{"id":137368,"date":"2019-03-20T10:31:57","date_gmt":"2019-03-20T02:31:57","guid":{"rendered":"https:\/\/lrxjmw.cn\/?p=137368"},"modified":"2019-02-25T12:34:23","modified_gmt":"2019-02-25T04:34:23","slug":"use-after-free","status":"publish","type":"post","link":"https:\/\/lrxjmw.cn\/use-after-free.html","title":{"rendered":"use-after-free\u6f0f\u6d1e\u53d1\u73b0\u4e4b\u65c5"},"content":{"rendered":"

\u68c0\u6d4bLinux\u5185\u6838\u4ee3\u7801\u4e2d\u52a8\u6001\u5185\u5b58\u9519\u8bef\u7684\u52a8\u6001\u5185\u5b58\u9519\u8bef\u68c0\u6d4b\u5de5\u5177(KASAN)\u521a\u521a\u83b7\u5f97\u4e86\u53e6\u4e00\u4e2a\u6210\u679c\uff0c\u5b83\u53d1\u73b0\u4e86\u4e00\u4e2a\u4ece\u65e9\u671fLinux 2.6\u5185\u6838\u5f00\u59cb\u5c31\u5b58\u5728\u7684use-after-free\u6f0f\u6d1e\u3002<\/p>\n

\u52a8\u6001\u5185\u5b58\u9519\u8bef\u68c0\u6d4b\u5de5\u5177(KASAN)\u5df2\u7ecf\u88ab\u8bc1\u660e\u5728\u53d1\u73b0\u5404\u79cd\u7f16\u7801\u9519\u8bef\u65b9\u9762\u975e\u5e38\u6709\u4ef7\u503c\uff0c\u5e0c\u671b\u5728\u5b9e\u9645\u5e94\u7528\u4e4b\u524d\u80fd\u591f\u53d1\u73b0\u8fd9\u4e9b\u9519\u8bef\u3002\u5185\u6838\u5730\u5740\u9519\u8bef\u68c0\u67e5\u7a0b\u5e8f\u5728CVE-2019-8912\u53d1\u73b0\u4e2d\u8d1f\u8d23\u53e6\u4e00\u4e2a\u6311\u6218\u3002<\/p>\n

\u5728\u7f51\u7edc\u5b50\u7cfb\u7edf\u7684sockfs\u4ee3\u7801\u4e2d\u53d1\u73b0\u4e86\u4e00\u4e2ause-after-free\u95ee\u9898\uff0c\u5b83\u53ef\u80fd\u5bfc\u81f4\u6267\u884c\u4efb\u610f\u4ee3\u7801\u3002<\/p>\n

\u534e\u4e3a\u7684\u4e00\u540d\u5de5\u7a0b\u5e08\u5728\u4e0a\u5468\u62a5\u544a\u4e86\u8fd9\u4e2a\u95ee\u9898\uff0c\u5e76\u5728\u4e0d\u4e45\u540e\u5c31\u4fee\u590d\u4e86Linux Git\u3002\u622a\u81f3\u4eca\u5929\u7684Linux 4.20.11\u5185\u6838\u7248\u672c\uff0c\u4e2d\uff0c\u5b83\u4f3c\u4e4e\u8fd8\u6ca1\u6709\u9644\u5e26\u8fd9\u4e2a\u8865\u4e01\uff0c\u4f46\u5e94\u8be5\u5f88\u5feb\u5c31\u4f1a\u51fa\u73b0\u5728\u5404\u79cd\u7a33\u5b9a\/\u957f\u671f\u5206\u652f\u4e2d\u3002
\n\u5f53\u524d\u7684\u63cf\u8ff0<\/p>\n

\u5728Linux\u5185\u6838\u4e2d\u901a\u8fc74.20.11 af_alg_release()\u52a0\u5bc6\/ af_alg\u3002 c\u6ca1\u6709\u8bbe\u7f6e\u4e00\u4e2aNULL\u503c\u5728\u4e00\u5b9a\u7ed3\u6784\u6210\u5458,\u5bfc\u81f4sockfs_setattr use-after-free\u3002<\/p>\n

\u89c6\u56fe\u5206\u6790\u63cf\u8ff0<\/strong><\/div>\n

\"\"<\/p>\n

\u5f15\u7528\u62a5\u544a\u3001\u89e3\u51b3\u65b9\u6848\u548c\u5de5\u5177<\/strong><\/div>\n

\u901a\u8fc7\u9009\u62e9\u8fd9\u4e9b\u94fe\u63a5,\u60a8\u5c06\u79bb\u5f00NIST\u591a\u4e45\u3002 \u6211\u4eec\u63d0\u4f9b\u4e86\u8fd9\u4e9b\u94fe\u63a5\u5230\u5176\u4ed6\u7f51\u7ad9,\u56e0\u4e3a \u4ed6\u4eec\u53ef\u80fd\u611f\u5174\u8da3\u7684\u4f60\u7684\u4fe1\u606f\u3002 \u6ca1\u6709\u63a8\u65ad\u5e94\u8be5\u753b\u5728\u5176\u4ed6\u7f51\u7ad9\u7684\u8d26\u6237 \u88ab\u5f15\u7528,\u4ece\u8fd9\u4e2a\u9875\u9762\u3002 \u53ef\u80fd\u4f1a\u6709\u5176\u4ed6\u7f51\u7ad9\u66f4\u9002\u5408\u60a8\u7684\u76ee\u7684\u3002 NIST\u4e0d\u4e00\u5b9a\u652f\u6301\u89c2\u70b9,\u6216\u540c\u610f\u5728\u8fd9\u4e9b\u7f51\u7ad9\u4e0a\u5448\u73b0\u7684\u4e8b\u5b9e\u3002 \u6b64\u5916, NIST\u7684\u4e0d\u8ba4\u53ef\u4efb\u4f55\u5546\u4e1a\u4ea7\u54c1\u53ef\u80fd\u5728\u8fd9\u4e9b\u7f51\u7ad9\u4e0a\u63d0\u5230\u7684\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"

\u68c0\u6d4bLinux\u5185\u6838\u4ee3\u7801\u4e2d\u52a8\u6001\u5185\u5b58\u9519\u8bef\u7684\u52a8\u6001\u5185\u5b58\u9519\u8bef\u68c0\u6d4b\u5de5\u5177(KASAN)\u521a\u521a\u83b7\u5f97\u4e86\u53e6\u4e00\u4e2a\u6210\u679c\uff0c\u5b83\u53d1\u73b0\u4e86\u4e00\u4e2a\u4ece\u65e9 […]<\/p>\n","protected":false},"author":1893,"featured_media":137370,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[21],"tags":[],"class_list":["post-137368","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/posts\/137368","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/users\/1893"}],"replies":[{"embeddable":true,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/comments?post=137368"}],"version-history":[{"count":2,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/posts\/137368\/revisions"}],"predecessor-version":[{"id":138139,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/posts\/137368\/revisions\/138139"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/media\/137370"}],"wp:attachment":[{"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/media?parent=137368"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/categories?post=137368"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/tags?post=137368"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}