{"id":104360,"date":"2022-06-12T09:36:50","date_gmt":"2022-06-12T07:36:50","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-firejail-pozvolyayushhaya-poluchit-root-dostup-v-sisteme"},"modified":"2022-06-12T09:36:50","modified_gmt":"2022-06-12T07:36:50","slug":"uyazvimost-v-firejail-pozvolyayushhaya-poluchit-root-dostup-v-sisteme","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-firejail-pozvolyayushhaya-poluchit-root-dostup-v-sisteme","title":{"rendered":"Nj\u00eb dob\u00ebsi n\u00eb firejail q\u00eb lejon marrjen e qasjes root n\u00eb sistem.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb mjetin p\u00ebr ekzekutimin e izoluar t\u00eb aplikacioneve Firejail u identifikua nj\u00eb dob\u00ebsi (CVE-2022-31214), e cila lejon nj\u00eb p\u00ebrdorues lokal t\u00eb fitoj\u00eb t\u00eb drejtat root n\u00eb sistemin kryesor. Nj\u00eb eksploit i punuesh\u00ebm \u00ebsht\u00eb n\u00eb dispozicion publik, e verifikuar n\u00eb versionet aktuale t\u00eb openSUSE, Debian, Arch, Gentoo dhe Fedora me mjetin firejail t\u00eb instaluar. Problemi \u00ebsht\u00eb zgjidhur n\u00eb versionin firejail 0.9.70. Si nj\u00eb m\u00ebnyr\u00eb alternative mbrojtjeje, mund t\u00eb vendosni n\u00eb konfigurimin (\\\/etc\\\/firejail\\\/firejail.config) parametrat \"join no\" dhe \"force-nonewprivs yes.\"      <\/p>\n<p>Firejail p\u00ebrdor mekanizmin e hap\u00ebsirave t\u00eb emrave (namespaces), AppArmor dhe filtrimin e thirrjeve sistemore (seccomp-bpf) n\u00eb Linux p\u00ebr izolim, por p\u00ebr t\u00eb konfiguruar ekzekutimin e izoluar k\u00ebrkon privilegje t\u00eb rritura, t\u00eb cilat i fiton p\u00ebrmes lidhjes me mjetin e flamurit suid root ose nga ekzekutimi me sudo. Dob\u00ebsia \u00ebsht\u00eb shkaktuar nga nj\u00eb gabim n\u00eb logjik\u00ebn e funksionit \"--join=\", i cili \u00ebsht\u00eb i destinuar p\u00ebr t'u lidhur me nj\u00eb ambient t\u00eb izoluar q\u00eb tashm\u00eb \u00ebsht\u00eb n\u00eb pun\u00eb (analog me komand\u00ebn login p\u00ebr ambientin sandbox) duke p\u00ebrcaktuar ambientin sipas identifikuesit t\u00eb procesit q\u00eb po punon. N\u00eb faz\u00ebn para se t\u00eb hiqen privilegjet, firejail p\u00ebrcakton privilegjet e procesit t\u00eb specifikuar dhe i aplikon ato n\u00eb nj\u00eb proces t\u00eb ri, t\u00eb lidhur me ambientin p\u00ebrmes opsionit \"--join.\"       <\/p>\n<p>Para se t\u00eb lidhesh, b\u00ebhet nj\u00eb verifikim p\u00ebr t\u00eb par\u00eb n\u00ebse procesi i specifikuar \u00ebsht\u00eb duke u ekzekutuar n\u00eb ambientin firejail. Kjo verifikim vler\u00ebson pranin\u00eb e skedarit \\\/run\\\/firejail\\\/mnt\\\/join. P\u00ebr t\u00eb shfryt\u00ebzuar dob\u00ebsin\u00eb, sulmuesi mund t\u00eb simuloj\u00eb nj\u00eb ambient t\u00eb pavarur firejail duke p\u00ebrdorur hap\u00ebsir\u00ebn e pikave t\u00eb montimit (mount namespace), pastaj t\u00eb lidhet me t\u00eb p\u00ebrmes opsionit \"--join.\" N\u00ebse n\u00eb konfigurim nuk \u00ebsht\u00eb aktivizuar modaliteti i ndalimit t\u00eb fitimit t\u00eb privilegjeve t\u00eb tjera n\u00eb proceset e reja (prctl NO_NEW_PRIVS), firejail do t\u00eb lidh\u00eb p\u00ebrdoruesin n\u00eb ambientin e simuluar dhe do t\u00eb p\u00ebrpiqet t\u00eb aplikoj\u00eb parametrat e hap\u00ebsir\u00ebs s\u00eb emrave t\u00eb identifikuesve t\u00eb p\u00ebrdoruesve (user namespace) t\u00eb procesit init (PID 1).     <\/p>\n<p>P\u00ebrfundimisht, procesi i lidhur p\u00ebrmes &#171;firejail &#8212;join&#187; do t\u00eb ndodhet n\u00eb hap\u00ebsir\u00ebn e identifikimit t\u00eb p\u00ebrdoruesve p\u00ebr p\u00ebrdoruesin, me privilegje t\u00eb pandryshuara, por n\u00eb nj\u00eb hap\u00ebsir\u00eb tjet\u00ebr pikash montimi, e cila kontrollohet plot\u00ebsisht nga sulmuesi. P\u00ebr m\u00eb tep\u00ebr, sulmuesi mund t\u00eb ekzekutoj\u00eb programe setuid-root n\u00eb hap\u00ebsir\u00ebn e tij t\u00eb pikave t\u00eb montimit, gj\u00eb q\u00eb lejon, p\u00ebr shembull, t\u00eb ndryshoj\u00eb konfigurimin e \"\/etc\/sudoers\" ose parametrat PAM n\u00eb hierarkin\u00eb e tij t\u00eb skedar\u00ebve dhe t\u00eb fitoj\u00eb mund\u00ebsin\u00eb p\u00ebr t\u00eb ekzekutuar komanda me t\u00eb drejtat root p\u00ebrmes mjeteve sudo ose su.