°ã«ãŒãã«ã§ã®åããã¹ãã«ã¯4åã®æéãããããŸããç§ãã¡ã«ãšã£ãŠãããã¯åºæ¬çãªããšã§ã¯ãªããããã§ããã©ãŒãã³ã¹ã枬å®ããã®ã§ã¯ãªãããã°ãæ¢ããŸãããã ãããã®ãããªé床äœäžã¯ã客æ§ã«ã¯åãå ¥ããããããããã°ã«ãŒãã«ãæ¬çªç°å¢ã«ç§»è¡ãããšããåœç€Ÿã®èŠæ±ã¯åžžã«æåŠãããŸããã
KASANã®ä»£ããã«ã圱é¿ãåããããŒãã§slub_debugãæå¹ã«ããããã«ã¯ã©ã€ã¢ã³ãã«äŸé ŒããŸãã..ããã®ãã¯ãããžãŒã«ãããã¡ã¢ãªã®ç Žæãæ€åºããããšãã§ããŸããåãªããžã§ã¯ãã«ã¬ãããŸãŒã³ãšã¡ã¢ãªãã€ãºãã³ã°ã䜿çšããŠãã¡ã¢ãªã¢ãã±ãŒã¿ã¯ãã¡ã¢ãªãå²ãåœãŠãŠè§£æŸãããã³ã«ããã¹ãŠãæ£åžžã§ãããã©ããã確èªããŸããäœãåé¡ãçºçããå Žåã¯ããšã©ãŒã¡ãã»ãŒãžãçºè¡ããæ€åºãããæå·ãå¯èœã§ããã°ä¿®æ£ããã«ãŒãã«ãåäœãç¶ç¶ã§ããããã«ããŸããããã«ããªããžã§ã¯ããæåŸã«å²ãåœãŠãŠè§£æŸãã人ã«é¢ããæ å ±ãä¿åããããããã¡ã¢ãªç Žæã®äºåŸæ€åºã®å Žåããã®ãªããžã§ã¯ãããéå»ã®äººçãã«ãã£ãã誰ããçè§£ããããšãã§ããŸãã Slub_debugã¯ãå®çšŒåã«ãŒãã«ã®ã«ãŒãã«ã³ãã³ãã©ã€ã³ã§æå¹ã«ã§ããŸããããããã®ãã§ãã¯ã¯ã¡ã¢ãªãšcpuãªãœãŒã¹ãæ¶è²»ããŸããéçºããã³QAãããã°ã®å Žåãããã¯åé¡ãããŸããããå®çšŒåã¯ã©ã€ã¢ã³ãã¯ããŸãç±å¿ã«äœ¿çšããŸããã
å幎ãçµã¡ãæ°å¹Žãè¿ã¥ããŠããŸããã KASANã䜿çšãããããã°ã«ãŒãã«ã§ã®ããŒã«ã«ãã¹ãã§ã¯åé¡ã¯æ€åºãããŸããã§ãããslub_debugãæå¹ã«ãªã£ãŠããããŒããããã°ã¬ããŒãã¯åä¿¡ãããŸããã§ãããåææã«äœãèŠã€ããããåé¡ãèŠã€ãããŸããã§ãããã¢ã³ãã¬ã€ã¯ä»ã®ã¿ã¹ã¯ãç©ãã§ããŸããããããã©ããããã®ã£ããããããæ¬¡ã®ãã°ã¬ããŒããåæããããã«æç€ºãããŸããã
ã¯ã©ãã·ã¥ãã³ããåæããåŸãåé¡ã®ããkmalloc-192ãªããžã§ã¯ããããã«çºèŠããŸããããã®ã¡ã¢ãªã¯ãããçš®ã®ãŽããå¥ã®ã¿ã€ãã®ãªããžã§ã¯ãã«å±ããæ å ±ã§ãã£ã±ãã§ãããè§£æŸåŸã®äœ¿çšã®çµæãšéåžžã«äŒŒãŠããŸããããåææã®æå·ãããªããžã§ã¯ãã®ã©ã€ããµã€ã¯ã«ãæ³šææ·±ã調ã¹ããšãããçããããã®ã¯äœãèŠã€ãããŸããã§ããã
ç§ã¯å€ããã°ã¬ããŒãã調ã¹ãŠãããã«ããã€ãã®æããããèŠã€ããããšããŸãããã圹ã«ç«ã¡ãŸããã§ããã
