{"id":104289,"date":"2022-06-06T09:36:38","date_gmt":"2022-06-06T07:36:38","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/eshhyo-odna-uyazvimost-v-podsisteme-yadra-linux-netfilter"},"modified":"2022-06-06T09:36:38","modified_gmt":"2022-06-06T07:36:38","slug":"eshhyo-odna-uyazvimost-v-podsisteme-yadra-linux-netfilter","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/eshhyo-odna-uyazvimost-v-podsisteme-yadra-linux-netfilter","title":{"rendered":"Un'altra vulnerabilit\u00e0 nel sotto-sistema del kernel Linux Netfilter","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00c8 stata scoperta una vulnerabilit\u00e0 nel sotto-sistema del kernel Netfilter (CVE-2022-1972), simile a un problema rivelato alla fine di maggio. La nuova vulnerabilit\u00e0 consente anch'essa a un utente locale di ottenere i diritti di root nel sistema attraverso la manipolazione delle regole in nftables e richiede l'accesso a nftables, che pu\u00f2 essere ottenuto in un namespace separato (network namespace o user namespace) con i privilegi CLONE_NEWUSER, CLONE_NEWNS o CLONE_NEWNET (ad esempio, quando \u00e8 possibile eseguire un container isolato).     <\/p>\n<p>Il problema \u00e8 causato da un errore nel codice per la gestione delle liste set con campi che includono pi\u00f9 intervalli, che porta a una scrittura al di fuori dell'area di memoria allocata durante l'elaborazione di parametri di lista appositamente formattati. I ricercatori sono riusciti a preparare un exploit funzionante per ottenere i diritti di root in Ubuntu 21.10 con il kernel 5.13.0-39-generic. La vulnerabilit\u00e0 si manifesta a partire dal kernel 5.6. La correzione \u00e8 stata proposta sotto forma di patch. Per bloccare l sfruttamento della vulnerabilit\u00e0 nei sistemi normali, \u00e8 necessario assicurarsi di disabilitare la possibilit\u00e0 di creare spazi dei nomi da parte di utenti non privilegiati (\u300csudo sysctl -w kernel.unprivileged_userns_clone=0\u300d).    <\/p>\n<p>Inoltre, sono state pubblicate informazioni su tre vulnerabilit\u00e0 nel kernel relative alla sottosistema NFC. Le vulnerabilit\u00e0 consentono di causare un arresto anomalo tramite l'esecuzione di azioni da parte di un utente non privilegiato (vettori di attacco pi\u00f9 pericolosi non sono stati ancora dimostrati):  <\/p>\n<ul>\n<li class=\"l\"> CVE-2022-1734 \u2014 accesso a memoria gi\u00e0 liberata (use-after-free) nel driver nfcmrvl (drivers\/nfc\/nfcmrvl), che si manifesta durante la simulazione di un dispositivo NFC nello spazio utente.\n<li class=\"l\"> CVE-2022-1974 \u2014 accesso a memoria gi\u00e0 liberata nelle funzioni netlink per dispositivi NFC (\/net\/nfc\/core.c), che si manifesta durante la registrazione di un nuovo dispositivo. Come per la vulnerabilit\u00e0 precedente, il problema pu\u00f2 essere sfruttato tramite la simulazione di un dispositivo NFC nello spazio utente.\n<li class=\"l\"> CVE-2022-1975 \u2014 errore nel codice di caricamento dei firmware per dispositivi NFC, che pu\u00f2 essere utilizzato per innescare uno stato di\u300cpanic\u300d.    <\/ul>\n<p>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=57305\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Netfilter \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-1972), \u043f\u043e\u0445\u043e\u0436\u0430\u044f \u043d\u0430 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u0440\u0430\u0441\u043a\u0440\u044b\u0442\u0443\u044e \u0432 \u043a\u043e\u043d\u0446\u0435 \u043c\u0430\u044f. \u041d\u043e\u0432\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0442\u0430\u043a\u0436\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0447\u0435\u0440\u0435\u0437 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u0438 \u0441 \u043f\u0440\u0430\u0432\u0438\u043b\u0430\u043c\u0438 \u0432 nftables \u0438 \u0442\u0440\u0435\u0431\u0443\u0435\u0442 \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043a nftables, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043c\u043e\u0436\u043d\u043e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u043c \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u0438\u043c\u0451\u043d (network namespace \u0438\u043b\u0438 user namespace) \u043f\u0440\u0438 \u043d\u0430\u043b\u0438\u0447\u0438\u0438 \u043f\u0440\u0430\u0432 CLONE_NEWUSER, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-104289","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Netfilter \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-1972), \u043f\u043e\u0445\u043e\u0436\u0430\u044f \u043d\u0430 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u0440\u0430\u0441\u043a\u0440\u044b\u0442\u0443\u044e \u0432 \u043a\u043e\u043d\u0446\u0435 \u043c\u0430\u044f.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/eshhyo-odna-uyazvimost-v-podsisteme-yadra-linux-netfilter\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0415\u0449\u0451 \u043e\u0434\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Linux Netfilter | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Netfilter \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-1972), \u043f\u043e\u0445\u043e\u0436\u0430\u044f \u043d\u0430 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u0440\u0430\u0441\u043a\u0440\u044b\u0442\u0443\u044e \u0432 \u043a\u043e\u043d\u0446\u0435 \u043c\u0430\u044f.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/eshhyo-odna-uyazvimost-v-podsisteme-yadra-linux-netfilter\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-06-06T07:36:38+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-06-06T07:36:38+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Another vulnerability in the Linux Netfilter kernel subsystem | ProHoster","description":"\u00c8 stata identificata una vulnerabilit\u00e0 nel sottosistema del kernel Netfilter (CVE-2022-1972), simile al problema rivelato alla fine di maggio.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/eshhyo-odna-uyazvimost-v-podsisteme-yadra-linux-netfilter","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0415\u0449\u0451 \u043e\u0434\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Linux Netfilter | ProHoster","og:description":"\u0412 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Netfilter \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-1972), \u043f\u043e\u0445\u043e\u0436\u0430\u044f \u043d\u0430 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u0440\u0430\u0441\u043a\u0440\u044b\u0442\u0443\u044e \u0432 \u043a\u043e\u043d\u0446\u0435 \u043c\u0430\u044f.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/eshhyo-odna-uyazvimost-v-podsisteme-yadra-linux-netfilter","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-06-06T07:36:38+00:00","article:modified_time":"2022-06-06T07:36:38+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"104289","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-25 11:33:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-06-06 07:37:01","updated":"2026-01-25 11:33:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/104289","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=104289"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/104289\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=104289"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=104289"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=104289"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}