{"id":182539,"date":"2026-07-08T10:54:16","date_gmt":"2026-07-08T08:54:16","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/bad-epoll-v-linux-i-android-nashli-uyazvimost-dlya-polucheniya-root-dostupa"},"modified":"2026-07-08T10:54:16","modified_gmt":"2026-07-08T08:54:16","slug":"bad-epoll-v-linux-i-android-nashli-uyazvimost-dlya-polucheniya-root-dostupa","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/bad-epoll-v-linux-i-android-nashli-uyazvimost-dlya-polucheniya-root-dostupa","title":{"rendered":"Vuln\u00e9rabilit\u00e9 Bad Epoll : une faille a \u00e9t\u00e9 d\u00e9couverte dans Linux et Android permettant un acc\u00e8s root.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" src=\"\/wp-content\/uploads\/2026\/07\/55dd8eda44f5f48052b033a5c9bcab2d.jpg\" style=\"display:block;margin: 0 auto;\" \/>                                  <noindex>          <a rel=\"nofollow\" id=\"memories_button\" href=\"#\" title=\"Suivre\"><i class=\"icon-bell\"><\/i><\/a><br \/>1                            <noindex><\/p>\n<p>Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9e dans le noyau Linux <strong>Mauvais Epoll<\/strong>, enregistr\u00e9 sous le nom <a rel=\"nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-46242\">CVE-2026-46242<\/a>. Cela permet \u00e0 un utilisateur local ordinaire, sans privil\u00e8ges sp\u00e9ciaux, d'\u00e9lever ses privil\u00e8ges au niveau root. Selon le chercheur Jayon Chong, le probl\u00e8me concerne non seulement les ordinateurs de bureau et les serveurs Linux, mais aussi certains appareils Android sous de nouvelles versions du noyau - cela est particuli\u00e8rement soulign\u00e9 dans <a rel=\"nofollow\" href=\"https:\/\/github.com\/J-jaeyoung\/bad-epoll\">la description de Mauvais Epoll<\/a>.<\/p>\n<p><\/noindex> <noindex><\/p>\n<p>L'erreur r\u00e9side dans le sous-syst\u00e8me <strong>epoll<\/strong> \u2014 le m\u00e9canisme standard de Linux pour suivre plusieurs descripteurs de fichiers, connexions r\u00e9seau et \u00e9v\u00e9nements d'entr\u00e9e\/sortie. Ces m\u00e9canismes sont largement utilis\u00e9s par les serveurs, navigateurs et services r\u00e9seaux, donc il n'est pas possible de d\u00e9sactiver epoll simplement. Dans <a rel=\"nofollow\" href=\"https:\/\/github.com\/J-jaeyoung\/security-research\/blob\/submit-cve-2026-46242\/pocs\/linux\/kernelctf\/CVE-2026-46242_lts_cos\/docs\/vulnerability.md\">l'analyse technique<\/a> la vuln\u00e9rabilit\u00e9 est d\u00e9crite comme une condition de course, entra\u00eenant un <strong>use-after-free<\/strong>: lorsque des objets epoll associ\u00e9s sont ferm\u00e9s simultan\u00e9ment, un thread lib\u00e8re les structures internes tandis qu'un autre continue \u00e0 y acc\u00e9der.<\/p>\n<p><\/noindex> <\/p>\n<p>Pour \u00eatre plus pr\u00e9cis, le probl\u00e8me se manifeste lorsqu'un descripteur epoll surveille un autre et que les deux descripteurs sont ferm\u00e9s en parall\u00e8le. Apr\u00e8s l'appel \u00e0 __ep_remove(), le champ file-&gt;f_ep est temporairement mis \u00e0 z\u00e9ro, et le concurrent __fput() peut d\u00e9cider que le nettoyage suppl\u00e9mentaire n'est plus n\u00e9cessaire. En cons\u00e9quence, l'objet struct eventpoll ou le struct file associ\u00e9 est lib\u00e9r\u00e9 trop t\u00f4t, mais le code continue de fonctionner avec des pointeurs vers une m\u00e9moire d\u00e9j\u00e0 lib\u00e9r\u00e9e. C'est exactement ce qui donne \u00e0 l'attaquant un moyen de corrompre la m\u00e9moire du noyau.<\/p>\n<p> <noindex><\/p>\n<p>Aucune capacit\u00e9 suppl\u00e9mentaire n'est n\u00e9cessaire pour l'attaque et aucune namespace utilisateur n'est requise - il suffit d'avoir CONFIG_EPOLL, ce qui rend le probl\u00e8me particuli\u00e8rement d\u00e9sagr\u00e9able pour les syst\u00e8mes Linux ordinaires. Selon <a rel=\"nofollow\" href=\"https:\/\/github.com\/J-jaeyoung\/security-research\/blob\/submit-cve-2026-46242\/pocs\/linux\/kernelctf\/CVE-2026-46242_lts_cos\/docs\/vulnerability.md\">le rapport initial du chercheur<\/a>, le bug a \u00e9t\u00e9 introduit dans le noyau par le commit <a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=58c9b016e128\">58c9b016e128<\/a> en 2023, et corrig\u00e9 par le commit <a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=a6dc643c693\">a6dc643c693<\/a>.<\/p>\n<p><\/noindex> <noindex><\/p>\n<p>Malgr\u00e9 une fen\u00eatre de course tr\u00e8s \u00e9troite, le chercheur a pr\u00e9par\u00e9 un exploit fonctionnel pour le Google kernelCTF. Dans <a rel=\"nofollow\" href=\"https:\/\/github.com\/J-jaeyoung\/security-research\/blob\/submit-cve-2026-46242\/pocs\/linux\/kernelctf\/CVE-2026-46242_lts_cos\/docs\/exploit.md\">la description de l'exploitation<\/a> il est d\u00e9montr\u00e9 comment l'erreur se transforme en une \u00e9criture de 8 octets dans une structure lib\u00e9r\u00e9e, puis en une fuite de m\u00e9moire du noyau via \/proc\/self\/fdinfo, en interceptant file-&gt;f_op-&gt;poll et en utilisant une cha\u00eene ROP pour obtenir le root. Pour l'objectif lts-6.12.67, une fiabilit\u00e9 d'environ 99 % est revendiqu\u00e9e, pour COS - environ 98 % ; l'exploit Android, selon l'auteur, est encore en cours de d\u00e9veloppement.