¸ü¶à Ñ¡ÔñÓïÑÔ
< ·µ»ØÖ÷²Ëµ¥
Çå¾²Ô¤¾¯-Éæ¼°ºÀÔ˹ú¼Ê²¿·Ö²úÆ·µÄLinux Kernel ÍâµØȨÏÞÌáÉýÎó²î
Ô¤¾¯±àºÅ£ºINSPUR-SA-202311-001
³õʼÐû²¼Ê±¼ä£º2023-11-22 16:38:45
¸üÐÂÐû²¼Ê±¼ä£º2023-11-30 15:00:45
Îó²îȪԴ£º

¹Ù·½Ðû²¼

Îó²îÓ°Ï죺

ÍâµØȨÏÞÌáÉý

Îó²îÐÎò£º

Îó²î±àºÅCVE-2023-35001£º¸ÃÎó²îÔ´ÓÚLinux ÄÚºË Netfilter Ä£¿é nft_byteorder_evalº¯Êý±£´æÔ½½çдÈëÎó²î ¡£¾ßÓÐ CAP_NET_ADMIN ȨÏÞµÄÍâµØ¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î½«È¨ÏÞÌáÉýÖÁROOTȨÏÞ ¡£
Îó²î±àºÅCVE-2023-42753£º¸ÃÎó²îÔ´ÓÚLinuxÄں˵ÄnetfilterÖÐipset×ÓÄ£¿é±£´æÊý×éÒýÓÃÔ½½çÎó²î£¬ÔÚip_set_hash_netportnetÖкêIP_SET_HASH_WITH_NET0ȱʧ»áµ¼ÖÂÅÌËãÊý×éÆ«ÒÆʱʹÓùýʧµÄCIDR_POS(c)ºê ¡£¸ÃÎó²îÔÊÐí¹¥»÷Õßͨ¹ý¼Ó¼õ·½·¨»á¼ûí§ÒâÄڴ棬¿ÉÄÜÔì³ÉÍâµØÌáȨ ¡£

CVSSÆÀ·Ö£º

CVE V3.1 Vector(Base) Base Score V3.1 Vector(Temporal Score) Temporal Score
CVE-2023-35001 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 7.8 E:P/RL:O/RC:C 7
CVE-2023-42753 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 7.8 E:P/RL:O/RC:C 7

ÊÜÓ°Ïì²úÆ·£º

²úÆ·Ãû³Æ ÊÜÓ°Ïì°æ±¾ Éý¼¶°ü°æ±¾
AS13000 CVE-2023-35001£º
as13000 3.7.x >=3.7.21.7
as13000 3.8.x >= 3.8.7.6
as13000 3.9.x <= 3.9.8.8
CVE-2023-42753£º
as13000 >= 3.7.0.1
as13000 <= 3.9.8.8
as13000_kernel_cve-2023-35001_cve-2023-42753_patch.zip
ICS  ICS <=6.10.0 InCloudSphere-V6R10B031-b1-x86_64-S300-b1.hotfix.zip
InCloudSphere-V6R10B031-b1-x86_64-M300-b1.hotfix.zip
ICR  ICR <=6.10.0 InCloudRail-V6R10B030-b3-x86_64-M300-b1.hotfix.zip
InCloudRail-V6R10B030-b3-x86_64-S300-b1.hotfix.zip
ICOS CVE-2023-35001:
ICOS 5.8.x
CVE-2023-42753:
ICOS < 5.8
kernel-4.18.0-477.36.1.el8_8.x86_64.rpm(centos8-CVE-2023-42753)
kernel-3.10.0-1160.102.1.el7.x86_64.rpm(centos7-CVE-2023-35001)
kernel-3.10.0-957.106.1.el7.x86_64.rpm(centos7.6-CVE-2023-35001)
kernel-4.18.0-477.27.1.el8_8.x86_64.rpm (centos8-CVE-2023-35001)
kernel-4.18.0-372.75.1.1.kos5.x86_64.rpm(kos x86)
kernel-4.19.91-26.6.18.kos.aarch64.rpm(kos_aarch64)
ICM ICM 5.x
ICKS ICKS < 5.8
InCloudOS InCloudOS 6.x <= 6.8.0