æçµçã«ç§ã¯èªåã®ãã°ã«æ»ããåã®ãªããžã§ã¯ããèŠå§ããŸããããŸãã䜿çšãããŠããããšã倿ããŸãããããã®å 容ããã¯å®å šã«çè§£ã§ããŸããã§ããã宿°ã颿°ãŸãã¯ä»ã®ãªããžã§ã¯ããžã®åç §ã¯ãããŸããã§ããããã®ãªããžã§ã¯ããžã®æ°äžä»£ã®åç §ã远跡ããåŸãç§ã¯æçµçã«ãããããçž®å°ãããããããããã§ããããšã«æ°ä»ããŸããããã®ãªããžã§ã¯ãã¯ãã³ã³ããã¡ã¢ãªãè§£æŸããããã®æé©åææ³ã®äžéšã§ããããã®ãã¯ãããžãŒã¯ããšããšç§ãã¡ã®ã«ãŒãã«ã®ããã«éçºãããŸããããåŸã«ãã®äœè ã§ããKirillTkhaiããããLinuxã¡ã€ã³ã©ã€ã³ã«ã³ãããããŸããã
ãçµæã¯ãããã©ãŒãã³ã¹ãå°ãªããšã548åã«åäžããããšã瀺ããŠããŸããã
æ°åã®ãã®ãããªãããã¯ãå ã®å®å®ããRHEL7ã«ãŒãã«ãè£å®ããVirtuozzoã«ãŒãã«ããã¹ãã£ã³ã°æ¥è ã«ãšã£ãŠå¯èœãªéã䟿å©ã«ããŸããå¯èœãªéããéçºå 容ãã¡ã€ã³ã©ã€ã³ã«éä¿¡ããããã«ããŠããŸããããã«ãããã³ãŒããè¯å¥œãªç¶æ ã«ç¶æãããããªããŸãã
ãªã³ã¯ããã©ããšãããããããã説æããæ§é ãèŠã€ãããŸãããèšè¿°åã¯ãããããããã®ãµã€ãºã¯240ãã€ãã§ããå¿ èŠããããšèããŠããŸããããå®éã«ã¯ãªããžã§ã¯ãã¯kmalloc-192ãã£ãã·ã¥ããå²ãåœãŠãããŠãããããããã¯ãŸã£ããåœãŠã¯ãŸããŸããã§ããã
ãã³ãŽïŒ
ãããããããæäœãã颿°ã¯ãäžéãè¶ ããŠã¡ã¢ãªã«ã¢ã¯ã»ã¹ããæ¬¡ã®ãªããžã§ã¯ãã®å 容ã倿Žããå¯èœæ§ãããããšã倿ããŸãããç§ã®å Žåããªããžã§ã¯ãã®å é ã«refcountããããããããããããããç¡å¹ã«ãããšããã®åŸã®ãããã«ãã£ãŠãªããžã§ã¯ããçªç¶è§£æŸãããŸããããã®åŸãã¡ã¢ãªãæ°ãããªããžã§ã¯ãã«æ°ãã«å²ãåœãŠããããã®åæåã¯å€ããªããžã§ã¯ãã®ã³ãŒãã«ãã£ãŠã¬ããŒãžãšããŠèªèãããé ããæ©ããå¿ ç¶çã«ããŒãã®ã¯ã©ãã·ã¥ã«ã€ãªãããŸããã

ã³ãŒãã®äœæè ã«çžè«ã§ãããšäŸ¿å©ã§ãã
ããªã«ãšã®åœŒã®ã³ãŒããèŠããšãæ€åºãããäžäžèŽã®æ ¹æ¬çãªåå ãããã«èŠã€ãããŸãããã³ã³ããã®æ°ãå¢ãããšããããããããå¢ããã¯ãã§ãããã±ãŒã¹ã®1ã€ãçç¥ããããããµã€ãºå€æŽãããããããã¹ãããããããšããããŸãããããŒã«ã«ãã¹ãã§ã¯ããã®ç¶æ³ã¯èŠã€ãããŸããã§ãããKirillãã¡ã€ã³ã©ã€ã³ã«éä¿¡ãããããã®ããŒãžã§ã³ã§ã¯ãã³ãŒããåèšèšããããã°ã¯ãããŸããã§ããã
4åã®è©Šè¡ã§ãKirillãšç§ã¯ååããŠãã®ãããªããããäœæãã1ãæéããŒã«ã«ãã¹ãã§å®è¡ãã2ææ«ã«åºå®ã«ãŒãã«ã®ã¢ããããŒãããªãªãŒã¹ããŸãããç§ãã¡ã¯ä»ã®ã¯ã©ãã·ã¥ãã³ããéžæçã«ãã§ãã¯ããè¿æã§ééã£ããããããããèŠã€ããåå©ãç¥ããéããªå Žæã§å€ããã°ãæžãçããŸããã
ããããèå©ã¯ã©ãã©ãèœã¡ãŠãããŸããããããã®çš®é¡ã®ãã°ã¬ããŒãã®çްæµã¯çž®å°ããŸããããå®å šã«æ¯æžããŠããŸããã
