¡¾Îó²îͨ¸æ¡¿vm2 ɳÏäÌÓÒÝÎó²î(CVE-2026-22709)
Ðû²¼Ê±¼ä 2026-01-28Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | vm2 ɳÏäÌÓÒÝÎó²î | ||
CVE ID | CVE-2026-22709 | ||
Îó²îÀàÐÍ | ɳÏäÌÓÒÝ | ·¢Ã÷ʱ¼ä | 2026-1-28 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
vm2ÊÇÒ»¸öÓÃÓÚÔÚNode.jsÇéÐÎÖн¨Éè¸ôÀëɳÏäµÄ¿â£¬£¬£¬ÔÊÐíÔÚÇå¾²µÄÇéÐÎÖÐÖ´Ðв»¿ÉÐŵÄJavaScript´úÂë¡£¡£¡£¡£Ëüͨ¹ýÄ£Äâä¯ÀÀÆ÷ÇéÐΣ¬£¬£¬ÌṩÁ˶ԴúÂëÖ´ÐеÄÑÏ¿á¿ØÖÆ£¬£¬£¬±ÜÃâ¶ñÒâ´úÂë»á¼ûËÞÖ÷ϵͳµÄÃô¸Ð×ÊÔ´¡£¡£¡£¡£vm2ÔÊÐíÔÚɳÏäÖÐÔËÐдúÂ룬£¬£¬Í¬Ê±È·±£´úÂëÎÞ·¨»á¼ûÈ«¾Ö¹¤¾ß¡¢Ä£¿£¿£¿é¡¢Îļþϵͳ»òÖ´ÐÐΣÏÕµÄϵͳ²Ù×÷¡£¡£¡£¡£ËüÆÕ±éÓÃÓÚÐèÒªÖ´Ðж¯Ì¬´úÂëÇÒÒªÇó¸ßÇå¾²ÐԵij¡¾°£¬£¬£¬ÈçÔÚÔÆÐ§ÀÍÆ½Ì¨¡¢²âÊÔÇéÐÎÖÐÖ´ÐÐδÑéÖ¤µÄ¾ç±¾¡£¡£¡£¡£
2026Äê1ÔÂ28ÈÕ£¬£¬£¬Z6×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½vm2ÖеÄÒ»¸öɳÏäÌÓÒÝÎó²î£¬£¬£¬ÔÚÊÜÓ°Ïì°æ±¾ÖУ¬£¬£¬Promise.prototype.thenºÍPromise.prototype.catchµÄ»Øµ÷º¯ÊýδÄÜÓÐÓõضԴ«ÈëµÄÊý¾Ý¾ÙÐÐÊʵ±µÄ¹ýÂ˺͸ôÀ룬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»ÈƹýɳÏäµÄÏÞÖÆ£¬£¬£¬Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬µ±Òì²½º¯Êý·µ»ØÒ»¸öglobalPromise¹¤¾ßʱ£¬£¬£¬Æä»Øµ÷ûÓоÓɳä·ÖµÄÇå¾²´¦Öóͷ££¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâÒ»µã½á¹¹¶ñÒâ´úÂ룬£¬£¬²¢ÔÚɳÏäÍⲿִÐС£¡£¡£¡£Í¨¹ýÈ«ÐÄÉè¼ÆµÄpromiseÁ´£¬£¬£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃÈçFunction½á¹¹Æ÷Ö´ÐÐϵͳÏÂÁ£¬£¬ÊµÏÖɳÏäÌÓÒÝ¡£¡£¡£¡£ÕâʹµÃ¹¥»÷ÕßÄܹ»ÔÚÊܱ£»£»£»£»£»£»£»¤ÇéÐÎÖÐÖ´ÐÐí§ÒâÏÂÁ£¬£¬ÑÏÖØÎ£º¦ÏµÍ³Çå¾²¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
vm2 <= 3.10.0
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/patriksimek/vm2/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