ÊÖÒÕϸ½Ú£º

ÎÞ

Îó²î½â¾ö¼Æ»®£º

ÇëÓû§Ö±½ÓÁªÏµ¿Í»§·þÎñÖ°Ô±£¬»ñÈ¡²¹¶¡ÒÔ¼°Ïà¹ØµÄÊÖÒÕÖ§³Ö ¡£

FAQ£º

ÎÞ

¸üмͼ£º

20231122-V1.0-Initial Release
20231130-V1.1-Update ÔöÌíÊÜÓ°Ïì²úÆ·

ºÀÔ˹ú¼ÊÇå¾²Ó¦¼±ÏìÓ¦¶ÔÍâ·þÎñ£º
ºÀÔ˹ú¼ÊÒ»Ö±Ö÷Õž¡È«Á¦°ü¹Ü²úÆ·Óû§µÄ×îÖÕÀûÒ棬×ñÕÕÈÏÕæÈεÄÇå¾²ÊÂÎñÅû¶ԭÔò£¬²¢Í¨¹ý²úÆ·Çå¾²ÎÊÌâ´¦Öóͷ£»úÖÆ´¦Öóͷ£²úÆ·Çå¾²ÎÊÌâ ¡£
·´ÏìºÀÔ˹ú¼Ê²úÆ·Çå¾²ÎÊÌ⣺ /lcjtww/psirt/vulnerability-management/index.html#report_ldbg

»ñÈ¡ÊÖÒÕÖ§³Ö£º/lcjtww/2317452/2317456/2317460/index.html

ÉùÃ÷

±¾ÎĵµÌṩµÄËùÓÐÊý¾ÝºÍÐÅÏ¢½ö¹©²Î¿¼£¬ÇÒ"°´Ô­Ñù"Ìṩ£¬²»ÔÊÐíÈκÎÕÑʾ¡¢Ä¬Ê¾ºÍ·¨¶¨µÄµ£±££¬°üÀ¨(µ«²»ÏÞÓÚ)¶ÔÊÊÏúÐÔ¡¢ÊÊÓÃÐÔ¼°²»ÇÖȨµÄµ£±£ ¡£ÔÚÈκÎÇéÐÎÏ£¬ºÀÔ˹ú¼Ê»òÆäÖ±½Ó»ò¼ä½Ó¿ØÖƵÄ×Ó¹«Ë¾£¬»òÆ乩ӦÉÌ£¬¾ù²î³ØÈκÎÒ»·½ÒòÒÀÀµ»òʹÓñ¾ÐÅÏ¢¶øÔâÊܵÄÈκÎËðʧ¼ç¸ºÔðÈΣ¬°üÀ¨Ö±½Ó£¬¼ä½Ó£¬ÎÞÒ⣬һ¶¨µÄÉÌÒµÀûÈóËðʧ»òÌØÊâËðʧ ¡£ºÀÔ˹ú¼Ê±£´æËæʱ¸ü¸Ä»ò¸üдËÎĵµµÄȨÁ¦ ¡£

ÔÚ
Ïß
¿Í
·þ
?
Áª
ϵ
ÎÒ
ÃÇ
¡Á
ºÀÔ˹ú¼Ê-×·Çó¿µ½¡,ÄãÎÒÒ»ÆðÉú³¤ ÁªÏµºÀÔ˹ú¼Ê
ERP¡¢ÆóÒµÈí¼þ¹ºÖÃÈÈÏß
400-018-7700
ÔÆ·þÎñ²úÆ·ÏúÊÛÈÈÏß
400-607-6657
¼¯ÍÅ¿Í»§Í¶ËßÈÈÏß
400-691-8711
ÖÇÄÜÖն˲úÆ·¿Í·þÈÈÏß
400-658-6111
ÍøÕ¾µØͼ