äžè¬çã«ãããã¯äºæ³ãããŠããŸãããç§ãã¡ã®ã¯ã©ã€ã¢ã³ãã¯ãã¹ãã£ã³ã°æ¥è ã§ããåèµ·å==ããŠã³ã¿ã€ã ==ãéã倱ã£ãã®ã§ã圌ãã¯ããŒãã®åèµ·åã匷ãå«ããŸãããŸããã«ãŒãã«ãé »ç¹ã«ãªãªãŒã¹ããããšã奜ãã§ã¯ãããŸãããã¢ããããŒãã®å ¬åŒãªãªãŒã¹ã¯ããªãé¢åãªæé ã§ãããããŸããŸãªãã¹ããå®è¡ããå¿ èŠããããŸãããããã£ãŠãæ°ããå®å®ããã«ãŒãã«ã¯çŽååæããšã«ãªãªãŒã¹ãããŸãã
ã¯ã©ã€ã¢ã³ãã®çç£ããŒãã«ãã°ä¿®æ£ãè¿ éã«é ä¿¡ããããã«ãReadyKernelã©ã€ããããã䜿çšããŠããŸããç§ã®æèŠã§ã¯ãç§ãã¡ä»¥å€ã®èª°ããããããŸããã Virtuozzo 7ã¯ãã©ã€ããããã䜿çšããããã«éåžžãšã¯ç°ãªãæŠç¥ã䜿çšããŠããŸãã
éåžžãlifepatchã¯ã»ãã¥ãªãã£ã®ã¿ã§ããç§ãã¡ã®åœã§ã¯ãä¿®æ£ã®3/4ã¯ãã°ä¿®æ£ã§ããã客æ§ããã§ã«ééããããŸãã¯å°æ¥ç°¡åã«ééããå¯èœæ§ã®ãããã°ã®ä¿®æ£ãäºå®äžããã®ãããªããšã¯é åžãããã«å¯ŸããŠã®ã¿è¡ãããšãã§ããŸãããŠãŒã¶ãŒããã®ãã£ãŒãããã¯ããªããã°ããŠãŒã¶ãŒã«ãšã£ãŠäœãéèŠã§äœãéèŠã§ãªãããçè§£ããããšã¯äžå¯èœã§ãã
ã©ã€ããããã¯ç¢ºãã«äžèœè¬ã§ã¯ãããŸãããäžè¬ã«ããã¹ãŠãé£ç¶ããŠãããããããšã¯äžå¯èœã§ãããã®ãã¯ãããžãŒã§ã¯èš±å¯ãããŠããŸãããæ°ããæ©èœããã®æ¹æ³ã§è¿œå ãããŸããããã ãããã°ã®å€§éšåã¯ãã©ã€ããããã«æé©ãªæãåçŽãª1è¡ã®ãããã§ä¿®æ£ãããŠããŸããããè€éãªã±ãŒã¹ã§ã¯ãå ã®ããããããã¡ã€ã«ã§äœæçã«å€æŽãããå¿ èŠããããã©ã€ããããã®ä»çµã¿ã«ãã°ãããå ŽåããããŸãããã©ã€ãããããŠã£ã¶ãŒãã®ZhenyaShatokhinã¯åœŒã®ä»äºãå®å šã«ç¥ã£ãŠããŸããæè¿ãäŸãã°ã圌ã¯çºæããŸããkpatchã®é æçãªãã°ãããã«ã€ããŠã¯ãæ£åœãªçç±ãããéåžžã¯å¥ã®ãªãã©ãæžã䟡å€ããããŸãã
é©åãªãã°ä¿®æ£ãèç©ããããšãéåžžã¯1ã2é±éã«1åãZhenyaã¯å¥ã®äžé£ã®ReadyKernelã©ã€ãããããèµ·åããŸãããªãªãŒã¹åŸã圌ãã¯å³åº§ã«ã¯ã©ã€ã¢ã³ãããŒãã«é£ãã§ãç§ãã¡ããã§ã«ç¥ã£ãŠããã¬ãŒããžã®æ»æãé²ããŸãããããŠãã¯ã©ã€ã¢ã³ãããŒããåèµ·åããã«ããããã¹ãŠããããŠãäžå¿ èŠã«ã«ãŒãã«ãé »ç¹ã«ãªãªãŒã¹ããŸããç¶ç¶çãªã¡ãªããã
ãã ããã©ã€ãããããã¯ã©ã€ã¢ã³ãã«å°çããã®ãé ãããããšããããããŸããã¯ããŒãºããåé¡ã¯ãã§ã«çºçããŠããŸãããããã§ãããŒãã¯ãŸã ã¯ã©ãã·ã¥ããŠããŸããã
