{"id":103645,"date":"2022-03-29T15:37:18","date_gmt":"2022-03-29T13:37:19","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/v-yadre-linux-vyyavleny-ekspluatiruemye-uyazvimosti-v-nf_tables-watch_queue-i-ipsec"},"modified":"2022-03-29T15:37:18","modified_gmt":"2022-03-29T13:37:19","slug":"v-yadre-linux-vyyavleny-ekspluatiruemye-uyazvimosti-v-nf_tables-watch_queue-i-ipsec","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/v-yadre-linux-vyyavleny-ekspluatiruemye-uyazvimosti-v-nf_tables-watch_queue-i-ipsec","title":{"rendered":"Jan\u00eb zbuluar vulnerabilitete t\u00eb shfryt\u00ebzueshme n\u00eb kernelin Linux n\u00eb nf_tables, watch_queue dhe IPsec","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb kernin e Linux jan\u00eb identifikuar disa dob\u00ebsi t\u00eb rrezikshme q\u00eb lejojn\u00eb p\u00ebrdoruesin lokal t\u00eb rris\u00eb privilegjet e tij n\u00eb sistem. Jan\u00eb p\u00ebrgatitur prototipa funksional\u00eb t\u00eb eksploit\u00ebve p\u00ebr t\u00eb gjitha problemet e shqyrtuara.    <\/p>\n<ul>\n<li class=\"l\"> Vulnerabiliteti (CVE-2022-0995) n\u00eb n\u00ebnstruktur\u00ebn e gjurmimit t\u00eb ngjarjeve watch_queue, i cili shkakton shkruarjen e t\u00eb dh\u00ebnave n\u00eb hap\u00ebsir\u00ebn e memories s\u00eb b\u00ebrtham\u00ebs p\u00ebrtej buffer-it t\u00eb caktuar. Sulmi mund t\u00eb kryhet nga \u00e7do p\u00ebrdorues i pa privilegjuar dhe mund t\u00eb \u00e7oj\u00eb n\u00eb ekzekutimin e kodit t\u00eb tij me t\u00eb drejtat e b\u00ebrtham\u00ebs. Vulnerabiliteti \u00ebsht\u00eb i pranish\u00ebm n\u00eb funksionin watch_queue_set_size() dhe \u00ebsht\u00eb i lidhur me p\u00ebrpjekjen p\u00ebr t\u00eb pastruar t\u00eb gjith\u00eb treguesit n\u00eb list\u00eb, edhe n\u00ebse nuk \u00ebsht\u00eb caktuar hap\u00ebsir\u00eb p\u00ebr ta. Problemi shfaqet kur b\u00ebrthama \u00ebsht\u00eb nd\u00ebrtuar me opsionin \"CONFIG_WATCH_QUEUE=y\", i cili p\u00ebrdoret n\u00eb shumic\u00ebn e shp\u00ebrndarjeve t\u00eb Linux.\n<p>Dob\u00ebsia \u00ebsht\u00eb eliminuar n\u00eb nj\u00eb ndryshim t\u00eb shtuar n\u00eb kernel m\u00eb 11 mars. Mund t\u00eb ndiqni publikimin e p\u00ebrdit\u00ebsimeve t\u00eb paketave n\u00eb distribuimet n\u00eb k\u00ebto faqe: Debian, SUSE, Ubuntu, RHEL, Fedora, Gentoo, Arch Linux. Prototipi i eksploitit tashm\u00eb \u00ebsht\u00eb n\u00eb dispozicion publik dhe lejon marrjen e aksesit root kur ekzekutohet n\u00eb Ubuntu 21.10 me kernel 5.13.0-37.      <center><img decoding=\"async\" alt=\"Jan\u00eb zbuluar vulnerabilitete t\u00eb shfryt\u00ebzueshme n\u00eb kernelin Linux n\u00eb nf_tables, watch_queue dhe IPsec\" src=\"\/wp-content\/uploads\/2022\/03\/9cdfd5bdf66d257757d1a4c600b96249.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/center>    <\/p>\n<li class=\"l\"> Dob\u00ebsia (CVE-2022-27666) n\u00eb modulet e kernit esp4 dhe esp6 me implementimin e transformimeve ESP (Encapsulating Security Payload) p\u00ebr IPsec, q\u00eb p\u00ebrdoren gjat\u00eb p\u00ebrdorimit t\u00eb IPv4 dhe IPv6. Dob\u00ebsia lejon nj\u00eb p\u00ebrdorues lokal me privilegje t\u00eb zakonshme t\u00eb rinovoj\u00eb objektet n\u00eb memorjen e kernit dhe t\u00eb rris\u00eb privilegjet e tij n\u00eb sistem. Problemi shkaktohet nga mungesa e verifikimit t\u00eb madh\u00ebsis\u00eb s\u00eb ndar\u00eb t\u00eb memorjes dhe t\u00eb dh\u00ebnave faktike t\u00eb marra, n\u00eb at\u00eb q\u00eb madh\u00ebsia maksimale e mesazhit mund t\u00eb tejkaloj\u00eb madh\u00ebsin\u00eb maksimale t\u00eb memorjes t\u00eb ndar\u00eb p\u00ebr struktur\u00ebn skb_page_frag_refill.