¥»¥­¥å¥ê¥Æ¥£¸¦µæ¼Ô¤ÎAlexander Peslyak»á(Ä̾Ρ§Solar Designer)¤Ï7·î8Æü(¸½ÃÏ»þ´Ö)¡¢Openwall¤Î¥á¡¼¥ê¥ó¥°¥ê¥¹¥È¤ËÅê¹Æ¤·¤¿¡Öoss-security - Re: CVE-2024-6387: RCE in OpenSSH's server, on glibc-based Linux systems¡×¤Ë¤ª¤¤¤Æ¡¢ÆÃÄê´Ä¶­¤ÎOpenSSH¤«¤éÀȼåÀ­¤òȯ¸«¤·¤¿¤ÈÅÁ¤¨¤¿¡£¤³¤ì¤Ï7·î1Æü¤Ë¸ø³«¤µ¤ì¤¿¥»¥­¥å¥ê¥Æ¥£ÀȼåÀ­¡ÖregreSSHion¡×¤Î¥ì¥Ó¥å¡¼Ãæ¤Ëȯ¸«¤µ¤ì¤¿ÀȼåÀ­¤È¤µ¤ì¤ë(»²¹Í¡§¡ÖOpenSSH¤Ë´ÉÍý¼Ô¸¢¸Â¤ÇǤ°Õ¥³¡¼¥É¼Â¹Ô¤ÎÀȼåÀ­¡¢¥¢¥Ã¥×¥Ç¡¼¥È¤ò | TECH+¡Ê¥Æ¥Ã¥¯¥×¥é¥¹¡Ë¡×)¡£

oss-security - Re: CVE-2024-6387: RCE in OpenSSH's server, on glibc-based Linux systems

¡û¿·¤¿¤ÊÀȼåÀ­

¿·¤·¤¯È¯¸«¤µ¤ì¤¿ÀȼåÀ­¤Ï¡ÖCVE-2024-6409¡×¤È¤·¤ÆÄÉÀפµ¤ì¤Æ¤¤¤ë¡£¤³¤Î¥£ÀȼåÀ­¤ÎËܼÁ¤Ï¡¢regreSSHion¤ÈƱ¤¸¥·¥°¥Ê¥ë¥Ï¥ó¥É¥é¡¼¶¥¹ç¾õÂÖ¤ÎÀȼåÀ­¤È¤µ¤ì¤ë¡£

Áê°ãÅÀ¤Ïprivsep(Privilege separation)»Ò¥×¥í¥»¥¹Æâ¤ËÀȼåÀ­¤¬Â¸ºß¤·¡¢ÈóÆø¢¥æ¡¼¥¶¡¼¤Ç¥ê¥â¡¼¥È¥³¡¼¥É¤ò¼Â¹Ô¤µ¤ì¤ë²ÄǽÀ­¤¬¤¢¤ëÅÀ(»²¹Í¡§¡ÖPrivilege Separated OpenSSH¡×)¡£¤½¤Î¤¿¤á¡¢ÀȼåÀ­¤Î¿¼¹ïÅÙ¤ÏregreSSHion¤ÈƱ¤¸½ÅÍ×(Important)¤ËʬÎव¤ì¤Æ¤¤¤ë¤¬¡¢regreSSHion¤è¤ê¤â¤ä¤äÄ㤯ɾ²Á¤µ¤ì¤Æ¤¤¤ë¡£

¡ûÀȼåÀ­¤¬Â¸ºß¤¹¤ëÀ½ÉÊ

¤³¤ÎÀȼåÀ­¤Ï°ìÉô¤ÎLinux¥Ç¥£¥¹¥È¥ê¥Ó¥å¡¼¥·¥ç¥ó¤ÎOpenSSH¤Ë¸ºß¤¹¤ë¡£±Æ¶Á¤ò¼õ¤±¤ë¥Ç¥£¥¹¥È¥ê¥Ó¥å¡¼¥·¥ç¥ó¤ª¤è¤ÓOpenSSH¤Î¥Ð¡¼¥¸¥ç¥ó¤Ï¼¡¤Î¤È¤ª¤ê¡£

Red Hat Enterprise Linux 9¤ÎOpenSSH 8.7/8.7p1

Fedora 35¤«¤é37¤Þ¤Ç¤ÎOpenSSH 8.7/8.7p1¤ª¤è¤Ó8.8/8.8p1

AlmaLinux OS 9¤ÎOpenSSH 8.7/8.7p1

Rocky Linux 9¤ÎOpenSSH 8.7/8.7p1

¤³¤ì¤é°ìÍ÷¤Ï¾¤Î´Ä¶­¤Ë¤ª¤¤¤Æ±Æ¶Á¤ò¼õ¤±¤Ê¤¤¤³¤È¤òÊݾڤ¹¤ë¤â¤Î¤Ç¤Ï¤Ê¤¤¡£±Æ¶Á¤Î̵ͭ¤Ï³Æ¥Ç¥£¥¹¥È¥ê¥Ó¥å¡¼¥·¥ç¥ó¤Îȯɽ¤òÂԤĤ«¡¢¤Þ¤¿¤Ï³«È¯¼Ô¤ËÌ䤤¹ç¤ï¤»¤Æ³Îǧ¤¹¤ëɬÍפ¬¤¢¤ë¡£

¡ûÂкö

¾åµ­¥Ç¥£¥¹¥È¥ê¥Ó¥å¡¼¥·¥ç¥ó¤Î¿¤¯¤Ï¤¹¤Ç¤Ë½¤Àµ¥Ñ¥Ã¥Á¤ò¸ø³«¤·¤Æ¤¤¤ë¡£±Æ¶Á¤ò¼õ¤±¤ëOpenSSH¤ò±¿ÍѤ·¤Æ¤¤¤ë´ÉÍý¼Ô¤Ë¤Ï¡¢³«È¯¼Ô¤ÎÄ󶡤¹¤ë¾ðÊó¤ò³Îǧ¤·¤Æ®¤ä¤«¤Ë¥¢¥Ã¥×¥Ç¡¼¥È¤¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£