{"id":103411,"date":"2022-02-22T15:37:00","date_gmt":"2022-02-22T13:37:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-podsisteme-netfilter-pozvolyayushhaya-vypolnit-kod-na-urovne-yadra-linux"},"modified":"2022-02-22T15:37:00","modified_gmt":"2022-02-22T13:37:00","slug":"uyazvimost-v-podsisteme-netfilter-pozvolyayushhaya-vypolnit-kod-na-urovne-yadra-linux","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-podsisteme-netfilter-pozvolyayushhaya-vypolnit-kod-na-urovne-yadra-linux","title":{"rendered":"Dhembshmeria n\u00eb njesin\u00eb netfilter, q\u00eb lejon ekzekutimin e kodit n\u00eb nivelin e kernelit t\u00eb Linux","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb Netfilter, n\u00ebn-sistemi i kernelit Linux q\u00eb p\u00ebrdoret p\u00ebr filtrimin dhe modifikimin e paketave rrjet, \u00ebsht\u00eb zbuluar nj\u00eb e dh\u00ebn\u00eb e rrezikshme (CVE-2022-25636) q\u00eb lejon ekzekutimin e kodit n\u00eb nivelin e kernelit. \u00cbsht\u00eb raportuar p\u00ebr p\u00ebrgatitjen e nj\u00eb shembulli t\u00eb eksploitit q\u00eb lejon nj\u00eb p\u00ebrdorues lokal t\u00eb rris\u00eb privilegjet e tij n\u00eb Ubuntu 21.10 me mekanizmin e mbrojtjes KASLR t\u00eb \u00e7aktivizuar. Problemi manifestohet q\u00eb nga kernel 5.4. Nj\u00eb zgjidhje aktualisht \u00ebsht\u00eb e disponueshme n\u00eb form\u00eb pat\u00e7i (versionet korrektuese t\u00eb kernelit nuk jan\u00eb formuar ende). Mund t\u00eb ndiqni publikimet e p\u00ebrdit\u00ebsimeve t\u00eb paketave n\u00eb shp\u00ebrndarjet n\u00eb k\u00ebto faqe: Debian, SUSE, Ubuntu, RHEL, Fedora, Gentoo, Arch Linux.    <\/p>\n<p>D\u00ebshtimi \u00ebsht\u00eb shkaktuar nga nj\u00eb gabim n\u00eb llogaritjen e madh\u00ebsis\u00eb s\u00eb matriz\u00ebs flow-&gt;rule-&gt;action.entries n\u00eb funksionin nft_fwd_dup_netdev_offload (i p\u00ebrcaktuar n\u00eb skedarin net\/netfilter\/nf_dup_netdev.c), i cili mund t\u00eb \u00e7oj\u00eb n\u00eb shkrimin e t\u00eb dh\u00ebnave t\u00eb kontrolluara nga sulmuesi n\u00eb nj\u00eb hap\u00ebsir\u00eb memorie jasht\u00eb buz\u00ebs s\u00eb alokuar. Gabimi shfaqet gjat\u00eb konfigurimit t\u00eb rregullave \"dup\" dhe \"fwd\" n\u00eb zinxhir\u00eb, p\u00ebr t\u00eb cilat aplikohet p\u00ebrshpejtimi harduerik i p\u00ebrpunimit t\u00eb paketave (offload). Pasi tejkalimi ndodh n\u00eb faz\u00ebn para krijimit t\u00eb rregullit t\u00eb filtrimit t\u00eb paketa dhe verifikimit t\u00eb mb\u00ebshtetjes p\u00ebr offload, kjo vulnerabilitet \u00ebsht\u00eb gjithashtu e aplikueshme p\u00ebr pajisjet rrjetore q\u00eb nuk mb\u00ebshtesin p\u00ebrshpejtim harduerik, si\u00e7 \u00ebsht\u00eb nd\u00ebrfaqja loopback.        <\/p>\n<p> K\u00ebtu theksohet se problemi \u00ebsht\u00eb mjaft i leht\u00eb p\u00ebr t'u shfryt\u00ebzuar, pasi q\u00eb vlerat q\u00eb dalin jasht\u00eb buferit mund t\u00eb shkruajn\u00eb mbi treguesin e struktur\u00ebs net_device, dhe t\u00eb dh\u00ebnat mbi vler\u00ebn e shkruar rikthehen n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit, \u00e7ka lejon t\u00eb dihen adresat e nevojshme p\u00ebr kryerjen e sulmit n\u00eb memorie. P\u00ebr t\u00eb shfryt\u00ebzuar k\u00ebt\u00eb e dh\u00ebn\u00eb, k\u00ebrkohet krijimi i disa rregullave n\u00eb nftables, q\u00eb \u00ebsht\u00eb e mundur vet\u00ebm n\u00ebse ka privilegje CAP_NET_ADMIN, t\u00eb cilat mund t\u00eb fitojn\u00eb nj\u00eb p\u00ebrdorues jo privilegjuar n\u00eb nj\u00eb hap\u00ebsir\u00eb t\u00eb ve\u00e7ant\u00eb t\u00eb emrave rrjet (network namespaces). E dh\u00ebna e rrezikshme gjithashtu mund t\u00eb p\u00ebrdoret p\u00ebr sulme n\u00eb sistemet e izolimit t\u00eb kontejner\u00ebve.