{"id":24237,"date":"2017-07-19T17:31:17","date_gmt":"2017-07-19T09:31:17","guid":{"rendered":"https:\/\/www.deepin.org\/?p=24237"},"modified":"2017-07-19T17:32:09","modified_gmt":"2017-07-19T09:32:09","slug":"deepin-security-updates-cve-2017-8890-cve-2017-9445","status":"publish","type":"post","link":"https:\/\/www.deepin.org\/zh\/deepin-security-updates-cve-2017-8890-cve-2017-9445\/","title":{"rendered":"\u6df1\u5ea6\u5b89\u5168\u66f4\u65b0\uff08CVE-2017-8890 &#038;CVE-2017-9445\uff09"},"content":{"rendered":"<img loading=\"lazy\" class=\"aligncenter size-full wp-image-24239\" src=\"https:\/\/www.deepin.org\/wp-content\/uploads\/2017\/07\/zh-1.jpg\" alt=\"zh\" width=\"749\" height=\"321\" srcset=\"https:\/\/www.deepin.org\/wp-content\/uploads\/2017\/07\/zh-1.jpg 749w, https:\/\/www.deepin.org\/wp-content\/uploads\/2017\/07\/zh-1-600x257.jpg 600w, https:\/\/www.deepin.org\/wp-content\/uploads\/2017\/07\/zh-1-150x64.jpg 150w, https:\/\/www.deepin.org\/wp-content\/uploads\/2017\/07\/zh-1-300x129.jpg 300w, https:\/\/www.deepin.org\/wp-content\/uploads\/2017\/07\/zh-1-24x10.jpg 24w, https:\/\/www.deepin.org\/wp-content\/uploads\/2017\/07\/zh-1-36x15.jpg 36w, https:\/\/www.deepin.org\/wp-content\/uploads\/2017\/07\/zh-1-48x21.jpg 48w\" sizes=\"(max-width: 749px) 100vw, 749px\" \/><\/p>\n<p>\u6b64\u6b21\u5b89\u5168\u6f0f\u6d1e\u66f4\u65b0\u5305\u62ecsystemd\u53calinux\u5185\u6838\u7684\u66f4\u65b0\u3002<\/p>\n<h1>\u6f0f\u6d1e\u6982\u8ff0<\/h1>\n<p><strong><a href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2017-9445\">CVE-2017-9445<\/a> \u2014 \u5b89\u5168\u66f4\u65b0<\/strong><\/p>\n<p>\u5b89\u5168\u6570\u636e\u5e93\u8be6\u7ec6\u4fe1\u606f\uff1a<\/p>\n<p>\u5728systemd\u5230233\u4e2d\uff0c\u5728systemd-resolved\u4e2d\u4f20\u9012\u7ed9dns_packet_new\u7684\u67d0\u4e9b\u5927\u5c0f\u4f1a\u81f4\u4f7f\u5b83\u5f88\u5c0f\u7684\u7f13\u51b2\u533a\u3002 \u4e00\u4e2a\u6076\u610f\u7684DNS\u670d\u52a1\u5668\u53ef\u4ee5\u901a\u8fc7\u4e00\u4e2a\u7279\u5236\u7684TCP\u6709\u6548\u8d1f\u8f7d\u7684\u54cd\u5e94\u6765\u5229\u7528\u8fd9\u4e2a\u529f\u80fd\u6765\u6b3a\u9a97\u7cfb\u7edf\u89e3\u6790\u5206\u914d\u4e00\u4e2a\u592a\u5c0f\u7684\u7f13\u51b2\u533a\uff0c\u968f\u540e\u5199\u51fa\u4efb\u610f\u6570\u636e\u8d85\u51fa\u5b83\u7684\u7ed3\u5c3e\u3002<\/p>\n<p>&nbsp;<\/p>\n<p><strong><a href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2017-8890\">CVE-2017-8890<\/a> \u2014 \u5b89\u5168\u66f4\u65b0<\/strong><\/p>\n<p>\u5b89\u5168\u6570\u636e\u5e93\u8be6\u7ec6\u4fe1\u606f\uff1a<\/p>\n<p>Linux\u5185\u6838\u4e2d\u7684net \/ ipv4 \/ inet_connection_sock.c\u4e2d\u7684inet_csk_clone_lock\u51fd\u6570\u901a\u8fc74.10.15\u5141\u8bb8\u653b\u51fb\u8005\u901a\u8fc7\u5229\u7528\u63a5\u53d7\u7cfb\u7edf\u8c03\u7528\u9020\u6210\u62d2\u7edd\u670d\u52a1\uff08\u53cc\u91cd\u514d\u8d39\uff09\u6216\u53ef\u80fd\u5177\u6709\u672a\u6307\u5b9a\u7684\u5176\u4ed6\u5f71\u54cd\u3002<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 29px; font-weight: bold;\">\u4fee\u590d\u60c5\u51b5<\/span><\/p>\n<p>systemd\u53calinux\u5185\u6838\u7684\u5b89\u5168\u6f0f\u6d1e\u5df2\u7ecf\u5728\u6df1\u5ea6\u64cd\u4f5c\u7cfb\u7edfv15.4.1\u7684\u66f4\u65b0\u63a8\u9001\u4e2d\u4fee\u590d\u3002<\/p>\n<p>\u8bf7\u5404\u4f4d\u5c3d\u5feb\u66f4\u65b0\u7cfb\u7edf\u4ee5\u83b7\u53d6\u6f0f\u6d1e\u4fee\u590d\u8865\u4e01\u3002","protected":false},"excerpt":{"rendered":"<p>\u6b64\u6b21\u5b89\u5168\u6f0f\u6d1e\u66f4\u65b0\u5305\u62ecsystemd\u53calinux\u5185\u6838\u7684\u66f4\u65b0\u3002 \u6f0f\u6d1e\u6982\u8ff0 CVE-2017-9445 \u2014 \u5b89\u5168\u66f4\u65b0 \u5b89\u5168\u6570\u636e\u5e93\u8be6\u7ec6\u4fe1\u606f\uff1a \u5728systemd\u5230233\u4e2d\uff0c\u5728systemd-resolved\u4e2d\u4f20\u9012\u7ed9dns_packet_new\u7684\u67d0\u4e9b\u5927\u5c0f\u4f1a\u81f4\u4f7f\u5b83\u5f88\u5c0f\u7684\u7f13\u51b2\u533a\u3002 \u4e00\u4e2a\u6076\u610f\u7684DNS\u670d\u52a1\u5668\u53ef\u4ee5\u901a\u8fc7\u4e00\u4e2a\u7279\u5236\u7684TCP\u6709\u6548\u8d1f\u8f7d\u7684\u54cd\u5e94\u6765\u5229\u7528\u8fd9\u4e2a\u529f\u80fd\u6765\u6b3a\u9a97\u7cfb\u7edf\u89e3\u6790\u5206\u914d\u4e00\u4e2a\u592a\u5c0f\u7684\u7f13\u51b2\u533a\uff0c\u968f\u540e\u5199\u51fa\u4efb\u610f\u6570\u636e\u8d85\u51fa\u5b83\u7684 ...<a href=https:\/\/www.deepin.org\/zh\/deepin-security-updates-cve-2017-8890-cve-2017-9445\/>\u9605\u8bfb\u66f4\u591a<\/a><\/p>\n","protected":false},"author":141,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[75],"tags":[],"_links":{"self":[{"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/posts\/24237"}],"collection":[{"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/users\/141"}],"replies":[{"embeddable":true,"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/comments?post=24237"}],"version-history":[{"count":9,"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/posts\/24237\/revisions"}],"predecessor-version":[{"id":24248,"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/posts\/24237\/revisions\/24248"}],"wp:attachment":[{"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/media?parent=24237"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/categories?post=24237"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/tags?post=24237"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}