ãã®ããããã§ã«ä¿®æ£ããåé¡ãå«ãæ°ãããã°ã¬ããŒãã®åºçŸã¯ãç§ãã¡ã«ãšã£ãŠäºæ³å€ã§ã¯ãããŸããã§ãããããããäœåºŠãè§£æãããšãããªãã¿ã®çç¶ãçŸããŸãããå€ãã«ãŒãã«ãkmalloc-192ã®ã¬ããŒãžããã®åã®ãééã£ãããããããããããã³ä¿®æ£ãããã¢ã³ããŒããŸãã¯é å»¶ããŒããããã©ã€ããããã§ãã
ãã®ãããªã±ãŒã¹ã®1ã€ã¯ãFastVPSã®OVZ-7188ã§ã2ææ«ã«ç§ãã¡ã«å±ããŸããã ããã°ã¬ããŒããããããšãããããŸããããæãã¿ç³ãäžããŸããæ¢ç¥ã®åé¡ãšããã«éåžžã«äŒŒãŠããŸãã OpenVZã«ã©ã€ããããããªãã®ã¯æ®å¿µã§ããå®å®ããã«ãŒãã«ã®ãªãªãŒã¹ãåŸ ã€ããVirtuozzoã«åãæ¿ãããããã°ä¿®æ£ã®ããäžå®å®ãªã«ãŒãã«ã䜿çšããŠãã ãããã
ãã°ã¬ããŒãã¯ãOpenVZãæäŸããæã䟡å€ã®ãããã®ã®1ã€ã§ãããããã調æ»ããããšã§ã倪ã£ãã¯ã©ã€ã¢ã³ããä»å ¥ããåã«æ·±å»ãªåé¡ãèŠã€ããæ©äŒãåŸãããŸãããããã£ãŠãæ¢ç¥ã®åé¡ã«ãããããããã¯ã©ãã·ã¥ãã³ããå ¥åããããã«äŸé ŒããŸããã
ãããã®æåã®ãã®ãè§£æããããšã¯ç§ã幟åèœèãããŸããïŒãæ²ãã£ããkmalloc-192ãªããžã§ã¯ãã®åã®ãééã£ããããããããã¯èŠã€ãããŸããã§ããã
å°ãåŸãåé¡ã¯æ°ããã«ãŒãã«ã§åçŸãããŸããããããŠãå¥ã®ãå¥ã®ããããŠå¥ã®ã
ãã£ãšïŒ
ã©ãããŠïŒæªä¿®æ£ïŒåææãå確èªããŸããããã¹ãŠåé¡ãªããããããé©çšãããäœã倱ãããŠããŸããã
åã³è æïŒåãå Žæã§ïŒ
ç§ã¯ãããããäžåºŠçè§£ããªããã°ãªããŸããã§ããã

ïŒããã¯äœã§ããïŒãããåç §ããŠãã ããïŒ
æ°ããã¯ã©ãã·ã¥ãã³ãã®ããããã§ã調æ»ã¯åã³kmalloc-192ãªããžã§ã¯ãã«ééããŸãããäžè¬ã«ããã®ãããªãªããžã§ã¯ãã¯éåžžã«æ£åžžã«èŠããŸãããããªããžã§ã¯ãã®æåã«ãæ¯åééã£ãã¢ãã¬ã¹ãèŠã€ãããŸããããªããžã§ã¯ãã®é¢ä¿ã远跡ãããšãã¢ãã¬ã¹ã®2ã€ã®å éšãã€ããç¡å¹ã«ãªã£ãŠããããšãããããŸããã
in all cases corrupted pointer contains nulls in 2 middle bytes: (mask 0xffffffff0000ffff)
0xffff9e2400003d80
0xffff969b00005b40
0xffff919100007000
0xffff90f30000ccc0
ãªã¹ããããæåã®ã±ââãŒã¹ã§ã¯ããééã£ããã¢ãã¬ã¹0xffff9e2400003d80ã®ä»£ããã«ããæ£ãããã¢ãã¬ã¹0xffff9e24740a3d80ãå¿ èŠã§ãããä»ã®å Žåã«ãåæ§ã®ç¶æ³ãèŠãããŸããã
