{"id":164054,"date":"2026-03-13T11:12:02","date_gmt":"2026-03-13T09:12:02","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-gssapi-patche-k-openssh-udalyonno-ekspluatiruemaya-na-stadii-do-autentifikaczii"},"modified":"2026-03-13T11:12:02","modified_gmt":"2026-03-13T09:12:02","slug":"uyazvimost-v-gssapi-patche-k-openssh-udalyonno-ekspluatiruemaya-na-stadii-do-autentifikaczii","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-gssapi-patche-k-openssh-udalyonno-ekspluatiruemaya-na-stadii-do-autentifikaczii","title":{"rendered":"Vulnerabilitate \u00een patch-ul GSSAPI pentru OpenSSH, exploatabil\u0103 de la distan\u021b\u0103 \u00een faza de dinaintea autentific\u0103rii.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00cen patch-ul gssapi.patch, folosit \u00een multe distribu\u021bii Linux, care adaug\u0103 suport pentru schimbul de chei bazat pe GSSAPI \u00een OpenSSH, a fost identificat\u0103 o vulnerabilitate (CVE-2026-3497) care duce la dereferirea unui pointer, coruperea memoriei \u0219i ocolirea mecanismului de separare a privilegiilor (Privsep). Vulnerabilitatea poate fi exploatat\u0103 de la distan\u021b\u0103 \u00eenainte de autentificare. Cercet\u0103torul care a identificat problema a demonstrat c\u0103 este posibil\u0103 ini\u021bierea unei opriri accidentale a procesului prin trimiterea unui pachet de re\u021bea modificat c\u0103tre serverul SSH. Nu se exclude c\u0103, pe l\u00e2ng\u0103 refuzul de serviciu, exist\u0103 \u0219i variante mai periculoase de exploatare a vulnerabilit\u0103\u021bii.      <\/p>\n<p>Este demn de remarcat c\u0103, la vremea respectiv\u0103, dezvoltatorii OpenSSH au refuzat s\u0103 includ\u0103 \u00een versiunea principal\u0103 modificarea pentru suportul GSSAPI din cauza \u00eendoielilor legate de siguran\u021ba sa. Cu toate acestea, multe distribu\u021bii Linux au inclus acest patch \u00een pachetele lor OpenSSH. Exist\u0103 mai multe versiuni ale patch-ului GSSAPI, dar \u00een majoritatea lor exist\u0103 o eroare care conduce la vulnerabilitate. Corec\u021bia este disponibil\u0103 momentan doar sub form\u0103 de patch, modificarea const\u00e2nd \u00een \u00eenlocuirea apelului la func\u021bia sshpkt_disconnect() cu ssh_packet_disconnect() \u00een fi\u0219ierul kexgsss.c.    <\/p>\n<p>\u00cen prezent, vulnerabilitatea este confirmat\u0103 \u00een Debian \u0219i Ubuntu. \u00cen celelalte distribu\u021bii, aplicarea patch-ului problematic \u0219i expunerea la vulnerabilitate sunt \u00een curs de clarificare (SUSE\/openSUSE, RHEL, Gentoo, Arch, Fedora). Vulnerabilitatea se manifest\u0103 doar c\u00e2nd op\u021biunea \u201eGSSAPIKeyExchange yes\u201d este activat\u0103 \u00een set\u0103ri. Posibilitatea exploat\u0103rii este, de asemenea, influen\u021bat\u0103 de op\u021biunile de compilare cu care pachetul a fost compilat \u00een distribu\u021bii.        <\/p>\n<p>Cauza apari\u021biei vulnerabilit\u0103\u021bii este o eroare \u00een func\u021bia sshpkt_disconnect(), care determina procesul s\u0103 nu se opreasc\u0103 dup\u0103 primirea unui mesaj de deconectare, permit\u00e2nd atacatorului, \u00een etapa de negociere a cheilor, s\u0103 trimit\u0103 un mesaj GSSAPI neprev\u0103zut de logica de func\u021bionare. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/ro\/server\/dts-los-angeles\/\" title=\"server\" data-wpil-keyword-link=\"linked\">server<\/a> tip de mesaj GSSAPI. Dup\u0103 primirea unui mesaj GSSAPI nea\u0219teptat,  <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/ro\/server\/\"   title=\"serverul\" data-wpil-keyword-link=\"linked\">serverul<\/a> \u00eel plaseaz\u0103 \u00een coad\u0103 \u0219i nu \u00eentrerupe executarea programului, dar nu ini\u021bializeaz\u0103 variabilele care definesc parametrii de conexiune. Ulterior, \u00een bucla de procesare a evenimentelor, este executat un cod care cite\u0219te structura neini\u021bializat\u0103 recv_tok din stiv\u0103 (se citesc datele r\u0103mase \u00een stiv\u0103 de la apelul anterior al func\u021biei), o trimite unui proces privilegiat prin IPC \u0219i apoi o paseaz\u0103 func\u021biei gss_release_buffer(), care poate apela func\u021bia free() \u0219i elibera memoria pentru un pointer incorect, referindu-se la o zon\u0103 aleatorie de memorie.<br \/>\n<br \/>Sursa: <a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=64983\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Linux \u043f\u0430\u0442\u0447\u0435 gssapi.patch, \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0432 OpenSSH \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0443 \u043e\u0431\u043c\u0435\u043d\u0430 \u043a\u043b\u044e\u0447\u0435\u0439 \u043d\u0430 \u0431\u0430\u0437\u0435 GSSAPI, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-3497), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0440\u0430\u0437\u044b\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u044e \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044f, \u043f\u043e\u0432\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u044e \u043f\u0430\u043c\u044f\u0442\u0438 \u0438 \u043e\u0431\u0445\u043e\u0434\u0443 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u0430 \u0440\u0430\u0437\u0434\u0435\u043b\u0435\u043d\u0438\u044f \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439 (Privsep). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u043d\u0430 \u0441\u0442\u0430\u0434\u0438\u0438 \u0434\u043e \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043b\u0435\u043d\u0438\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438. \u0412\u044b\u044f\u0432\u0438\u0432\u0448\u0438\u0439 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u043f\u0440\u043e\u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043b \u0438\u043d\u0438\u0446\u0438\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0433\u043e \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u043d\u0430 SSH-\u0441\u0435\u0440\u0432\u0435\u0440 \u043e\u0434\u043d\u043e\u0433\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-164054","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Linux \u043f\u0430\u0442\u0447\u0435 gssapi.patch, \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0432 OpenSSH \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0443 \u043e\u0431\u043c\u0435\u043d\u0430 \u043a\u043b\u044e\u0447\u0435\u0439 \u043d\u0430 \u0431\u0430\u0437\u0435 GSSAPI, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-3497), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0440\u0430\u0437\u044b\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u044e \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044f, \u043f\u043e\u0432\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u044e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-gssapi-patche-k-openssh-udalyonno-ekspluatiruemaya-na-stadii-do-autentifikaczii\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 GSSAPI-\u043f\u0430\u0442\u0447\u0435 \u043a OpenSSH, \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u043d\u0430 \u0441\u0442\u0430\u0434\u0438\u0438 \u0434\u043e \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Linux \u043f\u0430\u0442\u0447\u0435 gssapi.patch, \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0432 OpenSSH \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0443 \u043e\u0431\u043c\u0435\u043d\u0430 \u043a\u043b\u044e\u0447\u0435\u0439 \u043d\u0430 \u0431\u0430\u0437\u0435 GSSAPI, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-3497), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0440\u0430\u0437\u044b\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u044e \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044f, \u043f\u043e\u0432\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u044e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-gssapi-patche-k-openssh-udalyonno-ekspluatiruemaya-na-stadii-do-autentifikaczii\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-03-13T09:12:02+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-03-13T09:12:02+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitate \u00een patch-ul GSSAPI la OpenSSH, exploatabil de la distan\u021b\u0103 \u00een faza anterioar\u0103 autentific\u0103rii | ProHoster","description":"\u00cen patch-ul gssapi.patch utilizat \u00een multe distribuitive Linux, care adaug\u0103 suport pentru schimbul de chei bazat pe GSSAPI \u00een OpenSSH, a fost identificat\u0103 o vulnerabilitate (CVE-2026-3497) care duce la dereferen\u021bierea pointerului \u0219i coruperea acestuia.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-gssapi-patche-k-openssh-udalyonno-ekspluatiruemaya-na-stadii-do-autentifikaczii","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 GSSAPI-\u043f\u0430\u0442\u0447\u0435 \u043a OpenSSH, \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u043d\u0430 \u0441\u0442\u0430\u0434\u0438\u0438 \u0434\u043e \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 | ProHoster","og:description":"\u0412 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Linux \u043f\u0430\u0442\u0447\u0435 gssapi.patch, \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0432 OpenSSH \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0443 \u043e\u0431\u043c\u0435\u043d\u0430 \u043a\u043b\u044e\u0447\u0435\u0439 \u043d\u0430 \u0431\u0430\u0437\u0435 GSSAPI, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-3497), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0440\u0430\u0437\u044b\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u044e \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044f, \u043f\u043e\u0432\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u044e.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-gssapi-patche-k-openssh-udalyonno-ekspluatiruemaya-na-stadii-do-autentifikaczii","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-03-13T09:12:02+00:00","article:modified_time":"2026-03-13T09:12:02+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/164054","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=164054"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/164054\/revisions"}],"predecessor-version":[{"id":173149,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/164054\/revisions\/173149"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=164054"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=164054"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=164054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}