{"id":114603,"date":"2024-03-27T12:25:57","date_gmt":"2024-03-27T10:25:58","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-yadre-linux-pozvolyayushhie-podnyat-svoi-privilegii-cherez-nf_tables-i-ksmbd"},"modified":"2024-03-27T12:25:57","modified_gmt":"2024-03-27T10:25:58","slug":"uyazvimosti-v-yadre-linux-pozvolyayushhie-podnyat-svoi-privilegii-cherez-nf_tables-i-ksmbd","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-yadre-linux-pozvolyayushhie-podnyat-svoi-privilegii-cherez-nf_tables-i-ksmbd","title":{"rendered":"Vulnerabilitetet n\u00eb b\u00ebrtham\u00ebn Linux q\u00eb lejojn\u00eb ngritjen e privilegjeve p\u00ebrmes nf_tables dhe ksmbd","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb Netfilter, n\u00ebnsiestem\u00ebn e kernelit Linux, e p\u00ebrdorur p\u00ebr filtrimin dhe modifikimin e paketave rrjet, \u00ebsht\u00eb zbuluar nj\u00eb dob\u00ebsi (CVE-2024-1086) q\u00eb lejon nj\u00eb p\u00ebrdorues lokal t\u00eb ekzekutoj\u00eb kod n\u00eb nivelin e kernelit dhe t\u00eb rris\u00eb privilegjet e tij n\u00eb sistem. Problemi shkaktohet nga \u00e7lirimi i dyfisht\u00eb i memories (double-free) n\u00eb modulin nf_tables, i cili siguron funksionimin e filtrit t\u00eb paketave nftables. Hulumtuesi i dob\u00ebsis\u00eb zhvilloi dhe publikoi nj\u00eb prototip funksional t\u00eb exploit-it.             <\/p>\n<p>Puna e eksploitit \u00ebsht\u00eb demonstruar n\u00eb versionet aktuale t\u00eb Debian dhe Ubuntu me b\u00ebrthamat Linux 5.14 - 6.6, si dhe n\u00eb nj\u00eb mjedis me b\u00ebrtham\u00ebn KernelCTF (Capture the Flag), e cila p\u00ebrfshin patch-e shtes\u00eb p\u00ebr bllokimin e metodave t\u00eb zakonshme t\u00eb funksionimit t\u00eb eksploit\u00ebve dhe p\u00ebrdoret nga kompania Google n\u00eb programin e shp\u00ebrblimeve p\u00ebr gjetjen e dob\u00ebsive. Shkalla e suksesit t\u00eb funksionimit t\u00eb eksploitit vler\u00ebsohet n\u00eb 99.4%. N\u00eb artikullin shoq\u00ebrues, procesi i krijimit t\u00eb nj\u00eb eksploit komplekse me shum\u00eb nivele dhe anashkalimi i mekanizmave t\u00eb mbrojtjes dhe kund\u00ebrshtimit t\u00eb eksploit\u00ebve n\u00eb b\u00ebrtham\u00eb \u00ebsht\u00eb diskutuar n\u00eb detaje.    <center><img decoding=\"async\" alt=\"Vulnerabilitetet n\u00eb b\u00ebrtham\u00ebn Linux q\u00eb lejojn\u00eb ngritjen e privilegjeve p\u00ebrmes nf_tables dhe ksmbd\" src=\"\/wp-content\/uploads\/2024\/03\/379f4d2d8bf2d248097698da70ae8dd1.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>    <\/p>\n<p>Problemi \u00ebsht\u00eb i lidhur me nj\u00eb gabim n\u00eb funksionin nft_verdict_init(), i cili lejon p\u00ebrdorimin e vlerave pozitive si kod gabimi p\u00ebr heqjen e paketave (DROP) n\u00eb hook, q\u00eb mund t\u00eb p\u00ebrdoret p\u00ebr t\u00eb thirrur n\u00eb funksionin nf_hook_slow() nj\u00eb operacion t\u00eb rip\u00ebrs\u00ebritur t\u00eb \u00e7lirimit t\u00eb memories p\u00ebr nj\u00eb buffer, p\u00ebr t\u00eb cilin tashm\u00eb \u00ebsht\u00eb thirrur funksioni free(). Problemi ndodh kur operacioni NF_DROP formohet me nj\u00eb gabim dhe kernel-i n\u00eb fillim interpreton NF_DROP, por m\u00eb pas \u00e7liron buffer-in dhe kthen statusin NF_ACCEPT. Kjo situat\u00eb b\u00ebn q\u00eb, pavar\u00ebsisht \u00e7lirimit t\u00eb buffer-it t\u00eb lidhur me paket\u00ebn, p\u00ebrpunimi i saj t\u00eb mos ndalet, por t\u00eb kaloj\u00eb n\u00eb nj\u00eb trajtues tjet\u00ebr, i cili nj\u00eb her\u00eb tjet\u00ebr th\u00ebrret funksionin e \u00e7lirimit t\u00eb memories.      <\/p>\n<p>Dob\u00ebsia manifestohen duke filluar nga versioni i kernelit Linux 3.15, por exploit-i funksionon me kernel q\u00eb nga versioni 5.14. Korrigjimi i dob\u00ebsis\u00eb \u00ebsht\u00eb propozuar n\u00eb versionin e kernelit Linux 6.8-rc1 dhe n\u00eb fund t\u00eb shkurtit \u00ebsht\u00eb transferuar n\u00eb deget stabile 5.15.149, 6.1.76 dhe 6.6.15. N\u00eb shp\u00ebrndarjet e tyre, mund t\u00eb ndiqni korrigjimin e dob\u00ebsis\u00eb n\u00eb faqet: Debian, Ubuntu, Gentoo, RHEL, SUSE, Fedora, Arch.         <\/p>\n<p>S\u00eb fundi, mund t\u00eb theksohet nj\u00eb seri dob\u00ebsish n\u00eb modulit ksmbd, q\u00eb ofron nj\u00eb implementim t\u00eb integruar n\u00eb kernelin Linux p\u00ebr sistemet e skedar\u00ebve. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/server\/dts-los-angeles\/\"   title=\"server\u00eb\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3674\">server\u00eb<\/a> n\u00eb baz\u00eb t\u00eb protokollit SMB: Vulnerabiliteti CVE-2024-26592 lejon q\u00eb t\u00eb ekzekutohet kodi n\u00eb distanc\u00eb pa autentifikim me privilegje b\u00ebrthamore n\u00eb sisteme me modulin ksmbd t\u00eb aktivizuar. Problemi krijohet nga nj\u00eb gjendje garuese n\u00eb kodin e menaxhimit t\u00eb lidhjeve TCP, e cila ndodh p\u00ebr shkak t\u00eb munges\u00ebs s\u00eb bllokimeve t\u00eb duhura gjat\u00eb pun\u00ebs me objektin.    <\/p>\n<p>Vulnerabiliteti CVE-2023-52440 gjithashtu lejon q\u00eb t\u00eb ekzekutohet kodi n\u00eb distanc\u00eb me privilegje b\u00ebrthamore, por shkaktohet nga mbushja e tamponit gjat\u00eb menaxhimit t\u00eb \u00e7el\u00ebsave t\u00eb sesionit t\u00eb pap\u00ebrshtatsh\u00ebm p\u00ebr shkak t\u00eb munges\u00ebs s\u00eb kontrollit t\u00eb duhur t\u00eb madh\u00ebsis\u00eb s\u00eb t\u00eb dh\u00ebnave q\u00eb marrin nga p\u00ebrdoruesi para se ato t\u00eb kopjohen n\u00eb nj\u00eb tampon me madh\u00ebsi fikse.    <\/p>\n<p>Vulnerabilitetet (1, 2, 3) CVE-2024-26594, CVE-2023-52442 dhe CVE-2023-52441 n\u00eb ksmbd mund\u00ebsojn\u00eb t\u00eb p\u00ebrcaktohet p\u00ebrmbajtja e memories b\u00ebrthamore n\u00eb distanc\u00eb pa autentifikim. Vulnerabiliteti CVE-2024-26594 shkaktohet nga kontrolli i pap\u00ebrshtatsh\u00ebm i t\u00eb dh\u00ebnave gjat\u00eb menaxhimit t\u00eb token\u00ebve SMB2 Mech, duke \u00e7uar n\u00eb kthimin e t\u00eb dh\u00ebnave nga zona jasht\u00eb tamponit. Vulnerabiliteti CVE-2023-52442 shkaktohet nga mungesa e kontrolleve t\u00eb duhura t\u00eb t\u00eb dh\u00ebnave t\u00eb hyrjes gjat\u00eb menaxhimit t\u00eb k\u00ebrkesave t\u00eb lidhura n\u00eb zinxhir. Vulnerabiliteti CVE-2023-52441 shkaktohet nga mungesa e kontrollit t\u00eb nevojsh\u00ebm t\u00eb t\u00eb dh\u00ebnave t\u00eb hyrjes gjat\u00eb menaxhimit t\u00eb k\u00ebrkesave p\u00ebr negociimin e lidhjes SMB2.    <\/p>\n<p>Vulnerabilitetet CVE-2024-26594 dhe CVE-2024-26592 jan\u00eb eliminuar n\u00eb b\u00ebrtham\u00ebn 6.8 dhe n\u00eb ndreqjet e p\u00ebrdit\u00ebsuara t\u00eb deg\u00ebve t\u00eb kaluara t\u00eb stabilizuara 6.1.75, 6.6.14, 6.7.2. Vulnerabilitetet e tjera jan\u00eb eliminuar n\u00eb b\u00ebrtham\u00ebn 6.5 dhe n\u00eb p\u00ebrdit\u00ebsimet 5.15.145, 6.1.53, 6.4.16.      <\/p>\n<p>Si p\u00ebrfundim, mund t\u00eb p\u00ebrmendet aktivizimi i nj\u00eb ekipi t\u00eb ri t\u00eb zhvilluesve t\u00eb b\u00ebrtham\u00ebs Linux, i krijuar p\u00ebr analizimin e pranis\u00eb s\u00eb dob\u00ebsive dhe vler\u00ebsimin e lidhjes mes rregullimeve t\u00eb b\u00ebra n\u00eb b\u00ebrtham\u00eb dhe problemeve t\u00eb siguris\u00eb. N\u00eb shkurt, zhvilluesit e b\u00ebrtham\u00ebs krijuan nj\u00eb sh\u00ebrbim t\u00eb tyre CNA (CVE Numbering Authority), i cili mori autorizimin p\u00ebr t'u dh\u00ebn\u00eb vet\u00eb CVE-identifikues dob\u00ebsive. Deri m\u00eb tani, caktimi i CVE dhe analiza e lidhjes s\u00eb rregullimeve me dob\u00ebsit\u00eb e mundshme bien mbi supe t\u00eb zhvilluesve t\u00eb distribuacioneve, dhe n\u00eb b\u00ebrtham\u00eb, dob\u00ebsit\u00eb potenciale nuk ishin t\u00eb ndara dhe figuronin n\u00eb m\u00ebnyr\u00eb t\u00eb nj\u00ebjt\u00eb me rregullimet e zakonshme. Rezultatet e pun\u00ebs s\u00eb sh\u00ebrbimit t\u00eb ri i kaluan t\u00eb gjitha pritshm\u00ebrit\u00eb - \u00e7do dit\u00eb n\u00eb b\u00ebrtham\u00eb sh\u00ebnohen deri n\u00eb disa dhjet\u00ebra dob\u00ebsi t\u00eb reja, t\u00eb cilat m\u00eb par\u00eb nuk ishin sh\u00ebnuar si probleme me sigurin\u00eb. P\u00ebr shembull, m\u00eb 26 mars, u atribuohen 14 dob\u00ebsi t\u00eb reja CVE, t\u00eb cilat m\u00eb par\u00eb nuk ishin trajtuar si probleme me sigurin\u00eb, dhe m\u00eb 25 mars - 41 dob\u00ebsi.