\n<p>Dob\u00ebsia \u00ebsht\u00eb eliminuar n\u00eb kernel m\u00eb 7 mars (e rregulluar n\u00eb 5.17, 5.16.15 etj.). Mund t\u00eb ndiqni publikimin e p\u00ebrdit\u00ebsimeve t\u00eb paketave n\u00eb distribuimet n\u00eb k\u00ebto faqe: Debian, SUSE, Ubuntu, RHEL, Fedora, Gentoo, Arch Linux. Prototipi funksional i eksploitit, i cili lejon nj\u00eb p\u00ebrdorues t\u00eb zakonsh\u00ebm t\u00eb marr\u00eb akses root n\u00eb Ubuntu Desktop 21.10 n\u00eb konfigurimin e paracaktuar, tashm\u00eb \u00ebsht\u00eb publikuar n\u00eb GitHub. Raportohet se me disa ndryshime t\u00eb vogla eksploitit do t\u00eb jet\u00eb gjithashtu funksional n\u00eb Fedora dhe Debian. Vlen t\u00eb theksohet se eksploitit ishte fillimisht p\u00ebrgatitur p\u00ebr garat pwn2own 2022, por zhvilluesit e kernit zbuluan dhe rregulluan gabimin lidhur me t\u00eb, prandaj u vendos t\u00eb zbuloheshin detajet e dob\u00ebsis\u00eb.      <center>  <video controls=\"\" style=\"width: 720px; height: 480px; max-width:100%\" src=\"https:\/\/etenal.me\/wp-content\/uploads\/2022\/03\/yes_root.mp4\" ><source src=\"https:\/\/etenal.me\/wp-content\/uploads\/2022\/03\/yes_root.mp4\" type=\"video\/mp4\"><\/video><\/center>    <\/p>\n<li class=\"l\"> Dy dy, dy dyshime (CVE-2022-1015, CVE-2022-1016) n\u00eb n\u00ebn-sistemin netfilter n\u00eb modulit nf_tables, i cili siguron funksionimin e filtrit t\u00eb paketave nftables. Problemi i par\u00eb lejon nj\u00eb p\u00ebrdorues lokal pa privilegje t\u00eb arrij\u00eb shkrimin jasht\u00eb buffer-it t\u00eb alokuar n\u00eb stok. Shkarkimi ndodh gjat\u00eb p\u00ebrpunimit t\u00eb shprehjeve nftables t\u00eb formuara nj\u00eb m\u00ebnyr\u00eb t\u00eb caktuar, t\u00eb p\u00ebrpunuara n\u00eb faz\u00ebn e verifikimit t\u00eb indekseve t\u00eb vendosur nga p\u00ebrdoruesi, i cili ka qasje n\u00eb rregullat nftables.\n<p>Vulnerabiliteti shkaktohet nga fakti se zhvilluesit supozuan se vlera \"enum nft_registers reg\" \u00ebsht\u00eb nj\u00eb bajt, megjithat\u00eb, kur aktivizohen optimizime t\u00eb caktuara, kompajleri n\u00eb p\u00ebrputhje me specifikimet C89 mund t\u00eb p\u00ebrdor\u00eb nj\u00eb vler\u00eb 32-bit\u00ebshe p\u00ebr t\u00eb. P\u00ebr shkak t\u00eb k\u00ebtij karakteri, madh\u00ebsia e p\u00ebrdorur gjat\u00eb verifikimit dhe caktimit t\u00eb memories nuk korrespondon me madh\u00ebsin\u00eb aktuale t\u00eb t\u00eb dh\u00ebnave n\u00eb struktur\u00eb, duke \u00e7uar n\u00eb mbivendosjen e bishtit t\u00eb struktur\u00ebs n\u00eb treguesit n\u00eb struktur\u00ebn e grumbullit.    <\/p>\n<p>Problemi mund t\u00eb shfryt\u00ebzohet p\u00ebr ekzekutimin e kodit t\u00eb tij n\u00eb nivelin e b\u00ebrtham\u00ebs, por p\u00ebr nj\u00eb sulm t\u00eb suksessh\u00ebm k\u00ebrkohet akses n\u00eb nftables, i cili mund t\u00eb fitohet n\u00eb nj\u00eb hap\u00ebsir\u00eb t\u00eb ve\u00e7ant\u00eb rrjeti (network namespaces) me t\u00eb drejtat CLONE_NEWUSER ose CLONE_NEWNET (p\u00ebr shembull, n\u00ebse ka mund\u00ebsi t\u00eb ekzekutimit nga nj\u00eb kontejner i izoluar). Vulnerabiliteti gjithashtu \u00ebsht\u00eb i lidhur ngusht\u00eb me optimizimet e aplikuara nga kompajleri, t\u00eb cilat aktivizohen, p\u00ebr shembull, gjat\u00eb nd\u00ebrtimit n\u00eb modin \"CONFIG_CC_OPTIMIZE_FOR_PERFORMANCE=y\". Shfryt\u00ebzimi i vulnerabilitetit \u00ebsht\u00eb i mundur duke filluar nga b\u00ebrthama Linux 5.12.    <\/p>\n<p>Dob\u00ebsia e dyt\u00eb n\u00eb netfilter \u00ebsht\u00eb shkaktuar nga referimi n\u00eb nj\u00eb zon\u00eb t\u00eb lir\u00eb memorjeje (use-after-free) n\u00eb menaxherin nft_do_chain dhe mund t\u00eb \u00e7oj\u00eb n\u00eb rrjedhje t\u00eb zonave t\u00eb pa inicializuara t\u00eb memories s\u00eb b\u00ebrtham\u00ebs, t\u00eb cilat mund t\u00eb lexohen p\u00ebrmes manipulimeve me shprehjet nftables dhe t\u00eb p\u00ebrdoren, p\u00ebr shembull, p\u00ebr t\u00eb p\u00ebrcaktuar adresat e treguesve gjat\u00eb zhvillimit t\u00eb eksploit\u00ebve p\u00ebr dob\u00ebsi t\u00eb tjera. Shfryt\u00ebzimi i dob\u00ebsis\u00eb \u00ebsht\u00eb i mundur duke filluar nga b\u00ebrthama Linux 5.13.    <\/p>\n<p>Dobit\u00eb jan\u00eb eliminuar n\u00eb p\u00ebrdit\u00ebsimet korective t\u00eb sotme t\u00eb b\u00ebrtham\u00ebs 5.17.1, 5.16.18, 5.15.32, 5.10.109, 5.4.188, 4.19.237, 4.14.274 dhe 4.9.309. Mund t\u00eb ndiqni publikimet e p\u00ebrdit\u00ebsimeve t\u00eb paketave n\u00eb distribuimet e m\u00ebsip\u00ebrme n\u00eb k\u00ebto faqe: Debian, SUSE, Ubuntu, RHEL, Fedora, Gentoo, Arch Linux. Hulumtuesi q\u00eb zbuloj problemet deklaroi se ka p\u00ebrgatitur eksploit\u00eb funksional\u00eb p\u00ebr t\u00eb dy dobt\u00ebsit\u00eb, t\u00eb cilat pritet t\u00eb publikohen pas disa dit\u00ebsh, pasi distribuimet t\u00eb l\u00ebshojn\u00eb p\u00ebrdit\u00ebsimet e paketave me b\u00ebrtham\u00ebn.      <\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56931\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u0414\u043b\u044f \u0432\u0441\u0435\u0445 \u0440\u0430\u0441\u0441\u043c\u0430\u0442\u0440\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u044b \u0440\u0430\u0431\u043e\u0447\u0438\u0435 \u043f\u0440\u043e\u0442\u043e\u0442\u0438\u043f\u044b \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u043e\u0432. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-0995) \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u043e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u043d\u0438\u044f \u0441\u043e\u0431\u044b\u0442\u0438\u0439 watch_queue, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0437\u0430\u043f\u0438\u0441\u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u043f\u0430\u043c\u044f\u0442\u0438 \u044f\u0434\u0440\u0430 \u0437\u0430 \u043f\u0440\u0435\u0434\u0435\u043b\u043e\u043c \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0431\u0443\u0444\u0435\u0440\u0430. \u0410\u0442\u0430\u043a\u0430 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0430 \u043b\u044e\u0431\u044b\u043c \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c \u0438 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0437\u0430\u043f\u0443\u0441\u043a\u0443 \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":103646,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-103645","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u0414\u043b\u044f \u0432\u0441\u0435\u0445 \u0440\u0430\u0441\u0441\u043c\u0430\u0442\u0440\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u044b \u0440\u0430\u0431\u043e\u0447\u0438\u0435 \u043f\u0440\u043e\u0442\u043e\u0442\u0438\u043f\u044b \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u043e\u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/v-yadre-linux-vyyavleny-ekspluatiruemye-uyazvimosti-v-nf_tables-watch_queue-i-ipsec\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 nf_tables, watch_queue \u0438 IPsec | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u0414\u043b\u044f \u0432\u0441\u0435\u0445 \u0440\u0430\u0441\u0441\u043c\u0430\u0442\u0440\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u044b \u0440\u0430\u0431\u043e\u0447\u0438\u0435 \u043f\u0440\u043e\u0442\u043e\u0442\u0438\u043f\u044b \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u043e\u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/v-yadre-linux-vyyavleny-ekspluatiruemye-uyazvimosti-v-nf_tables-watch_queue-i-ipsec\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-03-29T13:37:19+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-03-29T13:37:19+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Dhet\u00eb t\u00eb shfryt\u00ebzueshme jan\u00eb zbuluar n\u00eb b\u00ebrtham\u00ebn Linux n\u00eb nf_tables, watch_queue dhe IPsec | ProHoster","description":"N\u00eb kernin e Linux jan\u00eb identifikuar disa dob\u00ebsi t\u00eb rrezikshme q\u00eb lejojn\u00eb p\u00ebrdoruesin lokal t\u00eb rris\u00eb privilegjet e tij n\u00eb sistem. Jan\u00eb p\u00ebrgatitur prototipa funksional\u00eb t\u00eb eksploit\u00ebve p\u00ebr t\u00eb gjitha problemet e shqyrtuara.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/v-yadre-linux-vyyavleny-ekspluatiruemye-uyazvimosti-v-nf_tables-watch_queue-i-ipsec","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 nf_tables, watch_queue \u0438 IPsec | ProHoster","og:description":"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u0414\u043b\u044f \u0432\u0441\u0435\u0445 \u0440\u0430\u0441\u0441\u043c\u0430\u0442\u0440\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u044b \u0440\u0430\u0431\u043e\u0447\u0438\u0435 \u043f\u0440\u043e\u0442\u043e\u0442\u0438\u043f\u044b \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u043e\u0432.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/v-yadre-linux-vyyavleny-ekspluatiruemye-uyazvimosti-v-nf_tables-watch_queue-i-ipsec","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-03-29T13:37:19+00:00","article:modified_time":"2022-03-29T13:37:19+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"103645","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-03-29 13:38:31","updated":"2022-09-30 01:21:24","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/103645","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=103645"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/103645\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/103646"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=103645"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=103645"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=103645"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}