ããã€ãã®ç¡é¢ä¿ãªã³ãŒãã2ãã€ãã§ãªããžã§ã¯ããç¡å¹ã«ããããšã倿ããŸãããæãå¯èœæ§ã®é«ãã·ããªãªã¯ãè§£æŸåŸã®äœ¿çšã§ãããªããžã§ã¯ããè§£æŸãããåŸãæåã®ãã€ãã®äžéšã®ãã£ãŒã«ãããŒãã«ãªããŸããæãé »ç¹ã«äœ¿çšããããªããžã§ã¯ãã確èªããŸããããçããããã®ã¯èŠã€ãããŸããã§ãããåã³è¡ãæ¢ãŸãã
FastVPSç§ãã¡ã®èŠæ±ã§ãKASANã䜿çšããŠãããã°ã«ãŒãã«ã1é±éå®è¡ããŸããããããã¯åœ¹ã«ç«ã¡ãŸããã§ãããåé¡ã¯åçŸãããŸããã§ããã slub_debugã®ç»é²ãäŸé ŒããŸããããåèµ·åãå¿ èŠã§ãåŠçã«æéãããããŸããã 3æãã4æã«ãããŒãã¯ããã«æ°åã¯ã©ãã·ã¥ããŸããããslub_debugããªãã«ãªã£ãŠãããããã«ãã£ãŠæ°ããæ å ±ãåŸãããŸããã§ããã
ãããŠãèœã¡çãããããåé¡ã®åçŸãæ¢ãŸããŸããã 4æãçµããã5æãéããŸãã-æ°ããæ»ã¯ãããŸããã§ããã
åŸ æ©ã¯6æ7æ¥ã«çµäºããŸãããæçµçã«ãslub_debugãæå¹ã«ããŠåé¡ãã³ã¢ã«çºçããŸããã slub_debugãªããžã§ã¯ããè§£æŸãããšãã«ã¬ãããŸãŒã³ããã§ãã¯ããŠãããšãã«ãäžéãè¶ ãã2ã€ã®ãŒããã€ããèŠã€ãããŸãããèšãæããã°ãããã¯è§£æŸåŸã®äœ¿çšã§ã¯ãªããåã®ãªããžã§ã¯ããåã³åå ã§ããããšã倿ããŸãããéåžžã®å€èŠ³ã®æ§é äœnf_ct_extããããŸããããã®æ§é ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã䜿çšãããããã¯ãŒã¯æ¥ç¶ã®èª¬æã§ããæ¥ç¶è¿œè·¡ãåç §ããŸãã
ãããããªããããèµ·ãã£ãã®ãã¯ãŸã æããã§ã¯ãããŸããã§ããã
ç§ã¯conntrackãèŠãå§ããŸããïŒèª°ããéããŠããããŒã1720ã§ipv6ã䜿çšããŠã³ã³ããã®1ã€ãããã¯ããŸãããããŒããšãããã³ã«ã§ã察å¿ããnf_conntrack_helperãèŠã€ããŸããã
static struct nf_conntrack_helper nf_conntrack_helper_q931[] __read_mostly = {
{
.name = "Q.931",
.me = THIS_MODULE,
.data_len = sizeof(struct nf_ct_h323_master),
.tuple.src.l3num = AF_INET, <<<<<<<< IPv4
.tuple.src.u.tcp.port = cpu_to_be16(Q931_PORT),
.tuple.dst.protonum = IPPROTO_TCP,
.help = q931_help,
.expect_policy = &q931_exp_policy,
},
{
.name = "Q.931",
.me = THIS_MODULE,
.tuple.src.l3num = AF_INET6, <<<<<<<< IPv6
.tuple.src.u.tcp.port = cpu_to_be16(Q931_PORT),
.tuple.dst.protonum = IPPROTO_TCP,
.help = q931_help,
.expect_policy = &q931_exp_policy,
},
};
