{"id":110873,"date":"2023-10-16T15:10:24","date_gmt":"2023-10-16T13:10:24","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/udalyonno-ekspluatiruemaya-uyazvimost-v-drajvere-nvme-of-tcp-iz-sostava-yadra-linux"},"modified":"2023-10-16T15:10:24","modified_gmt":"2023-10-16T13:10:24","slug":"udalyonno-ekspluatiruemaya-uyazvimost-v-drajvere-nvme-of-tcp-iz-sostava-yadra-linux","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-drajvere-nvme-of-tcp-iz-sostava-yadra-linux","title":{"rendered":"Vulnerabilidad explotable de forma remota en el controlador NVMe-oF\/TCP del n\u00facleo de Linux","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>En la subsistema nvmet-tcp de Linux (NVMe-oF\/TCP), que permite acceder a los dispositivos NVMe a trav\u00e9s de la red (NVM Express over Fabrics) utilizando el protocolo TCP, se ha descubierto una vulnerabilidad (CVE-2023-5178) que podr\u00eda permitir la ejecuci\u00f3n remota de c\u00f3digo en el nivel del kernel o, con acceso local, elevar las privilegios en el sistema. Actualmente, la correcci\u00f3n est\u00e1 disponible en forma de parche. El problema se presenta desde la primera versi\u00f3n del controlador NVMe-oF\/TCP (el informe de vulnerabilidad menciona el kernel de Linux 5.15, pero el soporte para NVMe-oF\/TCP se agreg\u00f3 en el kernel 5.0). Las sistemas afectados son aquellos con NVMe-oF\/TCP (NVME_TARGET_TCP) habilitado, que por defecto acepta conexiones en el puerto de red 4420. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/server\/dts-prohoster\/\"   title=\"el servidor\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"2996\">el servidor<\/a> NVMe-oF\/TCP (NVME_TARGET_TCP), que por defecto acepta conexiones en el puerto de red 4420.      <\/p>\n<p>La vulnerabilidad es causada por un error l\u00f3gico, que provoca que la funci\u00f3n nvmet_tcp_free_crypto se llame dos veces, liberando algunos punteros dos veces y desreferenciando direcciones liberadas. Este comportamiento conduce a un acceso a una zona de memoria ya liberada (use-after-free) y a una doble liberaci\u00f3n de memoria (double-free) al procesar un mensaje especialmente dise\u00f1ado de un cliente por parte del servidor NVMe-oF\/TCP, que puede estar en redes locales o globales.<br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59940\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 Linux-\u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 nvmet-tcp (NVMe-oF\/TCP), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043e\u0431\u0440\u0430\u0449\u0430\u0442\u044c\u0441\u044f \u043a NVMe-\u043d\u0430\u043a\u043e\u043f\u0438\u0442\u0435\u043b\u044f\u043c \u043f\u043e \u0441\u0435\u0442\u0438 (NVM Express over Fabrics), \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b TCP, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-5178), \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0438\u043b\u0438, \u043f\u0440\u0438 \u043d\u0430\u043b\u0438\u0447\u0438\u0438 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0434\u043e\u0441\u0442\u0443\u043f\u0430, \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u0418\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u043f\u043e\u043a\u0430 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u043e \u0432 \u0432\u0438\u0434\u0435 \u043f\u0430\u0442\u0447\u0430. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0441 \u0441\u0430\u043c\u043e\u0439 \u043f\u0435\u0440\u0432\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430 NVMe-oF\/TCP (\u0432 \u043e\u0442\u0447\u0451\u0442\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-110873","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 Linux-\u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 nvmet-tcp (NVMe-oF\/TCP), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043e\u0431\u0440\u0430\u0449\u0430\u0442\u044c\u0441\u044f \u043a NVMe-\u043d\u0430\u043a\u043e\u043f\u0438\u0442\u0435\u043b\u044f\u043c \u043f\u043e \u0441\u0435\u0442\u0438 (NVM Express over Fabrics), \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b TCP, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-5178), \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-drajvere-nvme-of-tcp-iz-sostava-yadra-linux\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 NVMe-oF\/TCP \u0438\u0437 \u0441\u043e\u0441\u0442\u0430\u0432\u0430 \u044f\u0434\u0440\u0430 Linux | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 Linux-\u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 nvmet-tcp (NVMe-oF\/TCP), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043e\u0431\u0440\u0430\u0449\u0430\u0442\u044c\u0441\u044f \u043a NVMe-\u043d\u0430\u043a\u043e\u043f\u0438\u0442\u0435\u043b\u044f\u043c \u043f\u043e \u0441\u0435\u0442\u0438 (NVM Express over Fabrics), \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b TCP, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-5178), \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-drajvere-nvme-of-tcp-iz-sostava-yadra-linux\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-10-16T13:10:24+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-10-16T13:10:24+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vulnerabilidad explotable remotamente en el controlador NVMe-oF\/TCP del n\u00facleo de Linux | ProHoster","description":"En la subsistema nvmet-tcp de Linux (NVMe-oF\/TCP), que permite acceder a los dispositivos NVMe a trav\u00e9s de la red (NVM Express over Fabrics) utilizando el protocolo TCP, se ha descubierto una vulnerabilidad (CVE-2023-5178) que podr\u00eda permitir la ejecuci\u00f3n remota.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-drajvere-nvme-of-tcp-iz-sostava-yadra-linux","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 NVMe-oF\/TCP \u0438\u0437 \u0441\u043e\u0441\u0442\u0430\u0432\u0430 \u044f\u0434\u0440\u0430 Linux | ProHoster","og:description":"\u0412 Linux-\u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 nvmet-tcp (NVMe-oF\/TCP), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043e\u0431\u0440\u0430\u0449\u0430\u0442\u044c\u0441\u044f \u043a NVMe-\u043d\u0430\u043a\u043e\u043f\u0438\u0442\u0435\u043b\u044f\u043c \u043f\u043e \u0441\u0435\u0442\u0438 (NVM Express over Fabrics), \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b TCP, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-5178), \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/udalyonno-ekspluatiruemaya-uyazvimost-v-drajvere-nvme-of-tcp-iz-sostava-yadra-linux","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-10-16T13:10:24+00:00","article:modified_time":"2023-10-16T13:10:24+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"110873","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-02-09 21:46:35","updated":"2026-02-09 21:46:35","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/110873","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=110873"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/110873\/revisions"}],"predecessor-version":[{"id":160277,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/110873\/revisions\/160277"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=110873"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=110873"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=110873"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}