Dobësitë në FreeBSD, të cilat lejojnë ngritjen e privilegjeve dhe ekzekutimin e kodit në distancë

Në FreeBSD janë eliminuar 22 vulneraibilitete, nga të cilat një mund të lejojë potencialisht ekzekutimin e kodit në distancë me të drejta root, ndërsa 13 ofrojnë mundësi për të rritur privilegjet në sistem. Vulerabilitetet janë eliminuar në përditësimet FreeBSD 15.1-RELEASE-p1, FreeBSD 15.0-RELEASE-p11, 14.4-RELEASE-p7 dhe 14.3-RELEASE-p16.

Vulnerabiliteti më i rrezikshëm (CVE-2026-49420) shkaktohet nga mbushja e tamponit në bibliotekën libalias, e cila përdoret në filtrin e paketave ipfw që funksionon në nivelin e bërthamës dhe në procesin background natd që ekzekutohet në hapësirën e përdoruesit për përkthimin e adresave të paketeve rrjetore që dërgohen ose priten. Mbushja ndodhte në trajtuesin e protokollit RTSP (Protokolli i Transmetimit në Kohë Reale), i cili riprodhonte paketat rrjetore dalëse duke përdorur një tampon me madhësi fikse pa kontrolluar nëse rezultati i riprodhimit të paketës mund të hapet brenda tij.

Gjatë trajtimit të trafik bum që vjen nga RTSP në NAT-gatishmëri, mund të ndodhë mbushje e sapunit, e cila potencialisht mund të çojë në ekzekutimin e kodit në nivelin e bërthamës ose të procesit natd, që funksionon në sistem me të drejta root.

Si rrugë alternative për të bllokuar vulnerabilitetin, mund të bllokoni ngarkimin e modulit të bërthamës alias_smedia.ko dhe të hiqni përmendjen e trajtuesit libalias_smedia.so nga skedari i konfigurimit /etc/libalias.conf. Nëse protokolli RTSP nuk përdoret në murin e zjarrit, mund të bllokoni trafikun në portet 554 dhe 7070 në rregullat e caktuara para se të aktivizohen rregullat NAT.

Vulnerabilitetet që çojnë në marrjen e të drejtave root nga një përdorues lokal me privilegje të ulëta:

  • CVE-2026-49415 — njĂ« gjendje garansh nĂ« thirrjen sistemore execve, e cila lejon njĂ« pĂ«rdorues lokal, gjatĂ« ekzekutimit tĂ« skedarĂ«ve ekzekutivĂ« me flamurin SUID root, tĂ« modifikojĂ« hapĂ«sirĂ«n adresore tĂ« procesit pĂ«rmes procfs ose linprocfs nĂ« njĂ« dritare tĂ« vogĂ«l kohore, qĂ« ndodh pas vendosjes sĂ« hapĂ«sirĂ«s sĂ« re virtuale tĂ« adresĂ«s pĂ«r procesin, por para azhurnimit tĂ« tĂ« dhĂ«nave mbi pronarin e tij.
  • CVE-2026-49422 — referimi ndaj memories sĂ« liruar tashmĂ« (Use-after-free) nĂ« modulin e bĂ«rthamĂ«s tcp_rack.ko me implementimin e algoritmit pĂ«r identifikimin e humbjes sĂ« paketeve TCP RACK (Pranimi i fundit). Vulnerabiliteti mund tĂ« shfrytĂ«zohet pĂ«r tĂ« rritur privilegjet pĂ«rmes manipulimeve me njĂ« soket lokal.
  • CVE-2026-49419 — overflow of the link counter underflow in the implementation of the Jail isolation mechanism. Through manipulations with jail environments using jail descriptors via the jail_set and jail_get functions, an attacker can reset the link counter and free memory for a structure that continues to be used in the kernel, which can potentially be exploited to escalate privileges.
  • CVE-2026-49429 — buffer overflow in OpenZFS, allowing a local user with ZFS 'userused' permissions to escalate privileges through manipulations with ioctl ZFS_IOC_USERSPACE_MANY.
  • CVE-2026-49427, CVE-2026-49428 — vulnerabilities in the implementation of 'largepage' shared memory objects, leading to access to already freed memory in the kernel, which can be exploited to escalate privileges through manipulations with the sendfile function with the SF_NOCACHE flag or with the open and fspacectl functions with the O_TRUNC flag.
  • CVE-2026-49421 — improper handling of the AT_RESOLVE_BENEATH flag in the unlinkat and funlinkat system calls can be used to delete files outside the base directory in configurations with restricted access to the file system.
  • CVE-2026-49418 — access to memory after it has been freed in the virtual memory subsystem, occurring when calling the msync(MS_INVALIDATE) function for device memory mapping. An attacker with access to a device supporting memory mapping can exploit the vulnerability to escalate privileges.
  • CVE-2026-49416 — integer overflow in the vt console driver, allowing a local user to potentially escalate privileges by sending ioctl CONS_HISTORY with an overly large size.
  • CVE-2026-49413 — vulnerability in Linuxulator allowing an unprivileged user to substitute their shared library through the LD_PRELOAD environment variable in an executable file with the suid flag and run their code with the privileges of that executable.
  • CVE-2026-49412 — access to already freed memory in the IPV6_MSFILTER option handler in sockets, allowing escalation of privileges.
  • CVE-2026-45258 — issues with the implementation of memory mapping support (mmap) in the sound driver, allowing reading and writing data in kernel memory areas through manipulations with the /dev/dsp device, which is by default writable by everyone.
  • CVE-2026-45257 — njĂ« vulnerabilitet nĂ« modulĂ«n e bĂ«rthamĂ«s ktls, i cili lejon ri-shkrimin nĂ« cache-n e faqeve tĂ« çdo skedari qĂ« Ă«shtĂ« i arritshĂ«m pĂ«r tu lexuar nga sulmuesi. Duke ri-shkruar nĂ« kĂ«tĂ« mĂ«nyrĂ« njĂ« skedar tĂ« tipit suid root, pĂ«r shembull, /bin/su, sulmuesi mund tĂ« fitojĂ« tĂ« drejtat root nĂ« sistem.

