Linuxãã£ã¹ããªãã¥ã¼ã·ã§ã³ã®ä¸ã¤ã§ããUbuntuã«ã¦ããã¼ã«ã«æ¨©éææ ¼ã®èå¼±(ããããã)æ§ãGameOver(lay)ããçºè¦ããã¾ãããCVEã¯ãCVE-2023-2640ãããã³ãCVE-2023-32629ãã®2ã¤ã§ãã¨ãã«ä¿®æ£ãããã2023å¹´7æ24æ¥ã«ãªãªã¼ã¹æ¸ã¿ã§ãããã®ã®ãèå¼±æ§ã®å 容ã2020å¹´ã«Linuxã«ã¼ãã«ã§ä¿®æ£ããããCVE-2021-3493ãã¨åããã®ã¨ãªã£ã¦ãããããªãä¿®æ£æ¸ã¿ã ã£ãã¯ãã®èå¼±æ§ãæ®ã£ã¦ããã®ããã«ã¤ãã¦ä»åã®èå¼±æ§ã®çºè¦è ã§ããã¯ã©ã¦ãã»ãã¥ãªãã£ä¼æ¥Wizã解説ãã¦ãã¾ãã GameOverlay Vulnerability Impacts 40% of Ubuntu Workloads | Wiz Blog https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability Wizã«
Ubuntuã¯ãä¸çä¸ã§2000ä¸äººãè¶ ããã¦ã¼ã¶ã¼ãæ¥å¸¸çã«å©ç¨ãã¦ããLinuxãªãã¬ã¼ãã£ã³ã°ã·ã¹ãã ã§ãã æ¥æ¬ã§ãå¤ãã®ã¦ã¼ã¶ãå©ç¨ãã¦ãã¾ãã Ubuntuã«éã£ã話ã§ã¯ãªãã®ã§ãããLinuxã¯ã¦ã¼ã¶ã¼ã¢ã¼ãã¨ã«ã¼ãã«ã¢ã¼ãã¨ãã2ã¤ã®ããã»ã¹å®è¡ç©ºéãæã£ã¦ãã¾ãã éè¦ãªæ å ±ãæ¸ãæããããªãçºã®ã«ã¼ãã«ã¢ã¼ãã¨ãé常ã®ã¢ããªã±ã¼ã·ã§ã³ãåä½ããã¦ã¼ã¶ã¼ã¢ã¼ãã§ãã ãã®å®è¡ç©ºéã®åé¢ãæ£ããæ©è½ãããã¨ã«ãããå¿ è¦ä»¥ä¸ã®æ¨©éãä¸è¬ã®ã¢ããªã±ã¼ã·ã§ã³ã«è¨±å¯ãããã¨ã®ãªããå®å ¨ãªå®è¡ç°å¢ãå¾ããã¾ãã ãã®åæãå´©ããèå¼±æ§ã確èªããã¦ãã¾ãã CVE-2023-2640 ä¸é©åãªæ¨©éãã§ãã¯ãåå ã§ããã¼ã«ã«ã®æ»æè ãææ ¼ããã権éãåå¾ã§ãã¦ãã¾ãã¾ãã CVSSã®v3ãã¼ã¹ã¹ã³ã¢ã¯7.8ã§ãã CVE-2023-32629 ä»®æ³ã¡ã¢ãªç©ºéã¸ã®ã¢ã¯ã»ã¹æã®ç«¶åç¶æ ã«ãã
ãUbuntuãã¯é·å¹´ã«ããããå¸å ´ã§æã人æ°ã®ãããLinuxããã£ã¹ããªãã¥ã¼ã·ã§ã³ã®1ã¤ã ãããã«ã¯å¤ãã®çç±ãããããçªãè©°ãã¦ããã¨ã使ããããã¨ç§é¸ãªãã¼ãã¦ã§ã¢ãµãã¼ãã«å¸°çãããã¨ãé常ã«å¤ããã¨ã¯ãããUbuntuãä¸äººã«ã¨ã£ã¦ã®çæ³ã®OSã¨ããããã§ã¯ãªãããã®ãããUbuntuããã¼ã¹ã¨ãã¦å¤ç¨®å¤æ§ãªã¦ã¼ã¶ã¼ã®ãã¼ãºã«å¯¾å¿ãããæ´¾çããã£ã¹ããªãã¥ã¼ã·ã§ã³ãå¤æ°æä¾ããã¦ããã