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56742\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 Netfilter, \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Linux, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u0438 \u043c\u043e\u0434\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-25636), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430. \u0417\u0430\u044f\u0432\u043b\u0435\u043d\u043e \u043e \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043a\u0435 \u043f\u0440\u0438\u043c\u0435\u0440\u0430 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u0430, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0433\u043e \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 Ubuntu 21.10 c \u043e\u0442\u043a\u043b\u044e\u0447\u0451\u043d\u043d\u044b\u043c \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u043e\u043c \u0437\u0430\u0449\u0438\u0442\u044b KASLR. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 \u044f\u0434\u0440\u0430 5.4. \u0418\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u043f\u043e\u043a\u0430 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u043e \u0432 \u0432\u0438\u0434\u0435 \u043f\u0430\u0442\u0447\u0430 (\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u044f\u0434\u0440\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-103411","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 Netfilter, \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Linux, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u0438 \u043c\u043e\u0434\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-25636), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-podsisteme-netfilter-pozvolyayushhaya-vypolnit-kod-na-urovne-yadra-linux\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 netfilter, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 Linux | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 Netfilter, \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Linux, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u0438 \u043c\u043e\u0434\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-25636), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-podsisteme-netfilter-pozvolyayushhaya-vypolnit-kod-na-urovne-yadra-linux\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-02-22T13:37:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-02-22T13:37:00+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47E dh\u00ebna e rrezikshme n\u00eb n\u00ebn-sistemin netfilter, e cila lejon ekzekutimin e kodit n\u00eb nivelin e kernelit Linux | ProHoster","description":"N\u00eb Netfilter, n\u00ebn-sistemi i kernelit Linux q\u00eb p\u00ebrdoret p\u00ebr filtrimin dhe modifikimin e paketave rrjet, \u00ebsht\u00eb zbuluar nj\u00eb e dh\u00ebn\u00eb e rrezikshme (CVE-2022-25636) q\u00eb lejon ekzekutimin e kodit n\u00eb nivelin e kernelit.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-podsisteme-netfilter-pozvolyayushhaya-vypolnit-kod-na-urovne-yadra-linux","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 netfilter, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 Linux | ProHoster","og:description":"\u0412 Netfilter, \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Linux, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u0438 \u043c\u043e\u0434\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-25636), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-podsisteme-netfilter-pozvolyayushhaya-vypolnit-kod-na-urovne-yadra-linux","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-02-22T13:37:00+00:00","article:modified_time":"2022-02-22T13:37:00+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"103411","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-02-22 13:37:41","updated":"2022-09-30 11:50:10","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/103411","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=103411"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/103411\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=103411"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=103411"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=103411"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}