{"id":100168,"date":"2021-05-14T16:23:07","date_gmt":"2021-05-14T14:23:07","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-podsisteme-ebpf-pozvolyayushhie-vypolnit-kod-na-urovne-yadra-linux"},"modified":"2021-05-14T16:23:07","modified_gmt":"2021-05-14T14:23:07","slug":"uyazvimosti-v-podsisteme-ebpf-pozvolyayushhie-vypolnit-kod-na-urovne-yadra-linux","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-podsisteme-ebpf-pozvolyayushhie-vypolnit-kod-na-urovne-yadra-linux","title":{"rendered":"Vulnerabilitetet n\u00eb n\u00ebn-sistemin e eBPF, t\u00eb cilat lejojn\u00eb ekzekutimin e kodit n\u00eb nivelin e b\u00ebrtham\u00ebs Linux","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Jan\u00eb zbuluar dy dob\u00ebsi t\u00eb reja n\u00eb n\u00ebnnd\u00ebrtes\u00ebn e eBPF, e cila lejon ekzekutimin e trajtuesve brenda b\u00ebrtham\u00ebs Linux n\u00eb nj\u00eb makin\u00eb virtuale speciale me JIT. T\u00eb dyja dob\u00ebsit\u00eb ofrojn\u00eb mund\u00ebsin\u00eb p\u00ebr t\u00eb ekzekutuar kodin tuaj me t\u00eb drejtat e b\u00ebrtham\u00ebs, jasht\u00eb makin\u00ebs virtuale t\u00eb izoluara eBPF. Informacioni mbi probleme \u00ebsht\u00eb publikuar nga ekipi i Zero Day Initiative, i cili organizon garat Pwn2Own, gjat\u00eb t\u00eb cilave k\u00ebt\u00eb vit u demonstruan tre sulme ndaj Ubuntu Linux, t\u00eb cilat p\u00ebrdor\u00ebn dob\u00ebsi t\u00eb panjohura m\u00eb par\u00eb (nuk \u00ebsht\u00eb raportuar n\u00ebse dob\u00ebsit\u00eb n\u00eb eBPF lidhen me k\u00ebto sulme).   <\/p>\n<ul>\n<li class=\"l\"> CVE-2021-3490 \u2014 nj\u00eb vulnerabilitet i shkaktuar nga mungesa e kontrollit t\u00eb daljes p\u00ebrtej kufijve t\u00eb vlerave 32-bit gjat\u00eb kryerjes s\u00eb operacioneve bitore AND, OR dhe XOR n\u00eb eBPF ALU32. Nj\u00eb sulmues mund t\u00eb shfryt\u00ebzoj\u00eb k\u00ebt\u00eb gabim p\u00ebr t\u00eb lexuar dhe shkruar t\u00eb dh\u00ebna jasht\u00eb kufijve t\u00eb memorie t\u00eb rezervuar. Problemi me operacionin XOR shfaqet q\u00eb nga versioni 5.7-rc1 i b\u00ebrtham\u00ebs, nd\u00ebrsa AND dhe OR \u2014 q\u00eb nga publikimi 5.10-rc1.\n<li class=\"l\"> CVE-2021-3489 \u2014 nj\u00eb vulnerabilitet i shkaktuar nga nj\u00eb gabim n\u00eb implementimin e buffer-it t\u00eb unaz\u00ebs dhe lidhet me faktin se funksioni bpf_ringbuf_reserve nuk kontrollonte n\u00ebse madh\u00ebsia e hap\u00ebsir\u00ebs s\u00eb rezervuar mund t\u00eb ishte m\u00eb e vog\u00ebl se madh\u00ebsia reale e buffer-it t\u00eb unaz\u00ebs ringbuf. Problemi shfaqet q\u00eb nga publikimi 5.8-rc1.  <\/ul>\n<p>Statusi i rregullimeve t\u00eb dob\u00ebsive n\u00eb shp\u00ebrndarjet mund t\u00eb ndjeket n\u00eb k\u00ebto faqe: Ubuntu, Debian, RHEL, Fedora, SUSE, Arch. Rregullimet jan\u00eb gjithashtu t\u00eb disponueshme n\u00eb form\u00ebn e patch-eve (CVE-2021-3489, CVE-2021-3490). Mund\u00ebsia p\u00ebr t\u00eb shfryt\u00ebzuar problemin varet nga disponueshm\u00ebria e thirrjes sistemike eBPF p\u00ebr p\u00ebrdoruesin. P\u00ebr shembull, n\u00eb konfigurimin e parazgjedhur n\u00eb RHEL, p\u00ebr t\u00eb shfryt\u00ebzuar dob\u00ebsin\u00eb k\u00ebrkohet q\u00eb p\u00ebrdoruesi t\u00eb ket\u00eb t\u00eb drejtat CAP_SYS_ADMIN.         <\/p>\n<p>Ve\u00e7an\u00ebrisht, mund t\u00eb p\u00ebrmendet nj\u00eb tjet\u00ebr vulnerabilitet n\u00eb b\u00ebrtham\u00ebn Linux \u2014 CVE-2021-32606, i cili lejon nj\u00eb p\u00ebrdorues lokal t\u00eb rris\u00eb privilegjet e tij n\u00eb nivelin root. Problemi shfaqet q\u00eb nga b\u00ebrthama Linux 5.11 dhe shkaktohet nga nj\u00eb gjendje garanc\u00eb n\u00eb implementimin e protokollit CAN ISOTP, e cila lejon ndryshimin e parametrave t\u00eb lidhjes me soketin p\u00ebr shkak t\u00eb munges\u00ebs s\u00eb vendosjes s\u00eb bllokimeve t\u00eb duhura n\u00eb funksionin isotp_setsockopt() gjat\u00eb p\u00ebrpunimit t\u00eb flagut CAN_ISOTP_SF_BROADCAST.    <\/p>\n<p>Pas mbylljes s\u00eb soketit, ISOTP vazhdon t\u00eb ruaj\u00eb lidhjen me soketin e marr\u00ebsit, i cili mund t\u00eb vazhdoj\u00eb t\u00eb p\u00ebrdor\u00eb struktura t\u00eb lidhura me soketin pas lirimit t\u00eb memorjes s\u00eb lidhur me to (use-after-free p\u00ebr shkak t\u00eb fuqizimit gjat\u00eb thirrjes isotp_rcv() n\u00eb nj\u00eb struktur\u00eb isotp_sock q\u00eb \u00ebsht\u00eb liruar tashm\u00eb). N\u00ebp\u00ebrmjet manipulimeve me t\u00eb dh\u00ebnat, mund t\u00eb arrihet t\u00eb mbizot\u00ebrohet treguesi n\u00eb funksionin sk_error_report() dhe t\u00eb ekzekutohet kodi juaj n\u00eb nivelin e b\u00ebrtham\u00ebs.