LinuxÄÚºËVMA UAFÌáȨÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-09-28

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-17182£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ7£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Linux kernel 4.18.8¼°Ö®Ç°°æ±¾


Îó²î¸ÅÊö


Linux kernelÊÇÃÀ¹úLinux»ù½ð»áÐû²¼µÄ¿ªÔ´²Ù×÷ϵͳLinuxËùʹÓõÄÄںˡ£¡£¡£

Linux kernel 4.18.8¼°Ö®Ç°°æ±¾Öб£´æÇå¾²Îó²î¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñȡȨÏÞ¡£¡£¡£


Îó²îÑéÖ¤


EXP£ºhttps://www.exploit-db.com/exploits/45497/


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=7a9cdebdcc17e426fb5287e4a82db1dfe86339b2 


²Î¿¼Á´½Ó


https://googleprojectzero.blogspot.com/2018/09/a-cache-invalidation-bug-in-linux.html

https://www.openwall.com/lists/oss-security/2018/09/18/4

https://github.com/torvalds/linux/commit/7a9cdebdcc17e426fb5287e4a82db1dfe86339b2