ÓÉÓÚLinuxÄں˵Änetfilter£ºnf_tables×é¼þ±£´æÊͷźóÖØÀûÓ鶴£¬nft_verdict_init()º¯ÊýÔÊÐíÔÚ¹³×ÓÅж¨ÖÐʹÓÃÕýÖµ×÷ΪÅ×Æú¹ýʧ£¬µ±NF_DROP·¢³öÀàËÆÓÚNF_ACCEPTµÄÅ×Æú´ínf_hook_slow() º¯Êý»áµ¼ÖÂË«ÖØÊÍ·Å©¶´£¬ÍâµØ¹¥»÷ÕßÀûÓôË©¶´¿É½«ÆÕͨÓû§È¨ÏÞÌáÉýÖÁrootȨÏÞ¡£
Glibc±£´æÍâµØÌáȨ©¶´(CVE-2023-4911)£¬¸Ã©¶´Ô´ÓÚGNU C ¿âµÄ¶¯Ì¬¼ÓÔØÆ÷ ld.so ÔÚ´¦Àí GLIBC_TUNABLES Çé¿ö±äÁ¿Ê±±£´æ»º³åÇøÒç³ö£¬¿ÉÄÜÔÊÐíÍâµØ¹¥»÷ÕßÔÚÔËÐоßÓÐSUIDȨÏ޵Ķþ½øÖÆÎļþʱͨ¹ý¶ñÒâµÄ GLIBC_TUNABLES Çé¿ö±äÁ¿À´ÌáÉýϵͳȨÏÞ¡£
HTTP/2 ÐÒé±£´æ¾Ü¾øЧÀÍ©¶´(CVE-2023-44487)£¬´Ë©¶´ÔÊÐí¶ñÒâ¹¥»÷ÕßÌᳫÕë¶ÔHTTP/2 ЧÀÍÆ÷µÄDDoS¹¥»÷£¬Ê¹Óà HEADERS ºÍ RST_STREAM·¢ËÍÒ»×éHTTPÇëÇ󣬲¢Öظ´´ËģʽÒÔÔÚÄ¿±ê HTTP/2 ЧÀÍÆ÷ÉÏÉú³É´ó×ÚÁ÷Á¿¡£Í¨¹ýÔÚµ¥¸öÁ¬½ÓÖдò°ü¶à¸öHEADERSºÍRST_STREAMÖ¡£¬¿ÉÄܵ¼ÖÂÿÃëÇëÇóÁ¿ÏÔÖøÔö¼Ó£¬²¢µ¼ÖÂЧÀÍÆ÷ÉϵÄCPU ÀûÓÃÂʽϸߣ¬×îÖÕµ¼ÖÂ×ÊÔ´ºÄ¾¡£¬Ôì³É¾Ü¾øЧÀÍ¡£
©¶´±àºÅCVE-2023-35001£º¸Ã©¶´Ô´ÓÚLinux ÄÚºË Netfilter Ä£¿é nft_byteorder_evalº¯Êý±£´æÔ½½çдÈ멶´¡£¾ßÓÐ CAP_NET_ADMIN ȨÏÞµÄÍâµØ¹¥»÷Õß¿ÉÒÔÀûÓø鶴½«È¨ÏÞÌáÉýÖÁROOTȨÏÞ¡£
©¶´±àºÅCVE-2023-42753£º¸Ã©¶´Ô´ÓÚLinuxÄں˵ÄnetfilterÖÐipset×ÓÄ£¿é±£´æÊý×éÒýÓÃÔ½½ç©¶´£¬ÔÚip_set_hash_netportnetÖкêIP_SET_HASH_WITH_NET0ȱʧ»áµ¼ÖÂÅÌËãÊý×éÆ«ÒÆʱʹÓùýʧµÄCIDR_POS(c)ºê¡£¸Ã©¶´ÔÊÐí¹¥»÷Õßͨ¹ý¼Ó¼õ·½·¨»á¼ûÈÎÒâÄڴ棬¿ÉÄÜÔì³ÉÍâµØÌáȨ¡£