<\/p>\n<p><\/noindex> <noindex><\/p>\n<p>Les noyaux bas\u00e9s sur la branche <strong>6.4 et plus r\u00e9cents<\/strong>, s'ils n'ont pas \u00e9t\u00e9 patch\u00e9s. Les anciens appareils Android sous des noyaux 6.1, y compris le Pixel 8 et des mod\u00e8les similaires, sont consid\u00e9r\u00e9s par l'auteur <a rel=\"nofollow\" href=\"https:\/\/github.com\/J-jaeyoung\/bad-epoll\">comme non vuln\u00e9rables<\/a>. Pour les utilisateurs et les administrateurs, la seule option de protection raisonnable reste d'installer la mise \u00e0 jour du noyau fournie par leur distribution ou le fournisseur de l'appareil.<\/p>\n<p><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.linux.org.ru\/news\/security\/18335032\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>1 \u0412 \u044f\u0434\u0440\u0435 Linux \u0440\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c Bad Epoll, \u0437\u0430\u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u0430\u044f \u043a\u0430\u043a CVE-2026-46242. \u041e\u043d\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043e\u0431\u044b\u0447\u043d\u043e\u043c\u0443 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0431\u0435\u0437 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0445 \u043f\u0440\u0430\u0432 \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0434\u043e root. \u041f\u043e \u0434\u0430\u043d\u043d\u044b\u043c \u0430\u0432\u0442\u043e\u0440\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f \u0414\u0436\u044d\u0451\u043d\u0430 \u0427\u043e\u043d\u0430, \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u043d\u0435 \u0442\u043e\u043b\u044c\u043a\u043e Linux-\u0434\u0435\u0441\u043a\u0442\u043e\u043f\u044b \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u044b, \u043d\u043e \u0438 \u0447\u0430\u0441\u0442\u044c Android-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 \u043d\u0430 \u043d\u043e\u0432\u044b\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u044f\u0434\u0440\u0430 \u2014 \u044d\u0442\u043e \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e \u043f\u043e\u0434\u0447\u0451\u0440\u043a\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0432 \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0438 Bad Epoll. \u041e\u0448\u0438\u0431\u043a\u0430 \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":9,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-182539","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Emin Berklin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/bad-epoll-v-linux-i-android-nashli-uyazvimost-dlya-polucheniya-root-dostupa\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Bad Epoll: \u0432 Linux \u0438 Android \u043d\u0430\u0448\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0434\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f root-\u0434\u043e\u0441\u0442\u0443\u043f\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/bad-epoll-v-linux-i-android-nashli-uyazvimost-dlya-polucheniya-root-dostupa\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-07-08T08:54:16+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-08T08:54:16+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Bad Epoll : une vuln\u00e9rabilit\u00e9 permettant d'obtenir un acc\u00e8s root a \u00e9t\u00e9 d\u00e9couverte sur Linux et Android | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/bad-epoll-v-linux-i-android-nashli-uyazvimost-dlya-polucheniya-root-dostupa","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Bad Epoll: \u0432 Linux \u0438 Android \u043d\u0430\u0448\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0434\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f root-\u0434\u043e\u0441\u0442\u0443\u043f\u0430 | ProHoster","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/bad-epoll-v-linux-i-android-nashli-uyazvimost-dlya-polucheniya-root-dostupa","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-07-08T08:54:16+00:00","article:modified_time":"2026-07-08T08:54:16+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"182539","title":null,"description":null,"keywords":null,"keyphrases":{"focus":[],"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-08-05 12:22:07","updated":"2026-08-05 12:22:07","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/182539","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=182539"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/182539\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=182539"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=182539"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=182539"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}