Vulnerabilitetet më pak të rrezikshme:

  • CVE-2026-49430, CVE-2026-49431 — vulnerabilitete nĂ« OpenZFS, qĂ« çojnĂ« nĂ« dĂ«mtimin e memorjes sĂ« bĂ«rthamĂ«s dhe mundĂ«sinĂ« e vendosjes sĂ« flamurit "$hasrecvd", pa pasur autorizimin e nevojshĂ«m.
  • CVE-2026-49426 — krijimi i papĂ«rshtatshĂ«m i regjistrimeve tĂ« auditit pĂ«r thirrjet ptrace. Kjo mund tĂ« pĂ«rdoret nga sulmuesi pĂ«r tĂ« anashkaluar sistemet e zbulimit tĂ« sulmeve.
  • CVE-2026-49423 — njĂ« vulnerabilitet DoS nĂ« distancĂ« nĂ« nĂ«nsistemin e bĂ«rthamĂ«s KTLS, i cili Ă«shtĂ« i shfrytĂ«zuar pĂ«rmes dĂ«rgimit tĂ« paketave TLS tĂ« dizajnuara posaçërisht. Problemi shfaqet vetĂ«m nĂ« sistemet qĂ« pĂ«rdorin KTLS pĂ«r tĂ« pĂ«rshpejtur pĂ«rpunimin e TLS (kern.ipc.tls.enable=1).
  • CVE-2026-49424 — njĂ« rrjedhje prej 104 bajtĂ«sh nga steka e papĂ«rgatitur e bĂ«rthamĂ«s nĂ« implementimin e thirrjes sĂ« sistemit waitid() nĂ« Linuxulator.
  • CVE-2026-49425 — njĂ« rrjedhje tĂ« dhĂ«nash nga steka e papĂ«rgatitur e bĂ«rthamĂ«s nĂ« nĂ«nsistemin compat32.
  • CVE-2026-58081, CVE-2026-58082 — mbushje buffer-i nĂ« bibliotekĂ«n iconv, tĂ« cilat mund tĂ« pĂ«rdoren pĂ«r sulme ndaj aplikacioneve qĂ« pĂ«rdorin iconv pĂ«r tĂ« konvertuar tĂ« dhĂ«nat e jashtme tĂ« pasigurta nĂ« kodime HZ, UTF-7, VIQR, ZW dhe ISO-2022.

Burimi: opennet.ru

Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS đŸ”„ Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS | ProHoster