{"id":170544,"date":"2026-05-09T12:24:31","date_gmt":"2026-05-09T10:24:32","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-sistemnom-vyzove-execve-predostavlyayushhaya-root-dostup-vo-freebsd"},"modified":"2026-05-09T12:24:31","modified_gmt":"2026-05-09T10:24:32","slug":"uyazvimost-v-sistemnom-vyzove-execve-predostavlyayushhaya-root-dostup-vo-freebsd","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-sistemnom-vyzove-execve-predostavlyayushhaya-root-dostup-vo-freebsd","title":{"rendered":"Vulnerabilitate \u00een apelul de sistem execve, oferind acces root \u00een FreeBSD","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>A fost descoperit\u0103 o vulnerabilitate \u00een FreeBSD (CVE-2026-7270) care permite unui utilizator neprivilegiat s\u0103 execute cod cu drepturi de kernel \u0219i s\u0103 ob\u021bin\u0103 acces root la sistem. Vulnerabilitatea afecteaz\u0103 toate versiunile FreeBSD lansate din 2013. Un exploit a fost publicat, a c\u0103rui func\u021bionare a fost verificat\u0103 pe sistemele cu FreeBSD 11.0 p\u00e2n\u0103 la 14.4. Vulnerabilitatea a fost remediat\u0103 \u00een actualiz\u0103rile FreeBSD 15.0-RELEASE-p7, 14.4-RELEASE-p3, 14.3-RELEASE-p12 \u0219i 13.5-RELEASE-p13. Pentru versiuni mai vechi, se poate utiliza un patch.      <\/p>\n<p>Problema este cauzat\u0103 de o dep\u0103\u0219ire a tamponului \u00een apelul de sistem execve, care apare \u00een procesarea prefixului specificat \u00een prima linie a scripturilor pentru a determina calea c\u0103tre interpretator (de exemplu, #!\/bin\/sh). Dep\u0103\u0219irea apare la apelul func\u021biei memmove din cauza compunerii gre\u0219ite a unei expresii matematice pentru a calcula dimensiunea argumentelor copiate \u00een tampon. \u00cen loc s\u0103 se scad\u0103 din args-&gt;endp valorile args-&gt;begin_argv \u0219i consume, din args-&gt;endp s-a sc\u0103zut doar valoarea args-&gt;begin_argv, iar variabila consume a fost ad\u0103ugat\u0103 la rezultat, ceea ce \u00eenseamn\u0103 c\u0103 s-au copiat mai multe date cu dou\u0103 valori consume. memmove(args-&gt;begin_argv + extend, args-&gt;begin_argv + consume, - args-&gt;endp - args-&gt;begin_argv + consume); + args-&gt;endp - (args-&gt;begin_argv + consume));         <\/p>\n<p>Dep\u0103\u0219irea permite rescrierea elementelor structurii exec_map aflate \u00een vecin\u0103tatea altui proces. \u00cen exploit, dep\u0103\u0219irea este folosit\u0103 pentru a rescrie con\u021binutul exec_map al proceselor privilegiate care sunt periodic executate \u00een sistem. Ca un astfel de proces este ales sshd, care, de fiecare dat\u0103 c\u00e2nd se stabile\u0219te o conexiune de re\u021bea, creeaz\u0103 prin apelul fork \u0219i execve procesul \/usr\/libexec\/sshd-session cu privilegii root.     <\/p>\n<p>Exploitul injecteaz\u0103 pentru acest proces variabila de mediu LD_PRELOAD=\/tmp\/evil.so, ceea ce duce la \u00eenc\u0103rcarea bibliotecii sale \u00een contextul sshd-session. Biblioteca injectat\u0103 creeaz\u0103 \u00een sistemul de fi\u0219iere un fi\u0219ier executabil \/tmp\/rootsh cu flag-ul suid root. Probabilitatea de succes a dep\u0103\u0219irii este estimat\u0103 la 0,6%, dar datorit\u0103 repet\u0103rii ciclice a \u00eencerc\u0103rilor, exploatarea reu\u0219it\u0103 se ob\u021bine \u00een aproximativ 6 secunde pe un sistem cu CPU quad-core.      <center><img decoding=\"async\" alt=\"Vulnerabilitate \u00een apelul de sistem execve, oferind acces root \u00een FreeBSD\" src=\"\/wp-content\/uploads\/2026\/05\/6d8779e37e52d9af205b881f8e8a065c.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>    <\/p>\n<p>\u00cen plus, \u00een FreeBSD au fost remediate \u0219i alte c\u00e2teva vulnerabilit\u0103\u021bi:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2026-35547, CVE-2026-39457 \u2014 buffer overflows in the libnv library, used in the kernel and in base system applications for processing key\/value formatted lists and for organizing data transfer during inter-process communication. The first issue arises from incorrect message size calculations when processing specially formatted IPC message headers. The second issue leads to stack overflow during data exchange through a socket due to the lack of checks to ensure that the socket descriptor size matches the buffer size used in the select() function. Potential vulnerabilities can be exploited to elevate privileges within the system.\n<li class=\"l\"> CVE-2026-42512 \u2014 a remotely exploitable buffer overflow in dhclient, occurring due to incorrect calculations of the pointer array size used to pass environment variables to dhclient-script. The possibility of creating an exploit for remote code execution via the transmission of specially crafted DHCP packets cannot be ruled out.\n<li class=\"l\"> CVE-2026-7164 \u2014 stack overflow in the pf packet filter, occurring when processing specially crafted SCTP packets. The issue is caused by unrestricted recursive parsing of SCTP parameters.