æ§é ãæ¯èŒãããšãipv6ãã«ããŒã.data_lenãå®çŸ©ããŠããªãããšã«æ°ä»ããŸãããç§ã¯ãããã©ãããæ¥ãã®ããçè§£ããããã«gitã«å ¥ãã2012幎ã®ããããçºèŠããŸããã
commit 1afc56794e03229fa53cfa3c5012704d226e1dec
äœæè ïŒPablo Neira Ayuso <pablo@netfilter.org>
æ¥ä»ïŒThu Jun 7 12:11:50 2012 +0200
netfilterïŒnf_ct_helperïŒå¯å€é·ãã«ããŒãã©ã€ããŒãããŒã¿ã®å®è£
ãã®ãããã¯ãæ°ããå¯å€é·conntrackæ¡åŒµæ©èœã䜿çšããŸãã
ãã¹ãŠã®
ãã«ããŒãã©ã€ããŒãããŒã¿æ å ±ãå«ããŠããªã³nf_conntrack_helpã䜿çšãã代ããã«
ããã©ã€ããŒããã«ããŒããŒã¿ãæ ŒçŽããããã«å¯å€é·é åãå²ãåœãŠãŸãã
ãã®ãããã«ã¯ãæ¢åã®ãã¹ãŠã®ãã«ããŒã®å€æŽãå«ãŸããŠããŸãã
ãŸããã³ã³ãã€ã«ãåé¿ããããã«ãããã€ãã®includeããããŒãå«ãŸããŠããŸã
èŠåã
ãããã«ããããã«ããŒã«æ°ãã.data_lenãã£ãŒã«ãã远å ãããŸãããããã¯ã察å¿ãããããã¯ãŒã¯æ¥ç¶ãã³ãã©ãŒã«å¿ èŠãªã¡ã¢ãªéã瀺ããŠããŸãããããã¯ããã®æç¹ã§å©çšå¯èœãªãã¹ãŠã®nf_conntrack_helpersã«å¯ŸããŠ.data_lenãå®çŸ©ããããšã«ãªã£ãŠããããç§ãèŠã€ããæ§é ãèŠéããŠããã
ãã®çµæãipv6ãä»ãããªãŒãã³ããŒã1720ãžã®æ¥ç¶ãq931_helpïŒïŒé¢æ°ãèµ·åãã誰ãã¡ã¢ãªãå²ãåœãŠãŠããªãæ§é ã«æžã蟌ãã ããšã倿ããŸãããåçŽãªããŒãã¹ãã£ã³ã§æ°ãã€ããç¡å¹ã«ãªããéåžžã®ãããã³ã«ã¡ãã»ãŒãžã®éä¿¡ã«ããæ§é ãããæå³ã®ããæ å ±ã§ãã£ã±ãã«ãªããŸãããããããã«ãããä»ã®èª°ãã®ã¡ã¢ãªãæŠãåããé ããæ©ãããããããŒãã®ã¯ã©ãã·ã¥ã«ã€ãªãããŸããã
Florian Westphalã¯ã2017幎ã«ã³ãŒããåèšèšããŸãã.data_lenãåé€ãããšãç§ãçºèŠããåé¡ã¯èŠéããããŸããã
çŸåšã®Linuxã«ãŒãã«ã®ã¡ã€ã³ã©ã€ã³ã§ãã°ãæ€åºãããªããªã£ãã«ãããããããåé¡ã¯ãçŸåšã®RHEL7 / CentOS7ãSLES 11ããã³12ãOracle Unbreakable Enterprise Kernel 3ããã³4ãDebian 8ããã³9ãããã³ãå«ã倿°ã®Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã®ã«ãŒãã«ã«ç¶æ¿ãããŸããã Ubuntu14.04ããã³16.04LTSã
ãã°ã¯ãã«ãŒãã«ãšå ã®RHEL7ã®äž¡æ¹ã®ãã¹ãããŒãã§ç°¡åã«åçŸãããŸãããæç€ºçãªã»ãã¥ãªãã£ïŒãªã¢ãŒã管çãããã¡ã¢ãªã®ç Žæã 1720 ipv6ããŒããéããŠããå Žæ-äºå®äžãæ»ã®pingã
