Zdalna podatność typu root w obsłudze automatycznej konfiguracji IPv6 w FreeBSD

W działającym w FreeBSD procesie w tle rtsold i narzędziu rtsol zidentyfikowano podatność (CVE-2025-14558), która umożliwia zdalne wykonanie kodu z uprawnieniami roota poprzez wysłanie specjalnie przygotowanego pakietu z ogłoszeniem routera IPv6. Wiadomości RA (Router Advertisement), przez które wykorzystywana jest podatność, nie są routowane i powinny być odrzucane przez routery. Aby przeprowadzić atak, napastnik musi mieć możliwość wysłania specjalnie skonstruowanego pakietu z systemu znajdującego się w tym samym segmencie sieciowym co podatny host.

Proces w tle rtsold stosowany jest na hostach do automatycznej konfiguracji połączenia przez IPv6 przy użyciu mechanizmu SLAAC (StateLess Address AutoConfiguration). Host wysyła wiadomość ICMPv6 RS (Router Solicitation) w trybie multicast i czeka na odpowiedź w postaci wiadomości RA (Router Advertisement) od routerów, które zawierają informacje o prefiksach sieciowych i parametrach konfiguracji. Narzędzie rtsol realizuje podobne funkcje bez uruchamiania procesu w tle.

Vulnerability is caused by rtsold passing the "domain search" list specified in the RA message to the resolvconf utility without validating correctness and without escaping special characters. The resolvconf utility is a shell script that does not validate input. To exploit the vulnerability, it is enough to send an RA packet with the name domeny, containing special characters, such as "test`id`test. The vulnerability has been fixed in FreeBSD updates 15.0-RELEASE-p1, 14.3-RELEASE-p7, 13.5-RELEASE-p8.

Additionally, in the updates FreeBSD 14.3-RELEASE-p7 and 13.5-RELEASE-p8 (the 15.x branch is not affected), a vulnerability (CVE-2025-14769) in the ipfw packet filter has been fixed, allowing denial of service through the sending of specially crafted packets. The vulnerability manifests only when using the "tcp-setmss" directive in ipfw rules. The issue is caused by the tcp-setmss handler, which under certain circumstances can free the memory that stores the received packet data and return an error. This error was ignored by the rule processing engine, causing the subsequent rule to possibly allow the passage of a packet whose data buffer has already been freed, leading to a null pointer dereference.

Źródło: opennet.ru

Kup solidny hosting stron z ochroną przed DDoS, serwery VPS VDS 🔥 Kup solidny hosting stron z ochroną przed DDoS, serwery VPS VDS | ProHoster