\n<li class=\"l\"> CVE-2026-42511 \u2014 the ability to substitute arbitrary directives in dhclient.conf due to improper escaping of double brackets in the BOOTP fields obtained from an external DHCP server. During subsequent parsing of this file by the dhclient process, the field specified by the attacker is passed to dhclient-script, which may be used to execute arbitrary commands with root privileges on systems using dhclient when connecting to a compromised DHCP server controlled by the attacker.\n<li class=\"l\"> CVE-2026-6386 \u2014 inadequate handling of large memory pages in the kernel function pmap_pkru_update_range(). An unprivileged user can cause pmap_pkru_update_range() to treat user space memory as a page in the memory page table, leading to the rewriting of a memory area that should not be accessible.\n<li class=\"l\"> CVE-2026-5398 \u2014 accessing already freed memory in the TIOCNOTTY handler, allowing an unprivileged process to gain root rights.        <\/ul>\n<p>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65408\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u043e FreeBSD \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-7270), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u044f\u0434\u0440\u0430 \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u0432\u0441\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 FreeBSD, \u0441\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u0441 2013 \u0433\u043e\u0434\u0430. \u0412 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u043c \u0434\u043e\u0441\u0442\u0443\u043f\u0435 \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442, \u0440\u0430\u0431\u043e\u0442\u0430 \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u043f\u0440\u043e\u0432\u0435\u0440\u0435\u043d\u0430 \u043d\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u0441 FreeBSD 11.0 \u043f\u043e 14.4. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f\u0445 FreeBSD 15.0-RELEASE-p7, 14.4-RELEASE-p3, 14.3-RELEASE-p12 \u0438 13.5-RELEASE-p13. \u0414\u043b\u044f \u0431\u043e\u043b\u0435\u0435 \u0441\u0442\u0430\u0440\u044b\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":170545,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-170544","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u043e FreeBSD \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-7270), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u044f\u0434\u0440\u0430 \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0441\u0438\u0441\u0442\u0435\u043c\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-sistemnom-vyzove-execve-predostavlyayushhaya-root-dostup-vo-freebsd\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u043c \u0432\u044b\u0437\u043e\u0432\u0435 execve, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0430\u044f root-\u0434\u043e\u0441\u0442\u0443\u043f \u0432\u043e FreeBSD | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u043e FreeBSD \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-7270), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u044f\u0434\u0440\u0430 \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0441\u0438\u0441\u0442\u0435\u043c\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-sistemnom-vyzove-execve-predostavlyayushhaya-root-dostup-vo-freebsd\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-05-09T10:24:32+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-05-09T10:24:32+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitate \u00een apelul de sistem execve, oferind acces root \u00een FreeBSD | ProHoster","description":"\u00cen FreeBSD a fost identificat\u0103 o vulnerabilitate (CVE-2026-7270), care permite unui utilizator f\u0103r\u0103 privilegii s\u0103 execute cod cu drepturi de kernel \u0219i s\u0103 ob\u021bin\u0103 acces root la sistem.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-sistemnom-vyzove-execve-predostavlyayushhaya-root-dostup-vo-freebsd","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u043c \u0432\u044b\u0437\u043e\u0432\u0435 execve, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0430\u044f root-\u0434\u043e\u0441\u0442\u0443\u043f \u0432\u043e FreeBSD | ProHoster","og:description":"\u0412\u043e FreeBSD \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-7270), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u044f\u0434\u0440\u0430 \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0441\u0438\u0441\u0442\u0435\u043c\u0435.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-sistemnom-vyzove-execve-predostavlyayushhaya-root-dostup-vo-freebsd","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-05-09T10:24:32+00:00","article:modified_time":"2026-05-09T10:24:32+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/170544","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=170544"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/170544\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media\/170545"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=170544"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=170544"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=170544"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}