{"id":125569,"date":"2025-05-25T15:05:07","date_gmt":"2025-05-25T13:05:07","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/udalyonnaya-uyazvimost-v-module-ksmbd-yadra-linux-vyyavlennaya-pri-pomoshhi-ai"},"modified":"2025-05-25T15:05:07","modified_gmt":"2025-05-25T13:05:07","slug":"udalyonnaya-uyazvimost-v-module-ksmbd-yadra-linux-vyyavlennaya-pri-pomoshhi-ai","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/udalyonnaya-uyazvimost-v-module-ksmbd-yadra-linux-vyyavlennaya-pri-pomoshhi-ai","title":{"rendered":"Vulnerabilit\u00e0 remota nel modulo ksmbd del kernel Linux, rilevata tramite AI","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nel modulo ksmbd, che offre un'implementazione del server file basata sul protocollo SMB integrata nel kernel Linux, \u00e8 stata identificata una vulnerabilit\u00e0 (CVE-2025-37899) che potrebbe consentire l'esecuzione di codice a livello di kernel tramite l'invio di pacchetti opportunamente formattati. \u00c8 notevole che il problema sia stato scoperto durante l'analisi del codice da parte del modello AI di OpenAI o3. Poich\u00e9 il codice completo del modulo ksmbd supera la dimensione del contesto consentita per il modello, il controllo \u00e8 stato eseguito in fasi per il codice che implementa singoli comandi SMB, utilizzando richieste standard.    <\/p>\n<p>La vulnerabilit\u00e0 \u00e8 causata da un accesso alla memoria gi\u00e0 liberata (use-after-free) nel codice di gestione del comando SMB \u00ablogoff\u00bb: la struttura sess-&gt;user veniva utilizzata in un altro thread se, nell'ambito di un'altra connessione, arrivava una richiesta di impostazione della sessione, legata alla sessione liberata. Durante l'elaborazione di tali richieste veniva eseguita la funzione smb2_sess_setup, che accedeva gi\u00e0 alla struttura sess-&gt;user liberata.     <\/p>\n<p>La vulnerabilit\u00e0 \u00e8 stata risolta negli aggiornamenti 6.15-rc5, 6.14.6, 6.12.28, 6.6.90, 6.1.138. Nella branch 5.15, che include il modulo ksmbd, il problema non si manifesta. Puoi seguire la risoluzione della vulnerabilit\u00e0 nelle distribuzioni sulle seguenti pagine: Debian, Ubuntu, Fedora, SUSE\/openSUSE, RHEL, Arch.       <\/p>\n<p>Il problema \u00e8 stato scoperto da Sean Heelan, creatore della piattaforma di profilazione del codice Prodfiler, specializzato nell'ottimizzazione e nell'audit della sicurezza del codice. Sean ha deciso di valutare quanto siano pronte le moderne AI per condurre audit di sicurezza e ha concluso che il modello o3 ha fatto significativi progressi nell'analisi e nella comprensione della struttura, della logica e funzionalit\u00e0 del codice. \u00c8 stato notato che per identificare la vulnerabilit\u00e0, il modello \u00e8 riuscito a costruire una catena di ragionamento che tiene conto della possibilit\u00e0 di connessioni parallele all\u2019utilizzo di strutture dati in diverse situazioni. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/it\/server\/dts-shicago\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"2950\">server<\/a> Di conseguenza, il modello ha identificato il punto critico nel codice, in cui l'oggetto liberato rimaneva accessibile in un altro thread. Inoltre, il modello ha trovato il problema autonomamente basandosi semplicemente su una richiesta generale che chiedeva di controllare la presenza di vulnerabilit\u00e0 nel codice, ponendo l'accento sul controllo dei puntatori sospesi e sugli accessi alla memoria dopo la sua liberazione, escludendo falsi positivi e problemi ipotetici.       <\/p>\n<p>In conclusione, il modello ha rilevato il punto problematico nel codice, dove l'oggetto liberato era ancora accessibile in un altro thread. Ha trovato il problema autonomamente solo sulla base di una richiesta generale che chiedeva una verifica delle vulnerabilit\u00e0 nel codice, ponendo l'accento sul controllo dei puntatori pendenti e sugli accessi alla memoria dopo la liberazione, escludendo falsi positivi e problematiche ipotetiche.     <\/p>\n<p>Prima di cercare nuove vulnerabilit\u00e0, Sean ha testato diversi modelli per identificare la vulnerabilit\u00e0 CVE-2025-37778 in ksmbd, precedentemente individuata da lui durante un'audit manuale e corretta nell'aggiornamento del kernel 6.15-rc3. Il modello o3 ha gestito con successo il compito, mostrando un risultato molto vicino a quello dell'audit manuale, dopodich\u00e9 Sean si \u00e8 concentrato su esperimenti per scoprire vulnerabilit\u00e0 precedentemente sconosciute.