ÓÉÓÚLinuxÄں˵Änetfilter£ºnf_tables×é¼þ±£´æÊͷźóÖØʹÓÃÎó²î£¬nft_verdict_init()º¯ÊýÔÊÐíÔÚ¹³×ÓÅжÏÖÐʹÓÃÕýÖµ×÷ΪÑïÆú¹ýʧ£¬µ±NF_DROP·¢³öÀàËÆÓÚNF_ACCEPTµÄÑïÆú´ínf_hook_slow() º¯Êý»áµ¼ÖÂË«ÖØÊÍ·ÅÎó²î£¬ÍâµØ¹¥»÷ÕßʹÓôËÎó²î¿É½«Í¨Ë×Óû§È¨ÏÞÌáÉýÖÁrootȨÏÞ¡£
Glibc±£´æÍâµØÌáȨÎó²î(CVE-2023-4911)£¬¸ÃÎó²îÔ´ÓÚGNU C ¿âµÄ¶¯Ì¬¼ÓÔØÆ÷ ld.so ÔÚ´¦Öóͷ£ GLIBC_TUNABLES ÇéÐαäÁ¿Ê±±£´æ»º³åÇøÒç³ö£¬¿ÉÄÜÔÊÐíÍâµØ¹¥»÷ÕßÔÚÔËÐоßÓÐSUIDȨÏ޵Ķþ½øÖÆÎļþʱͨ¹ý¶ñÒâµÄ GLIBC_TUNABLES ÇéÐαäÁ¿À´ÌáÉýϵͳȨÏÞ¡£
HTTP/2 ÐÒé±£´æ¾Ü¾ø·þÎñÎó²î(CVE-2023-44487)£¬´ËÎó²îÔÊÐí¶ñÒâ¹¥»÷ÕßÌᳫÕë¶ÔHTTP/2 ·þÎñÆ÷µÄDDoS¹¥»÷£¬Ê¹Óà HEADERS ºÍ RST_STREAM·¢ËÍÒ»×éHTTPÇëÇ󣬲¢Öظ´´ËģʽÒÔÔÚÄ¿µÄ HTTP/2 ·þÎñÆ÷ÉÏÌìÉú´ó×ÚÁ÷Á¿¡£Í¨¹ýÔÚµ¥¸öÅþÁ¬Öдò°ü¶à¸öHEADERSºÍRST_STREAMÖ¡£¬¿ÉÄܵ¼ÖÂÿÃëÇëÇóÁ¿ÏÔÖøÔöÌí£¬²¢µ¼Ö·þÎñÆ÷ÉϵÄCPU ʹÓÃÂʽϸߣ¬×îÖÕµ¼ÖÂ×ÊÔ´ºÄ¾¡£¬Ôì³É¾Ü¾ø·þÎñ¡£
Îó²î±àºÅCVE-2023-35001£º¸ÃÎó²îÔ´ÓÚLinux ÄÚºË Netfilter Ä£¿é nft_byteorder_evalº¯Êý±£´æÔ½½çдÈëÎó²î¡£¾ßÓÐ CAP_NET_ADMIN ȨÏÞµÄÍâµØ¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î½«È¨ÏÞÌáÉýÖÁROOTȨÏÞ¡£
Îó²î±àºÅCVE-2023-42753£º¸ÃÎó²îÔ´ÓÚLinuxÄں˵ÄnetfilterÖÐipset×ÓÄ£¿é±£´æÊý×éÒýÓÃÔ½½çÎó²î£¬ÔÚip_set_hash_netportnetÖкêIP_SET_HASH_WITH_NET0ȱʧ»áµ¼ÖÂÅÌËãÊý×éÆ«ÒÆʱʹÓùýʧµÄCIDR_POS(c)ºê¡£¸ÃÎó²îÔÊÐí¹¥»÷Õßͨ¹ý¼Ó¼õ·½·¨»á¼ûí§ÒâÄڴ棬¿ÉÄÜÔì³ÉÍâµØÌáȨ¡£
