ืคืจื’ื ื–ื™ื” ื”ื™ื ืคื’ื™ืขื•ืช ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก ื”ืžืืคืฉืจืช ื’ื™ืฉืช root ืขืœ ื™ื“ื™ ืฉื™ื ื•ื™ ืžื˜ืžื•ืŸ ื”ื“ืฃ.

ืคื’ื™ืขื•ืช ืจื‘ื™ืขื™ืช (CVE-2026-46300) ื”ืชื’ืœืชื” ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก ื‘ืฉื‘ื•ืขื™ื™ื ื”ืื—ืจื•ื ื™ื. ืคื’ื™ืขื•ืช ื–ื• ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืœื ืžื•ืจืฉื” ืœืงื‘ืœ ื”ืจืฉืื•ืช root ืขืœ ื™ื“ื™ ื”ื—ืœืคืช ื ืชื•ื ื™ื ื‘ืžื˜ืžื•ืŸ ื”ื“ืฃ. ื”ืคื’ื™ืขื•ืช ืงื™ื‘ืœื” ืฉื ืงื•ื“ Fragnesia, ืื• Copy Fail 3.0. ื”ืคื’ื™ืขื•ืช ื“ื•ืžื” ืœืคื’ื™ืขื•ื™ื•ืช Copy Fail ื•-Dirty Frag ืฉื ื—ืฉืคื• ื‘ืขื‘ืจ. ื‘ื“ื•ืžื” ืœ-Dirty Frag, ื”ืคื’ื™ืขื•ืช ื”ื—ื“ืฉื” ืงื™ื™ืžืช ื‘ืชืช-ื”ืžืขืจื›ืช xfrm-ESP, ืืš ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื‘ืื’ ืื—ืจ ื•ื“ื•ืจืฉืช ืชื™ืงื•ืŸ ื ืคืจื“. ืงื™ื™ื ื ื™ืฆื•ืœ ืœืจืขื” ืคืขื™ืœ.

ื”ืคื’ื™ืขื•ืช ืžืชื‘ื˜ืืช ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก ืฉืคื•ืจืกืžื” ืœืื—ืจ ื”-5 ื‘ืžืื™ ืขืงื‘ ื”ืคืขืœื” ืžืงืจื™ืช ืฉืœ ื”ืคื’ื™ืขื•ืช Dirty Frag ืขืœ ื™ื“ื™ ืชื™ืงื•ืŸ. ื”ื•ืฆืข ืชื™ืงื•ืŸ ืขื‘ื•ืจ ืœื™ื‘ืช ืœื™ื ื•ืงืก ื›ื“ื™ ืœื˜ืคืœ ื‘ืคื’ื™ืขื•ืช Fragnesia. ื ื™ืชื•ื— ืชื™ืงื•ืŸ ื–ื” ื’ื™ืœื” ืฉื”ื•ื ืื™ื ื• ืžืกืคื™ืง, ืžื” ืฉื”ื•ื‘ื™ืœ ืœืคื™ืชื•ื— ืชื™ืงื•ืŸ ืฉื ื™.

ื”ืคื’ื™ืขื•ืช ืงื™ื™ืžืช ื‘ืžื™ืžื•ืฉ ืฉืœ ืžื ื’ื ื•ืŸ ื”ืงืคืกื•ืœืฆื™ื” Encapsulating Security Payload (ESP) ื‘-TCP (ESP-in-TCP, RFC 8229) ืขืœ ื™ื“ื™ ืชืช-ื”ืžืขืจื›ืช xfrm, ื”ืžืฉืžืฉ ืœื”ืขื‘ืจืช ืชืขื‘ื•ืจืช IPsec ื“ืจืš TCP. ื›ื“ื™ ืœืžื ื•ืข ืื—ืกื•ืŸ ืžื™ื•ืชืจื™ื, ืคืขื•ืœื•ืช ื”ืžืฉืชืžืฉื•ืช ื‘ืืœื’ื•ืจื™ืชื AES-GCM ื‘ื•ืฆืขื• ื‘ืžืงื•ื ืขืœ ื™ื“ื™ ื‘ื™ืฆื•ืข ืคืขื•ืœืช XOR ืขืœ ื ืชื•ื ื™ื ื‘ืžื˜ืžื•ืŸ ื”ื“ืฃ. ืฉื’ื™ืื” ืœื•ื’ื™ืช ื™ืฆืจื” ืชื ืื™ื ืฉืืคืฉืจื• ื“ืจื™ืกื” ืฉืœ ื‘ื™ื™ื˜ ื‘ื•ื“ื“ ื‘ืžื˜ืžื•ืŸ ื”ื“ืฃ ื‘ื”ื™ืกื˜ ืžื•ื’ื“ืจ. ื—ื–ืจื” ืขืœ ืคืขื•ืœื•ืช ืืœื• ืืคืฉืจื” ืœืฉื ื•ืช ืืช ืชื•ื›ืŸ ื›ืœ ืงื•ื‘ืฅ ื‘ืžื˜ืžื•ืŸ ื”ื“ืฃ ื‘ื™ื™ื˜ ืื—ืจ ื‘ื™ื™ื˜.