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=57337\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 \u0434\u043b\u044f \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 Firejail \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-31214), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u0412 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u043c \u0434\u043e\u0441\u0442\u0443\u043f\u0435 \u0438\u043c\u0435\u0435\u0442\u0441\u044f \u0440\u0430\u0431\u043e\u0447\u0438\u0439 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442, \u043f\u0440\u043e\u0432\u0435\u0440\u0435\u043d\u043d\u044b\u0439 \u0432 \u0430\u043a\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u0445 openSUSE, Debian, Arch, Gentoo \u0438 Fedora \u0441 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0443\u0442\u0438\u043b\u0438\u0442\u043e\u0439 firejail. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0435 firejail 0.9.70. \u0412 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u043e\u0431\u0445\u043e\u0434\u043d\u043e\u0433\u043e \u043f\u0443\u0442\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u043c\u043e\u0436\u043d\u043e \u0432\u044b\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0432 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u0445 (\/etc\/firejail\/firejail.config) [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-104360","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 \u0434\u043b\u044f \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 Firejail \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-31214), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-firejail-pozvolyayushhaya-poluchit-root-dostup-v-sisteme\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 firejail, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 \u0434\u043b\u044f \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 Firejail \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-31214), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-firejail-pozvolyayushhaya-poluchit-root-dostup-v-sisteme\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-06-12T07:36:50+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-06-12T07:36:50+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitet n\u00eb firejail q\u00eb lejon qasje root n\u00eb sistem | ProHoster","description":"N\u00eb utilitetin p\u00ebr ekzekutimin e izoluar t\u00eb aplikacioneve Firejail \u00ebsht\u00eb zbuluar nj\u00eb vulnerabilitet (CVE-2022-31214) q\u00eb lejon nj\u00eb p\u00ebrdorues lokal t\u00eb fitoj\u00eb t\u00eb drejtat root n\u00eb sistemin kryesor.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-firejail-pozvolyayushhaya-poluchit-root-dostup-v-sisteme","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 firejail, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 | ProHoster","og:description":"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 \u0434\u043b\u044f \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 Firejail \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-31214), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-firejail-pozvolyayushhaya-poluchit-root-dostup-v-sisteme","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-06-12T07:36:50+00:00","article:modified_time":"2022-06-12T07:36:50+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"104360","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-25 11:46:55","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-06-12 07:37:45","updated":"2026-01-25 11:46:55","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/104360","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=104360"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/104360\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=104360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=104360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=104360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}