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55150\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 eBPF, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0442\u044c \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0432\u043d\u0443\u0442\u0440\u0438 \u044f\u0434\u0440\u0430 Linux \u0432 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0439 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u0435 \u0441 JIT. \u041e\u0431\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0434\u0430\u044e\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u044f\u0434\u0440\u0430, \u0432\u043d\u0435 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u044b eBPF. \u0418\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u0445 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u043a\u043e\u043c\u0430\u043d\u0434\u0430 Zero Day Initiative, \u043f\u0440\u043e\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u0441\u043e\u0440\u0435\u0432\u043d\u043e\u0432\u0430\u043d\u0438\u044f Pwn2Own, \u0432 \u0445\u043e\u0434\u0435 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0432 \u044d\u0442\u043e\u043c \u0433\u043e\u0434\u0443 \u0431\u044b\u043b\u0438 \u043f\u0440\u043e\u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u0442\u0440\u0438 \u0430\u0442\u0430\u043a\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-100168","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 eBPF, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0442\u044c \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0432\u043d\u0443\u0442\u0440\u0438 \u044f\u0434\u0440\u0430 Linux \u0432 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0439 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u0435 \u0441 JIT.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-podsisteme-ebpf-pozvolyayushhie-vypolnit-kod-na-urovne-yadra-linux\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 eBPF, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 Linux | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 eBPF, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0442\u044c \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0432\u043d\u0443\u0442\u0440\u0438 \u044f\u0434\u0440\u0430 Linux \u0432 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0439 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u0435 \u0441 JIT.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-podsisteme-ebpf-pozvolyayushhie-vypolnit-kod-na-urovne-yadra-linux\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-05-14T14:23:07+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-05-14T14:23:07+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitetet n\u00eb n\u00ebndeg\u00ebn e eBPF, q\u00eb lejojn\u00eb ekzekutimin e kodit n\u00eb nivelin e b\u00ebrtham\u00ebs Linux | ProHoster","description":"Jan\u00eb zbuluar dy vulnerabilitete t\u00eb reja n\u00eb n\u00ebndeg\u00ebn e eBPF, e cila lejon ekzekutimin e trajtuesve brenda b\u00ebrtham\u00ebs Linux n\u00eb nj\u00eb makin\u00eb virtuale speciale me JIT.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-podsisteme-ebpf-pozvolyayushhie-vypolnit-kod-na-urovne-yadra-linux","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 eBPF, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 Linux | ProHoster","og:description":"\u0412\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 eBPF, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0442\u044c \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0432\u043d\u0443\u0442\u0440\u0438 \u044f\u0434\u0440\u0430 Linux \u0432 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0439 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u0435 \u0441 JIT.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-podsisteme-ebpf-pozvolyayushhie-vypolnit-kod-na-urovne-yadra-linux","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-05-14T14:23:07+00:00","article:modified_time":"2021-05-14T14:23:07+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"100168","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-05-14 21:05:35","updated":"2022-10-09 15:55:52","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/100168","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=100168"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/100168\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=100168"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=100168"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=100168"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}