ื›ืœ ืคืขื•ืœื•ืช ืงืจื™ืืช ื”ืงื‘ืฆื™ื ืžืื—ื–ืจื•ืช ืชื—ื™ืœื” ืืช ื”ืชื•ื›ืŸ ืžืžื˜ืžื•ืŸ ื”ื“ืฃ. ืื ื”ื ืชื•ื ื™ื ื‘ืžื˜ืžื•ืŸ ื”ื“ืฃ ืžืฉืชื ื™ื, ืคืขื•ืœื•ืช ืงืจื™ืืช ื”ืงื‘ืฆื™ื ื™ื—ื–ื™ืจื• ื ืชื•ื ื™ื ืฉื”ื•ื—ืœืคื•, ืœื ืืช ื”ืžื™ื“ืข ื‘ืคื•ืขืœ ื”ืžืื•ื—ืกืŸ ื‘ื›ื•ื ืŸ. ื ื™ืฆื•ืœ ื”ืคื’ื™ืขื•ืช ื›ื•ืœืœ ืฉื™ื ื•ื™ ืžื˜ืžื•ืŸ ื”ื“ืฃ ืขื‘ื•ืจ ืงื•ื‘ืฅ ื”ืจืฆื” ืขื ื“ื’ืœ ื”ืฉื•ืจืฉ suid, ืืฉืจ ื ืงืจื ื‘ืขื‘ืจ ื›ื“ื™ ืœื”ื™ื•ืช ืžื•ื›ื ืก ืœืžื˜ืžื•ืŸ ื”ื“ืฃ. ื‘ื ื™ืฆื•ืœ ืฉื”ื•ืฆืข ืขืœ ื™ื“ื™ ื”ื—ื•ืงืจื™ื, 192 ื”ื‘ื™ื™ื˜ื™ื ื”ืจืืฉื•ื ื™ื ืฉืœ ืงื•ื‘ืฅ /usr/bin/su ื‘ืžื˜ืžื•ืŸ ื”ื“ืฃ ืžื•ื—ืœืคื™ื ื‘ืงื•ื“ ืœื”ืคืขืœืช /usr/bin/sh. ื”ืคืขืœื” ืœืื—ืจ ืžื›ืŸ ืฉืœ ื›ืœื™ ื”ืฉื™ืจื•ืช "su" ื’ื•ืจืžืช ืœื›ืš ืฉื”ืขื•ืชืง ืฉื”ืฉืชื ื” ืžืžื˜ืžื•ืŸ ื”ื“ืฃ ื ื˜ืขืŸ ืœื–ื™ื›ืจื•ืŸ, ื•ืœื ืงื•ื‘ืฅ ื”ื”ืคืขืœื” ื”ืžืงื•ืจื™ ืžื”ื›ื•ื ืŸ.

ื›ื“ื™ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ืฉืœ Fragnesia, ื™ืฉ ืœื”ืคืขื™ืœ ื™ืฆื™ืจืช ืžืจื—ื‘ ืฉืžื•ืช ืžืฉืชืžืฉื™ื ื‘ืžืขืจื›ืช. ื‘ืื•ื‘ื•ื ื˜ื•, ืืคืฉืจื•ืช ื–ื• ืžื•ืฉื‘ืชืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืืš ื ื™ืชืŸ ืœื”ืคืขื™ืœ ืื•ืชื” ื“ืจืš ืคืจื•ืคื™ืœื™ sysctl ืื• AppArmor "kernel.apparmor_restrict_unprivileged_userns=0". ื‘ื”ืคืฆื•ืช ืื—ืจื•ืช, ื ื’ื™ืฉื•ืช ืžืจื—ื‘ ืฉืžื•ืช ืžืฉืชืžืฉื™ื ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื ืœืœื ื”ืจืฉืื•ืช ืชืœื•ื™ื” ื‘ื”ื’ื“ืจื” sysctl "kernel.unprivileged_userns_clone" (ืื 0, ื”ื™ื ืžื•ืฉื‘ืชืช).

ืขื“ื›ื•ื ื™ื ืขื ืชื™ืงื•ื ื™ื ืขื‘ื•ืจ ืœื™ื‘ืช ืœื™ื ื•ืงืก ื•ื—ื‘ื™ืœื•ืช ืœื™ื‘ื” ื‘ื”ืคืฆื•ืช ื˜ืจื ืคื•ืจืกืžื•. ื ื™ืชืŸ ืœื”ืขืจื™ืš ืืช ืกื˜ื˜ื•ืก ืชื™ืงื•ื ื™ ื”ืคื’ื™ืขื•ื™ื•ืช ื‘ื”ืคืฆื•ืช ื‘ื“ืคื™ื ื”ื‘ืื™ื: ื“ื‘ื™ืืŸ, ืื•ื‘ื•ื ื˜ื•, SUSE/openSUSE, RHEL, ื’'ื ื˜ื•, ืืจื›ื™' ื•ืคื“ื•ืจื”. ื›ืคืชืจื•ืŸ ืขื•ืงืฃ, ื ื™ืชืŸ ืœื—ืกื•ื ืืช ื˜ืขื™ื ืช ืžื•ื“ื•ืœื™ ื”ืœื™ื‘ื” esp4 ื•-esp6:

sh -c "printf 'ื”ืชืงื ืช esp4 /bin/false\nื”ืชืงื ืช esp6 /bin/false\n' > /etc/modprobe.d/dirtyfrag.conf; rmmod esp4 esp6 2>/dev/null; true"

ืžืงื•ืจ: OpenNet.ru

ืงื ื” ืื™ืจื•ื— ืืžื™ืŸ ืœืืชืจื™ื ืขื ื”ื’ื ืช DDoS, ืฉืจืชื™ VPS VDS ๐Ÿ”ฅ ืงื ื” ืื—ืกื•ืŸ ืืชืจื™ื ืืžื™ืŸ ืขื ื”ื’ื ืช DDoS, ืฉืจืชื™ VPS VDS | ProHoster