å©ç¨ã·ã¼ã³ãåºãããUbuntuããå®å¿ãã¦æ´»ç¨ããããã®ãã¤ã³ãã¨ã¯ï¼Linuxã®åç¨å©ç¨ã«æ±ããããã»ãã¥ãªãã£ã¨ä¿¡é ¼æ§ã«å¿ãã ãCentOSãããã®ç§»è¡å ãä¼æ¥ã®åºå¹¹ã·ã¹ãã ãAIãæ©æ¢°å¦ç¿ã½ããã¦ã§ã¢ã®ç¨¼åç°å¢ã¨ãã¦æ³¨ç®ããããUbuntuããä¼æ¥ãå®å¿ãã¦Ubuntuãæ´»ç¨ããããã«ãã»ãã¥ãªãã£ãéç¨é¢ã«ããã¦ã©ããã£ã対å¿ãå¯è½ãªã®ã ãããã ãµã¼ãOSã¨ãã¦ä¸çæ¨æºã¨ãªãã¤ã¤ããUbuntu ä¼æ¥åãã®ãµã¼ãOSã¨ãã¦ãæ¥æ¬ã§ã¡ã¸ã£ã¼ãªLinuxãã£ã¹ããªãã¥ã¼ã·ã§ã³ã®ä¸ã¤ã¨ãã¦äººæ°ã ã£ããCentOSããã ããCentOS Streamãã¸ã®ç§»è¡ãçºè¡¨ããã2021å¹´12æã«CentOS 8ã®éçºããµãã¼ããçµäºãCentOS 7ãã¾ãã2024å¹´6æã«ãµãã¼ãçµäºãè¿ããã CentOS Streamã¨CentOSã®ãµãã¼ãçµäºã®çºè¡¨ã¯ãä¼æ¥ã®ã·ã¹ãã 管çè ã«å¤§ããªå½±
Linuxãã£ã¹ããªãã¥ã¼ã·ã§ã³ã¨ãã¦ãããã·ã§ã¢ãèªãUbuntuã«ãæ¨æºã¦ã¼ã¶ã¼ããç¹æ¨©ã¦ã¼ã¶ã¼ãç°¡åã«ä½æã§ãã¦ãã¾ãèå¼±æ§ãè¦ã¤ããã¾ããã How to get root on Ubuntu 20.04 by pretending nobodyâs /home - GitHub Security Lab https://securitylab.github.com/research/Ubuntu-gdm3-accountsservice-LPE Ubuntu fixes bugs that standard users could use to become root | Ars Technica https://arstechnica.com/information-technology/2020/11/ubuntu-fixes-bugs-that-standard-users
ç¾å¨Windows 10ã§ã¯Windows Subsystem for Linux(以ä¸WSL)ã¨ãã°ããæ©è½ãå©ç¨ãã¦å種Linuxãã£ã¹ããªãã¥ã¼ã·ã§ã³ã使ç¨ãããã¨ãã§ãã¾ãã WSLä¸ã®Linuxã¯ããã¤ãã£ããªLinuxç°å¢ã¨åæ§ã«ä½¿ç¨ã§ããé¨åãå¤ãã®ã§ããããã¹ã®åãæ±ããªã©ããã¯ãWSLãªãã§ã¯ã®éããåå¨ãã¾ãã æ¬æ¥ç´¹ä»ãããubuntu-wslãã¯ããããªWSLä¸ã®Ubuntuç°å¢ã®ãããUbuntuéçºãã¼ã ãå°å ¥ãéå§ããã¡ã¿ããã±ã¼ã¸ã§ãã ç¾å¨ã®ã¨ããubuntu-wslãã¤ã³ã¹ãã¼ã«ãããã¨ã§ãWSLã便å©ã«æ±ãããã®ã¦ã¼ãã£ãªãã£ã®ã³ã¬ã¯ã·ã§ã³ãwsluããã¤ã³ã¹ãã¼ã«ãããã¨ãã§ãã¾ãã ubuntu-wslã®ã¤ã³ã¹ãã¼ã« ubuntu-wslã¡ã¿ããã±ã¼ã¸ã¯ä»¥ä¸ã®ã³ãã³ãã§ã¤ã³ã¹ãã¼ã«ã§ãã¾ãã sudo apt update sudo apt ins
ã¡ã³ããã³ã¹
ãç¥ãã
é害
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}