Sudo±£´æȨÏÞÌáÉýÎó²î£¨CVE-2023-22809£©£¬¸ÃÎó²î±£´æÓÚSudoµÄ-eÑ¡ÏÓÖÃûsudoedit£©¹¦Ð§¶ÔÓû§ÌṩµÄÇéÐαäÁ¿£¨Sudo_EDITOR¡¢VISUALºÍEDITOR£©ÖÐת´ïµÄÌØÊâ²ÎÊý´¦Öóͷ£²»µ±£¬¾ßÓÐsudoedit»á¼ûȨÏÞµÄÍâµØÓû§¿ÉÒÔͨ¹ýÔÚÒª´¦Öóͷ£µÄÎļþÁбíÖÐÌí¼Óí§ÒâÌõÄ¿ºó±à¼Î´¾ÊÚȨµÄÎļþÀ´´¥·¢¸ÃÎó²î£¬¿ÉÄܵ¼ÖÂȨÏÞÌáÉý¡£ÈôÊÇÖ¸¶¨µÄ±à¼Æ÷°üÀ¨Ê¹±£»¤»úÖÆʧЧµÄ¡°--¡±²ÎÊý£¨ÈƹýsudoersÕ½ÂÔ£©£¬ÔòÒ×ÊܸÃÎó²îÓ°Ïì¡£
Linux kernelÌض¨°æ±¾Öб£´æÒ»´¦È¨ÏÞÌáÉýÎó²î£¨CVE-2022-2588£©£¬ÔÚLinuxÄÚºËµÄ net/sched/cls_route.c¹ýÂËÆ÷ʵÏÖÖпÉÒÔÖØÓÃÒÑÊͷŵÄÄڴ棬Èô±»ÍâµØ¾ÓÉÉí·ÝÈÏÖ¤µÄ¹¥»÷ÕßʹÓ㬿ÉÄܻᵼÖÂϵͳÍ߽⡢ȨÏÞÌáÉýµÈ¡£
Linux Kernel·¢Ã÷ÁËÒ»¸öÄÚºËÌáȨºÍÈÝÆ÷ÌÓÒÝÎó²î£¬Îó²î±àºÅΪCVE-2022-0492£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îͨ¹ýCgroups Release Agent ÈƹýLinuxÄں˵ÄÏÞÖÆ£¬ÒÔÌáÉýȨÏÞ»òÔì³ÉÈÝÆ÷ÌÓÒÝ¡£
Linux Kernel±£´æȨÏÞÌáÉýÎó²îCVE-2022-27666£¬net/ipv4/esp4.c ºÍ net/ipv6/esp6.c ÖÐµÄ IPsec ESP ת»»´úÂëÖб£´æ¶Ñ»º³åÇøÒç³öÎÊÌ⣬ÀÖ³ÉʹÓôËÎó²îÔÊÐí¾ßÓÐͨË×Óû§È¨ÏÞµÄÍâµØ¹¥»÷ÕßÁýÕÖÄں˶ѹ¤¾ß£¬¿ÉÒÔʵÏÖÍâµØȨÏÞÌáÉý¡£
Çå¾²¸üÐÂÔÚFastjson 1.2.80¼°ÒÔÏ°汾Öб£´æ·´ÐòÁл¯Îó²î(CVE-2022-25845)£¬¹¥»÷Õß¿ÉÒÔÔÚÌض¨Ìõ¼þÏÂÈƹýautoType¹Ø±Õ£¨Ä¬ÈÏ£©ÏÞÖÆ£¬´Ó¶ø·´ÐòÁл¯ÓÐÇ徲Σº¦µÄÀà¡£
¿ËÈÕ£¬OpenSSL¹Ù·½Ðû²¼Çå¾²¸üУ¬ÐÞ¸´ÁËOpenSSL¾Ü¾ø·þÎñÎó²î£¨CVE-2022-0778£©¡£¸ÃÎó²îÊÇÓÉÓÚÖ¤ÊéÆÊÎöʱʹÓÃµÄ BN_mod_sqrt() º¯Êý±£´æÒ»¸ö¹ýʧ£¬Ëü»áµ¼ÖÂÔÚ·ÇÖÊÊýµÄÇéÐÎÏÂÓÀԶѻ·¡£¿Éͨ¹ýÌìÉú°üÀ¨ÎÞЧµÄÏÔʽÇúÏß²ÎÊýµÄÖ¤ÊéÀ´´¥·¢ÎÞÏÞÑ»·¡£ÓÉÓÚÖ¤ÊéÆÊÎöÊÇÔÚÑéÖ¤Ö¤ÊéÊðÃû֮ǰ¾ÙÐеģ¬Òò´ËÈκÎÆÊÎöÍⲿÌṩµÄÖ¤ÊéµÄ³ÌÐò¶¼¿ÉÄÜÊܵ½¾Ü¾ø·þÎñ¹¥»÷¡£