ãµã¼ãã¼ã¯ã¼ã¯ã¹ããµãã¼ãçªå£ããç·æ¥ã§ãç¥ãããããã¾ãã
éå ±
Linuxã«ã¼ãã«3.8以éã®ã·ã¹ãã ã«ããã¦
ãã¼ã«ã«ã¦ã¼ã¶ãroot権éãåå¾å¯è½ã¨ãªãèå¼±æ§ãçºè¦ããã¾ããã
èå¼±æ§ã®æ¦è¦
èå¼±æ§ã®è©³ç´°ã¯ä»¥ä¸ã®è¨äºããåç §ãã ãã
ANALYSIS AND EXPLOITATION OF A LINUX KERNEL VULNERABILITY (CVE-2016-0728)
主ã«ãã©ã¤ããã»ãã¥ãªãã£ãã¼ã¿ãèªè¨¼ãã¼ãæå·åãã¼ã¨ã«ã¼ãã«å
ã®ä»ã®ãã¼ã¿ãä¿æã¾ãã¯ãã£ãã·ã¥ãã
ãã¼ãªã³ã°ã¨ããæ©æ§ã«ããã¦ãã®ãã¼ãªã³ã°ãã¼ã¿ãç½®ãæããããã»ã¹ã«ããã¦èå¼±æ§ãåå¨ãããã¨ã«ãã
以åã«è§£æ¾ããããã¼ãªã³ã°ãªãã¸ã§ã¯ãã«ãã£ã¦ä½¿ç¨ãããã¡ã¢ãªãä»ãã¦ã¦ã¼ã¶ã¼ç©ºéããå¥ã®ã«ã¼ãã«ãªãã¸ã§ã¯ããå²ãå½ã¦ã³ã¼ãã®å®è¡ãå¯è½ã¨ãªãã¾ãã
ãã®èå¼±æ§ã®åé¿çã¯ããã¾ããã
å¯è½ãªéãæ©æ¥ã«ãããé©ç¨ãè¡ãããäºãæ¨å¥¨ããã¦ããã¾ãã
å½±é¿ç¯å²
å½±é¿ãåããã·ã¹ãã ã¯ä»¥ä¸ã®éãã§ãã
Amazon Linux kernel-4.1.13-19.30.amzn1ããã³ãã以å
Red Hat Enterprise Linux 7.
CentOS Linux 7.
Scientific Linux 7.
Debian Linux 8.x (jessie) and 9.x (stretch).
SUSE Enterprise 12 (desktop, server and workstation flavours).
Ubuntu 14.04 LTS (Trusty Tahr), 15.04 (Vivid Vervet), and 15.10 (Wily Werewolf).
OpenSUSE Linux LEAP and 13.2.
ãªãã以ä¸ã®ã·ã¹ãã ã¯å½±é¿ãåãã¾ãã
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 4
ããããªãªã¼ã¹ç¶æ³
Amazon Linux
Amazon Linux ALAS-2016-642 kernel-4.1.13-19.31.amzn1 ããªãªã¼ã¹ããã¦ããã¾ãã
yum clean all
yum update kernel ã«ããé©ç¨ãå¯è½ã§ãã
é©ç¨å¾ãåèµ·åãè¡ã£ã¦ä¸ããã
Red Hat Enterprise Linux 7
2016/01/20 12:00(JST)æç¹ã§ã¯ã¾ã ãªãªã¼ã¹ããã¦ãã¾ããã
ãã®ä»ãã£ã¹ããªãã¥ã¼ã·ã§ã³
åãã£ã¹ããªãã¥ã¼ã¿ã¼ã®ã¢ãã¦ã³ã¹ãã確èªãã ããã