6æ9æ¥ããããŸããªèª¬æãå«ã1è¡ã®ããããäœæããã¡ã€ã³ã©ã€ã³ã«éä¿¡ããŸããã詳现ãªèª¬æãRedHat Bugzillaã«éä¿¡ããRed HatSecurityã«åå¥ã«æžã蟌ã¿ãŸããã
ç§ã®åå ãªãã«ãããªãã€ãã³ããå±éãããŸããã
6æ15æ¥ãZhenyaShatokhinã¯å€ãã«ãŒãã«çšã®ReadyKernelã©ã€ããããããªãªãŒã¹ããŸããã
https://readykernel.com/patch/Virtuozzo-7/readykernel-patch-131.10-108.0-1.vl7/
6æ18æ¥ã«ãVirtuozzoãšOpenVzã§æ°ããå®å®ããã«ãŒãã«ããªãªãŒã¹ããŸããã
https://virtuozzosupport.force.com/s/article/VZA-2020-043
6æ24æ¥ãRed HatSecurityã¯CVEIDããã°ã«å²ãåœãŠãŸãã
https://access.redhat.com/security/cve/CVE-2020-14305
åé¡ç°åžžã«é«ãCVSSv3ã¹ã³ã¢8.1ã§äžçšåºŠã®åœ±é¿ãåããæ¬¡ã®æ°æ¥éã§ä»ã®
SUSEãã£ã¹ããªãã¥ãŒã·ã§ã³ããããªãã¯ããããã°https://bugzilla.suse.com/show_bug.cgi?id=CVE-2020-14305
Debian httpsïŒ/ /security-tracker.debian.org/tracker/CVE-2020-14305
Ubuntuhttps://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-14305.html
7æ6æ¥ãKernelCareã¯åœ±é¿ãåãããã£ã¹ããªãã¥ãŒã·ã§ã³ã®ã©ã€ããããããªãªãŒã¹ããŸããã
https://blog.kernelcare.com/new-kernel-vulnerability-found-by-virtuozzo-live-patched-by-kernelcare
7æ9æ¥ã«ããã®åé¡ã¯å®å®ããLinuxã«ãŒãã«4.9.230ããã³4.4.230ã§ä¿®æ£ãããŸããã
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=linux-4.9.y&id=396ba2fc4f27ef6c44bbc0098bfddf4da76dc4c9
ãã ãããã£ã¹ããªãã¥ãŒã·ã§ã³ã¯ãŸã 穎ãå¡ãã§ããŸãã..ã
ãã»ããã³ã¹ãã£ã¢ããšç§ã¯ããŒãããŒã®ã³ã¹ãã£ã¢ã»ã³ã¬ã³ã³ã«èšããŸãããç§ãã¡ã®æ®»ã¯åãç«å£ã«2ååœãã£ãïŒåånepoymiã«äŒã£ããšããç§ãš1人ã®ãªããžã§ã¯ãã®çµãããè¶ ããã¢ã¯ã»ã¹ããããããã§2åç¶ããŠèšªåããŸãããæããŠãã ãããããã¯äºä¹ç¢ºçã®ãããªãã®ã§ããïŒãŸãã¯æ£æ¹åœ¢ã§ã¯ãããŸãããïŒ
-確çã¯äºä¹ã§ããã¯ããããããããã§ããªãã¯èŠãªããã°ãªããŸãã-ã©ã®ãããªã€ãã³ãã確çã§ããïŒç°åžžãªãã°ã2åç¶ããŠçºçããã€ãã³ãã®äºä¹ç¢ºçã䞊ãã§ããŸãã
ããŠãã³ã¹ãã£ã¢ã¯è³¢ãã§ãã圌ã¯ããç¥ã£ãŠããŸãã