Sudo±£´æȨÏÞÌáÉý©¶´£¨CVE-2023-22809£©£¬¸Ã©¶´±£´æÓÚSudoµÄ-eÑ¡ÏÓÖÃûsudoedit£©¹¦Ð§¶ÔÓû§ÌṩµÄÇé¿ö±äÁ¿£¨Sudo_EDITOR¡¢VISUALºÍEDITOR£©ÖÐͨ±¨µÄÌرð²ÎÊý´¦Àí²»µ±£¬¾ßÓÐsudoedit»á¼ûȨÏÞµÄÍâµØÓû§¿ÉÒÔͨ¹ýÔÚÒª´¦ÀíµÄÎļþÁбíÖÐÌí¼ÓÈÎÒâÌõÄ¿ºó±à¼Î´¾ÊÚȨµÄÎļþÀ´´¥·¢¸Ã©¶´£¬¿ÉÄܵ¼ÖÂȨÏÞÌáÉý¡£Èç¹ûÖ¸¶¨µÄ±à¼Æ÷°üÀ¨Ê¹±£»¤»úÖÆʧЧµÄ¡°--¡±²ÎÊý£¨ÈƹýsudoersÕ½ÂÔ£©£¬ÔòÒ×Êܸ鶴ӰÏì¡£
Linux kernelÌض¨°æ±¾Öб£´æÒ»´¦È¨ÏÞÌáÉý©¶´£¨CVE-2022-2588£©£¬ÔÚLinuxÄÚºËµÄ net/sched/cls_route.c¹ýÂËÆ÷ʵÏÖÖпÉÒÔÖØÓÃÒÑÊͷŵÄÄڴ棬Èô±»ÍâµØ¾¹ýÉí·ÝÈÏÖ¤µÄ¹¥»÷ÕßÀûÓ㬿ÉÄܻᵼÖÂϵͳÍ߽⡢ȨÏÞÌáÉýµÈ¡£
Linux Kernel·¢Ã÷ÁËÒ»¸öÄÚºËÌáȨºÍÈÝÆ÷ÌÓÒÝ©¶´£¬Â©¶´±àºÅΪCVE-2022-0492£¬¹¥»÷Õß¿ÉÀûÓø鶴ͨ¹ýCgroups Release Agent ÈƹýLinuxÄں˵ÄÏÞÖÆ£¬ÒÔÌáÉýȨÏÞ»òÔì³ÉÈÝÆ÷ÌÓÒÝ¡£
Linux Kernel±£´æȨÏÞÌáÉý©¶´CVE-2022-27666£¬net/ipv4/esp4.c ºÍ net/ipv6/esp6.c ÖÐµÄ IPsec ESP ת»»´úÂëÖб£´æ¶Ñ»º³åÇøÒç³öÎÊÌ⣬ÀÖ³ÉÀûÓôË©¶´ÔÊÐí¾ßÓÐÆÕͨÓû§È¨ÏÞµÄÍâµØ¹¥»÷ÕßÁýÕÖÄں˶ѹ¤¾ß£¬¿ÉÒÔʵÏÖÍâµØȨÏÞÌáÉý¡£
Äþ¾²¸üÐÂÔÚFastjson 1.2.80¼°ÒÔÏ°汾Öб£´æ·´ÐòÁл¯Â©¶´(CVE-2022-25845)£¬¹¥»÷Õß¿ÉÒÔÔÚÌض¨Ìõ¼þÏÂÈƹýautoType¹Ø±Õ£¨Ä¬ÈÏ£©ÏÞÖÆ£¬´Ó¶ø·´ÐòÁл¯ÓÐÄþ¾²Î£º¦µÄÀà¡£
½üÈÕ£¬OpenSSL¹Ù·½Ðû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËOpenSSL¾Ü¾øЧÀÍ©¶´£¨CVE-2022-0778£©¡£¸Ã©¶´ÊÇÓÉÓÚÖ¤Êé½âÎöʱʹÓÃµÄ BN_mod_sqrt() º¯Êý±£´æÒ»¸ö¹ýʧ£¬Ëü»áµ¼ÖÂÔÚ·ÇÖÊÊýµÄÇé¿öÏÂÓÀԶѻ·¡£¿Éͨ¹ýÉú³É°üÀ¨ÎÞЧµÄÏÔʽÇúÏß²ÎÊýµÄÖ¤ÊéÀ´´¥·¢ÎÞÏÞÑ»·¡£ÓÉÓÚÖ¤Êé½âÎöÊÇÔÚÑéÖ¤Ö¤ÊéÇ©Ãû֮ǰ½øÐеģ¬Òò´ËÈκνâÎöÍⲿÌṩµÄÖ¤ÊéµÄ³ÌÐò¶¼¿ÉÄÜÊܵ½¾Ü¾øЧÀ͹¥»÷¡£