{"id":108438,"date":"2023-05-09T12:48:21","date_gmt":"2023-05-09T10:48:21","guid":{"rendered":"https:\/\/prohoster.info\/?p=108438"},"modified":"2023-05-10T08:54:54","modified_gmt":"2023-05-10T06:54:54","slug":"uyazvimosti-v-netfilter-i-io_uring-pozvolyayushhie-povysit-svoi-privilegii-v-sisteme","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-netfilter-i-io_uring-pozvolyayushhie-povysit-svoi-privilegii-v-sisteme","title":{"rendered":"Dob\u00ebsi n\u00eb Netfilter dhe io_uring, q\u00eb lejojn\u00eb rritjen e privilegjeve n\u00eb sistem","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb n\u00ebn-sistemet e b\u00ebrtham\u00ebs Linux Netfilter dhe io_uring jan\u00eb zbuluar vulnerabilitete q\u00eb lejojn\u00eb nj\u00eb p\u00ebrdorues lokal t\u00eb rris\u00eb privilegjet e tij n\u00eb sistem:  <\/p>\n<ul>\n<li class=\"l\"> Vulnerabiliteti (CVE-2023-32233) n\u00eb n\u00ebn-sistemin Netfilter, i shkaktuar nga qasja n\u00eb memorie pas lirimit t\u00eb saj (use-after-free) n\u00eb modulin nf_tables, i cili siguron funksionimin e filtrit t\u00eb paketave nftables. Ky vulnerabilitet mund t\u00eb shfryt\u00ebzohet duke d\u00ebrguar k\u00ebrkesa t\u00eb formatuara n\u00eb m\u00ebnyr\u00eb t\u00eb ve\u00e7ant\u00eb p\u00ebr p\u00ebrdit\u00ebsimin e konfigurimit t\u00eb nftables. P\u00ebr t\u00eb realizuar sulmin, nevojitet akses n\u00eb nftables, i cili mund t\u00eb merret n\u00eb nj\u00eb hap\u00ebsir\u00eb rrjetesh t\u00eb ve\u00e7anta (network namespaces) me t\u00eb drejtat CLONE_NEWUSER, CLONE_NEWNS ose CLONE_NEWNET (p.sh., n\u00eb rastin e mund\u00ebsis\u00eb p\u00ebr t\u00eb nisur nj\u00eb kontejner t\u00eb izoluar).\n<p>P\u00ebr t\u00eb dh\u00ebn\u00eb p\u00ebrdoruesve koh\u00eb p\u00ebr t\u00eb instaluar p\u00ebrdit\u00ebsimet, hulumtuesi q\u00eb zbuloi problemin premtoi t\u00eb shtyj\u00eb p\u00ebr nj\u00eb jav\u00eb (deri m\u00eb 15 maj) publikimin e informacionit t\u00eb detajuar dhe nj\u00eb shembulli t\u00eb nj\u00eb eksperimenti funksional q\u00eb ofron shell root. Vulnerabiliteti \u00ebsht\u00eb eliminuar n\u00eb p\u00ebrdit\u00ebsimin 6.4-rc1. Mund t\u00eb ndiqni korrigjimin e vulnerabilitetit n\u00eb shp\u00ebrndarjet n\u00eb k\u00ebto faqe: Debian, Ubuntu, Gentoo, RHEL, Fedora, SUSE\/openSUSE, Arch.      <\/p>\n<li class=\"l\"> Vulnerabiliteti (CVE ende nuk i \u00ebsht\u00eb caktuar) n\u00eb implementimin e nd\u00ebrfaqes p\u00ebr hyrje dhe dalje asinkrone io_uring, e cila \u00ebsht\u00eb pjes\u00eb e b\u00ebrtham\u00ebs Linux q\u00eb nga publikimi 5.1. Problemi \u00ebsht\u00eb shkaktuar nga nj\u00eb gabim n\u00eb funksionin io_sqe_buffer_register, i cili lejon aksesin n\u00eb memorin\u00eb fizike jasht\u00eb nj\u00eb buffer-i t\u00eb alokuar statikisht. Problemi shfaqet vet\u00ebm n\u00eb deg\u00ebn 6.3 dhe do t\u00eb eliminohet n\u00eb p\u00ebrdit\u00ebsimin e ardhsh\u00ebm 6.3.2. Nj\u00eb prototip funksional i eksploitit \u00ebsht\u00eb tashm\u00eb i disponuesh\u00ebm p\u00ebr testim, i cili lejon ekzekutimin e kodit me privilegjet e b\u00ebrtham\u00ebs.\n<ul>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59101\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u044f\u0434\u0440\u0430 Linux Netfilter \u0438 io_uring \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435: \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-32233) \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 Netfilter, \u0432\u044b\u0437\u0432\u0430\u043d\u043d\u0430\u044f \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0435\u043c \u043a \u043f\u0430\u043c\u044f\u0442\u0438 \u043f\u043e\u0441\u043b\u0435 \u0435\u0451 \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0435\u043d\u0438\u044f (use-after-free) \u0432 \u043c\u043e\u0434\u0443\u043b\u0435 nf_tables, \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u044e\u0449\u0435\u043c \u0440\u0430\u0431\u043e\u0442\u0443 \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u043d\u0430 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 nftables. \u0414\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u0442\u0440\u0435\u0431\u0443\u0435\u0442\u0441\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-108438","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u044f\u0434\u0440\u0430 Linux Netfilter \u0438 io_uring \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435: \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-32233) \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 Netfilter.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-netfilter-i-io_uring-pozvolyayushhie-povysit-svoi-privilegii-v-sisteme\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Netfilter \u0438 io_uring, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u044f\u0434\u0440\u0430 Linux Netfilter \u0438 io_uring \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435: \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-32233) \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 Netfilter.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-netfilter-i-io_uring-pozvolyayushhie-povysit-svoi-privilegii-v-sisteme\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-05-09T10:48:21+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-05-10T06:54:54+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitete n\u00eb Netfilter dhe io_uring q\u00eb lejojn\u00eb rritjen e privilegjeve n\u00eb sistem | ProHoster","description":"N\u00eb n\u00ebn-sistemet e b\u00ebrtham\u00ebs Linux Netfilter dhe io_uring jan\u00eb zbuluar vulnerabilitete q\u00eb lejojn\u00eb nj\u00eb p\u00ebrdorues lokal t\u00eb rris\u00eb privilegjet e tij n\u00eb sistem: Vulnerabiliteti (CVE-2023-32233) n\u00eb n\u00ebn-sistemin Netfilter.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-netfilter-i-io_uring-pozvolyayushhie-povysit-svoi-privilegii-v-sisteme","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Netfilter \u0438 io_uring, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 | ProHoster","og:description":"\u0412 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u044f\u0434\u0440\u0430 Linux Netfilter \u0438 io_uring \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435: \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-32233) \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 Netfilter.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-netfilter-i-io_uring-pozvolyayushhie-povysit-svoi-privilegii-v-sisteme","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-05-09T10:48:21+00:00","article:modified_time":"2023-05-10T06:54:54+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/108438","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=108438"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/108438\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=108438"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=108438"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=108438"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}