Debian 安全漏洞速递与处置要点
一、近期需重点关注的高危漏洞
二、Debian 受影响版本与修复状态
| Debian 版本 | 包名 | 已修复版本 | 安全公告 |
|---|---|---|---|
| Debian 11(bullseye) | libblockdev | 2.25-2+deb11u1 | DLA-4221-1 |
| Debian 12(bookworm) | libblockdev | 2.28-2+deb12u1 | DSA-5943-1 |
| Debian sid/trixie | libblockdev | 3.3.0-2.1 | Debian Tracker |
dpkg -l | grep libblockdevsudo apt update && sudo apt upgradesudo systemctl restart udisks2 或 sudo rebootapt changelog libblockdev 与 /var/log/apt/history.log。三、临时缓解与加固措施(在无法立即升级时)
/etc/polkit-1/rules.d/50-local.rulespolkit.addRule(function(action, subject) {
if (action.id == "org.freedesktop.udisks2.modify-device") {
return polkit.Result.AUTH_ADMIN;
}
});
sudo systemctl restart polkitfind / -type f -perm -4000 -o -perm -2000 2>/dev/null),仅保留必需项。PermitRootLogin no、PasswordAuthentication no、AllowUsers youruser。四、持续监测与响应