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60860\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 Netfilter, \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Linux, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u0438 \u043c\u043e\u0434\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-1086), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0438 \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u0434\u0432\u043e\u0439\u043d\u044b\u043c \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0435\u043d\u0438\u0435\u043c \u043f\u0430\u043c\u044f\u0442\u0438 (double-free) \u0432 \u043c\u043e\u0434\u0443\u043b\u0435 nf_tables, \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u044e\u0449\u0435\u043c \u0440\u0430\u0431\u043e\u0442\u0443 \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u044c\u0442\u0440\u0430 nftables. \u0412\u044b\u044f\u0432\u0438\u0432\u0448\u0438\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043b \u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b \u0440\u0430\u0431\u043e\u0447\u0438\u0439 \u043f\u0440\u043e\u0442\u043e\u0442\u0438\u043f \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u0430. \u0420\u0430\u0431\u043e\u0442\u0430 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":114604,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-114603","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 Netfilter, \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Linux, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u0438 \u043c\u043e\u0434\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-1086), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0438 \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-yadre-linux-pozvolyayushhie-podnyat-svoi-privilegii-cherez-nf_tables-i-ksmbd\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u044f\u0434\u0440\u0435 Linux, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 nf_tables \u0438 ksmbd | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 Netfilter, \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Linux, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u0438 \u043c\u043e\u0434\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-1086), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0438 \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-yadre-linux-pozvolyayushhie-podnyat-svoi-privilegii-cherez-nf_tables-i-ksmbd\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-03-27T10:25:58+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-03-27T10:25:58+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Dob\u00ebsit\u00eb n\u00eb b\u00ebrtham\u00ebn Linux, t\u00eb cilat lejojn\u00eb rritjen e privilegjeve p\u00ebrmes nf_tables dhe ksmbd | ProHoster","description":"N\u00eb Netfilter, n\u00ebn-sistemi i b\u00ebrtham\u00ebs Linux, i p\u00ebrdorur p\u00ebr filtrimin dhe modifikimin e paketimeve rrjet, \u00ebsht\u00eb identifikuar nj\u00eb dob\u00ebsi (CVE-2024-1086), e cila lejon nj\u00eb p\u00ebrdorues lokal t\u00eb ekzekutoj\u00eb kod n\u00eb nivelin e b\u00ebrtham\u00ebs dhe t\u00eb rris\u00eb privilegjet e tij.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-yadre-linux-pozvolyayushhie-podnyat-svoi-privilegii-cherez-nf_tables-i-ksmbd","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u044f\u0434\u0440\u0435 Linux, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 nf_tables \u0438 ksmbd | ProHoster","og:description":"\u0412 Netfilter, \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Linux, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u0438 \u043c\u043e\u0434\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-1086), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0438 \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimosti-v-yadre-linux-pozvolyayushhie-podnyat-svoi-privilegii-cherez-nf_tables-i-ksmbd","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-03-27T10:25:58+00:00","article:modified_time":"2024-03-27T10:25:58+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"114603","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-02-22 15:29:46","updated":"2026-02-22 15:29:46","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/114603","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=114603"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/114603\/revisions"}],"predecessor-version":[{"id":162202,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/114603\/revisions\/162202"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/114604"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=114603"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=114603"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=114603"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}