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=63301\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 ksmbd, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u044e\u0449\u0435\u043c \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u0443\u044e \u0432 \u044f\u0434\u0440\u043e Linux \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 SMB, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-37899), \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432. \u041f\u0440\u0438\u043c\u0435\u0447\u0430\u0442\u0435\u043b\u044c\u043d\u043e, \u0447\u0442\u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0431\u044b\u043b\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0432 \u0445\u043e\u0434\u0435 \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u043a\u043e\u0434\u0430 AI-\u043c\u043e\u0434\u0435\u043b\u044c\u044e OpenAI o3. \u0422\u0430\u043a \u043a\u0430\u043a \u043f\u043e\u043b\u043d\u044b\u0439 \u043a\u043e\u0434 \u043c\u043e\u0434\u0443\u043b\u044f ksmbd \u043f\u0440\u0435\u0432\u044b\u0448\u0430\u0435\u0442 \u0434\u043e\u043f\u0443\u0441\u0442\u0438\u043c\u044b\u0439 \u0434\u043b\u044f \u043c\u043e\u0434\u0435\u043b\u0438 \u0440\u0430\u0437\u043c\u0435\u0440 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-125569","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 ksmbd, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u044e\u0449\u0435\u043c \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u0443\u044e \u0432 \u044f\u0434\u0440\u043e Linux \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 SMB, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-37899), \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/udalyonnaya-uyazvimost-v-module-ksmbd-yadra-linux-vyyavlennaya-pri-pomoshhi-ai\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043c\u043e\u0434\u0443\u043b\u0435 ksmbd \u044f\u0434\u0440\u0430 Linux, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u0430\u044f \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 AI | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 ksmbd, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u044e\u0449\u0435\u043c \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u0443\u044e \u0432 \u044f\u0434\u0440\u043e Linux \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 SMB, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-37899), \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/udalyonnaya-uyazvimost-v-module-ksmbd-yadra-linux-vyyavlennaya-pri-pomoshhi-ai\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-05-25T13:05:07+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-05-25T13:05:07+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vulnerabilit\u00e0 remota nel modulo ksmbd del kernel Linux, scoperta grazie all'AI | ProHoster","description":"Nel modulo ksmbd, che offre un'implementazione del server di file integrata nel kernel Linux basata sul protocollo SMB, \u00e8 stata rilevata una vulnerabilit\u00e0 (CVE-2025-37899) che potrebbe consentire l'esecuzione di codice a livello di kernel.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/udalyonnaya-uyazvimost-v-module-ksmbd-yadra-linux-vyyavlennaya-pri-pomoshhi-ai","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043c\u043e\u0434\u0443\u043b\u0435 ksmbd \u044f\u0434\u0440\u0430 Linux, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u0430\u044f \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 AI | ProHoster","og:description":"\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 ksmbd, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u044e\u0449\u0435\u043c \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u0443\u044e \u0432 \u044f\u0434\u0440\u043e Linux \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 SMB, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-37899), \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/udalyonnaya-uyazvimost-v-module-ksmbd-yadra-linux-vyyavlennaya-pri-pomoshhi-ai","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-05-25T13:05:07+00:00","article:modified_time":"2025-05-25T13:05:07+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"125569","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-09 22:10:05","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 13:00:19","updated":"2026-02-09 22:10:05","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/125569","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=125569"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/125569\/revisions"}],"predecessor-version":[{"id":160231,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/125569\/revisions\/160231"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=125569"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=125569"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=125569"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}