I-Linux Kernel Flaw eyenza amadivaysi e-Android asengozini

NgoJan 21, 2016

Iintsuku ezimbalwa ezedlulileyo, Indawo yokuPhepha, i-Israel ye-cybersecurity firm, ifumene ukukhuseleka kwokhuseleko kwosuku kwi-Linux kernel elinika inani elingapheliyo leseva, ii-PC kunye neyona nto ibaluleke kakhulu, iifowuni ze-Android ezisetyenziswayo . I-hacker efuna ukuthatha inzuzo yolu xhatshazo, inokufumana amalungelo angcambu kwinqanaba kwaye ingafumana ukufikelela okungagunyazisiweyo kwedatha okanye ukwenza ikhowudi ngokuthanda kwayo.

Okunye malunga neLuxal Kernel Flaw

Ngokweengcali, isizathu sokuba iphosakele ikhona kwi- Linux kernel eyona nto, efana nesevava, ii-PC kunye ne-Android. Le mpazamo, eyabelwe igama elithi CVE-2016-0728, ikholelwa ukuba ifuthe ngaphezu kwama-60 ekhulwini kuwo onke amacebo anikwe i-Android. Ngokweqile, eli qhopholo lokuqala lenze ukubonakala kwangaphambili ngo-2012 kwi-Linux version 3.8 kwaye isaphila kwiinkqubo zombini ze -Lin-32 kunye ne-64-bit .

Into ephazamisayo apha kukuba ubungozi bubekho khona malunga neminyaka engama-3 kwaye banakho ukuvumela abacebisi ukuba bafumane ukulawulwa okungagunyaziwe kwiinkonzo ze-Linux-run, ii-PC, i-Android kunye nezinye izixhobo ezifakiwe. Ngokuqinisekileyo kuvela kwiziko le-key kernel kwaye ivumela ii-apps ezisebenzayo phantsi komsebenzisi wendawo ukuba enze ikhowudi kwi-kernel. Oku kuthetha ukuba ubungozi bungabangela ulwazi olubalulekileyo lwabasebenzisi, kubandakanya ukuqinisekiswa kunye neenkcukacha zokubhaliweyo, ekungciphekweni kokungena.

Indlela enokuyibeka ngayo iPhenyizi kwi-Android

Into enokubangela ukuba le ntsholongwane iyinkxalabo enkulu kukuba ichaphazela zonke izakhiwo zobugcisa, kuquka i-ARM. Oku kuchaza ngokuzenzekelayo, ukuba zonke idivayisi ze-Android ziqhuba i- Android 4.4 KitKat kwaye kamva, zimele zithinteke kuyo. Okwangoku, oku kubakho malunga nama-70 ekhulwini kuwo onke amadivayisi e-Android.

I-Android OS sele isaziwa ngezinga eliphezulu layo lokuqhekeka kunye nokuhlaziywa kokulibaziseka. Izabelo zeGoogle zikwabelana ngezokhuseleko kunye nabenzi beefowuni, abazisebenzisayo ngokwahlukileyo. Inkampani ihambisa ezinye iinguqulelo ngokubambisana nabathwali bezithuthi ezichaphazelekayo. Ukuqhubela phambili ukuxubusha imiba, ezininzi zezixhobo zifumana inkxaso yesoftware kuphela kwiinyanga ezili-18, emva koko abafumani nayiphi na iinguqulelo okanye ii-patches. Oku kuya kuthetha ukuba abaninzi abasebenzisi beedivaysi, ingakumbi abo basebenzisa amadivayisi asekudala ase-Android, abanakuze bakwazi ukufumana izilungiso zakutsha kunye nokulungiswa kwezigulane.

Esi siganeko siya kubonakala kubasebenzisi ukuba iinguqu ze-Android ezidlulileyo aziyi kuphinda zikhuselekile ukusetyenziswa kwaye kufuneka zihlale ziphucula izixhobo zazo ukwenzela ukuba zifumane iimpawu zokhuseleko kunye nenye imisebenzi. Kwakhona oko kuya kuba sisisombululo esingenakwenzeka kwingxaki - kungekhona wonke umntu oya kukulungele ukuguqula i-smartphone okanye ithebhulethi yakhe kanye emva kweminyaka emibini.

Kuze kube ngoku, imboni yeselula iye yabonakala kwiintlobo ze-malware ephathekayo eziye zazingekho. Kuza kubekho namhlanje, akukho kuhlaselwa kwe-hacks kuye kwabangela ingozi enkulu kubasebenzisi. Nangona kunjalo, inyaniso ihlala kukuba i-Android yinjongo ephosakeleyo ye-malware kwaye ingaba ngumcimbi wexesha ngaphambi kokuba umntu aqalise ukuhlaselwa okukhulu kwiimeko ezikhoyo ezikhoyo.

Yiyiphi iLinux neGoogle Plan yokwenza

Ngethamsanqa, nangona ubungozi bukhona, akukho hlaselo lokuhlaselwa luye lwabonakala. Nangona kunjalo, iingcali zokhuseleko ziya kuluba ngokugqithiseleyo ukuze zifumene ukuba le mpazamo yaxhatshazwa ngexesha elidlulileyo. Iqela lezokukhusela iLinux kunye ne-Red Hat sele isebenzayo ukukhupha iimpawu ezinxulumene nazo - zifanele zifumaneke ekupheleni kweli veki. Nangona kunjalo, kukho ezinye iinkqubo ezinokuthi zihlale zisengozini, ubuncinci ixesha elithile.

I-Google ayikwazanga ukunika impendulo ngokukhawuleza ngokukhawuleza xa iphoso liza kufakwa kwi-code ye-Android. Esi sikhokelo, ukuba ngumthombo ovulekileyo, kuya kuba kubakhi beefayili kunye nabaphuhlisi ukuba bangeze kwaye bahanjiswe iqhosha kumakhasimende abo. Okwangoku, i-Google, njengokuba isoloko, iya kuqhubeka nokukhupha izibuyekezo zenyanga kunye neendlela zokulungisa izigulane kwi-Nexus line ye-Android. Iqhosha elikhulu liceba ukuxhasa nganye yeemodeli zayo ubuncinane iminyaka emi-2 emva komhla wokuthengiswa kokuqala kwisitoreji sayo kwi-intanethi .