¹Ù·½Ðû²¼
ÍâµØȨÏÞÌáÉý
Glibc±£´æÍâµØÌáȨÎó²î(CVE-2023-4911)£¬¸ÃÎó²îÔ´ÓÚGNU C ¿âµÄ¶¯Ì¬¼ÓÔØÆ÷ ld.so ÔÚ´¦Öóͷ£ GLIBC_TUNABLES ÇéÐαäÁ¿Ê±±£´æ»º³åÇøÒç³ö£¬¿ÉÄÜÔÊÐíÍâµØ¹¥»÷ÕßÔÚÔËÐоßÓÐSUIDȨÏ޵Ķþ½øÖÆÎļþʱͨ¹ý¶ñÒâµÄ GLIBC_TUNABLES ÇéÐαäÁ¿À´ÌáÉýϵͳȨÏÞ¡£
CVSSÆÀ·Ö£º
CVE | V3.1 Vector(Base) | Base Score | V3.1 Vector(Temporal Score) | Temporal Score |
CVE-2023-4911 | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 7.8 | E:P/RL:O/RC:C | 7 |
ÊÜÓ°Ïì²úÆ·£º
²úÆ·Ãû³Æ | ÊÜÓ°Ïì°æ±¾ | Éý¼¶°ü°æ±¾ |
ICOS | ICOS 5.8.x | glibc-2.28-225.el8_8.6.x86_64.rpm glibc-2.28-189.5.0.3.kos5.x86_64.rpm |
InCloudOS | InCloudOS 6.x <= 6.8.0 |
ÎÞ
Îó²î½â¾ö¼Æ»®£ºÇëÓû§Ö±½ÓÁªÏµ¿Í»§·þÎñÖ°Ô±£¬»ñÈ¡²¹¶¡ÒÔ¼°Ïà¹ØµÄÊÖÒÕÖ§³Ö¡£
FAQ£ºÎÞ
¸üмͼ£º20231130-V1.0-Initial Release
K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾Çå¾²Ó¦¼±ÏìÓ¦¶ÔÍâ·þÎñ£º»ñÈ¡ÊÖÒÕÖ§³Ö£º/lcjtww/2317452/2317456/2317460/index.html
±¾ÎĵµÌṩµÄËùÓÐÊý¾ÝºÍÐÅÏ¢½ö¹©²Î¿¼£¬ÇÒ"°´ÔÑù"Ìṩ£¬²»ÔÊÐíÈκÎÕÑʾ¡¢Ä¬Ê¾ºÍ·¨¶¨µÄµ£±££¬°üÀ¨(µ«²»ÏÞÓÚ)¶ÔÊÊÏúÐÔ¡¢ÊÊÓÃÐÔ¼°²»ÇÖȨµÄµ£±£¡£ÔÚÈκÎÇéÐÎÏ£¬K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾»òÆäÖ±½Ó»ò¼ä½Ó¿ØÖƵÄ×Ó¹«Ë¾£¬»òÆ乩ӦÉÌ£¬¾ù²î³ØÈκÎÒ»·½ÒòÒÀÀµ»òʹÓñ¾ÐÅÏ¢¶øÔâÊܵÄÈκÎËðʧ¼ç¸ºÔðÈΣ¬°üÀ¨Ö±½Ó£¬¼ä½Ó£¬ÎÞÒ⣬һ¶¨µÄÉÌÒµÀûÈóËðʧ»òÌØÊâËðʧ¡£K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾±£´æËæʱ¸ü¸Ä»ò¸üдËÎĵµµÄȨÁ¦¡£