{"id":164054,"date":"2026-03-13T11:12:02","date_gmt":"2026-03-13T09:12:02","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-gssapi-patche-k-openssh-udalyonno-ekspluatiruemaya-na-stadii-do-autentifikaczii"},"modified":"2026-03-13T11:12:02","modified_gmt":"2026-03-13T09:12:02","slug":"uyazvimost-v-gssapi-patche-k-openssh-udalyonno-ekspluatiruemaya-na-stadii-do-autentifikaczii","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-gssapi-patche-k-openssh-udalyonno-ekspluatiruemaya-na-stadii-do-autentifikaczii","title":{"rendered":"Dob\u00ebsia n\u00eb patch-in GSSAPI p\u00ebr OpenSSH, q\u00eb shfryt\u00ebzohet n\u00eb distanc\u00eb p\u00ebrpara autentifikimit","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb patch-in gssapi.patch t\u00eb p\u00ebrdorur n\u00eb shum\u00eb distribucione Linux, i cili shton mb\u00ebshtetje p\u00ebr ndarjen e \u00e7elqeve mbi baz\u00ebn e GSSAPI n\u00eb OpenSSH, \u00ebsht\u00eb zbuluar nj\u00eb vulnerabilitet (CVE-2026-3497), q\u00eb \u00e7on n\u00eb dereferencimin e treguesve, d\u00ebmtimin e memorie dhe shkeljen e mekanizmit t\u00eb ndarjes s\u00eb privilegjeve (Privsep). Ky vulnerabilitet mund t\u00eb shfryt\u00ebzohet n\u00eb m\u00ebnyr\u00eb t\u00eb aferme para se t\u00eb kryhet autentifikimi. Nj\u00eb k\u00ebkash q\u00eb zbuloi problematik\u00ebn demonstroi nisjen e nj\u00eb mbylljeje t\u00eb procesit duke d\u00ebrguar nj\u00eb paket\u00eb rrjeti t\u00eb modifikuar n\u00eb serverin SSH. Nuk p\u00ebrjashtohet mund\u00ebsia q\u00eb, p\u00ebrve\u00e7 nd\u00ebrprerjes s\u00eb sh\u00ebrbimit, t\u00eb ekzistojn\u00eb variante m\u00eb t\u00eb rrezikshme shfryt\u00ebzimi t\u00eb vulnerabilitetit.      <\/p>\n<p>\u00cbsht\u00eb e r\u00ebnd\u00ebsishme t\u00eb theksohet se n\u00eb at\u00eb koh\u00eb zhvilluesit e OpenSSH refuzuan t\u00eb pranojn\u00eb ndryshimin p\u00ebr mb\u00ebshtetje GSSAPI p\u00ebr shkak t\u00eb dyshimeve mbi sigurin\u00eb e tij. Megjithat\u00eb, shum\u00eb distribucione Linux e p\u00ebrfshin\u00eb k\u00ebt\u00eb patch n\u00eb paketat e tyre t\u00eb OpenSSH. N\u00eb p\u00ebrdorim jan\u00eb disa versione t\u00eb patch-it GSSAPI, por shumica prej tyre kan\u00eb nj\u00eb gabim q\u00eb \u00e7on n\u00eb vulnerabilitet. Nj\u00eb zgjidhje \u00ebsht\u00eb e disponueshme vet\u00ebm si patch, ndryshimi i t\u00eb cilit p\u00ebrfshin z\u00ebvend\u00ebsimin e thirrjes s\u00eb funksionit sshpkt_disconnect() me ssh_packet_disconnect() n\u00eb skedarit kexgsss.c.    <\/p>\n<p>Aktualisht, prania e nj\u00eb dob\u00ebsie \u00ebsht\u00eb konfirmuar n\u00eb Debian dhe Ubuntu. N\u00eb shp\u00ebrndarjet e tjera, aplikimi i patch-it problematik dhe ndjeshm\u00ebria e tij ndaj dob\u00ebsis\u00eb po shqyrtohet (SUSE\/openSUSE, RHEL, Gentoo, Arch, Fedora). Dob\u00ebsia shfaqet vet\u00ebm kur \u00ebsht\u00eb aktivizuar opsioni 'GSSAPIKeyExchange yes' n\u00eb konfigurime. Po ashtu, opsionet e kompajlerit q\u00eb jan\u00eb p\u00ebrdorur p\u00ebr nd\u00ebrtimin e paketave n\u00eb shp\u00ebrndarje kan\u00eb ndikim n\u00eb mund\u00ebsin\u00eb e shfryt\u00ebzimit.        <\/p>\n<p>Arsyeja e shfaqjes s\u00eb vulnerabilitetit \u00ebsht\u00eb nj\u00eb gabim n\u00eb funksionin sshpkt_disconnect(), i cili b\u00ebri q\u00eb procesi t\u00eb mos p\u00ebrfundonte pas marrjes s\u00eb nj\u00eb mesazhi disconnect, duke lejuar sulmuesin q\u00eb n\u00eb faz\u00ebn e negociatave t\u00eb \u00e7elqeve t\u00eb d\u00ebrgonte nj\u00eb mesazh GSSAPI q\u00eb nuk ishte parashikuar nga logjika e funksionimit. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/server\/dts-los-angeles\/\" title=\"server\u00eb\" data-wpil-keyword-link=\"linked\">server\u00eb<\/a> pas marrjes s\u00eb nj\u00eb mesazhi GSSAPI t\u00eb paplanifikuar,  <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/server\/\"   title=\"server\" data-wpil-keyword-link=\"linked\">server<\/a> e vendos at\u00eb n\u00eb radh\u00eb dhe nuk ndalon ekzekutimin e programit, por nuk inicializon variablat q\u00eb p\u00ebrcaktojn\u00eb parametrat e lidhjes. M\u00eb von\u00eb, n\u00eb ciklin e trajtimit t\u00eb ngjarjeve, ekzekutohet kodi q\u00eb lexon struktur\u00ebn e pa inicializuar recv_tok nga stack-u (lexohen t\u00eb dh\u00ebnat q\u00eb kan\u00eb mbetur n\u00eb stack nga thirrja e m\u00ebparshme e funksionit), e d\u00ebrgon at\u00eb n\u00eb procesin me privilegje n\u00ebp\u00ebrmjet IPC dhe m\u00eb pas e kalon n\u00eb funksionin gss_release_buffer(), i cili mund t\u00eb th\u00ebrras\u00eb funksionin free() dhe t\u00eb \u00e7liroj\u00eb memorjen p\u00ebr nj\u00eb tregues t\u00eb pavlefsh\u00ebm q\u00eb i referohet nj\u00eb zone t\u00eb rast\u00ebsishme t\u00eb memorjes.<br \/>\n<br \/>Burimi: <a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=64983\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Linux \u043f\u0430\u0442\u0447\u0435 gssapi.patch, \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0432 OpenSSH \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0443 \u043e\u0431\u043c\u0435\u043d\u0430 \u043a\u043b\u044e\u0447\u0435\u0439 \u043d\u0430 \u0431\u0430\u0437\u0435 GSSAPI, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-3497), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0440\u0430\u0437\u044b\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u044e \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044f, \u043f\u043e\u0432\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u044e \u043f\u0430\u043c\u044f\u0442\u0438 \u0438 \u043e\u0431\u0445\u043e\u0434\u0443 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u0430 \u0440\u0430\u0437\u0434\u0435\u043b\u0435\u043d\u0438\u044f \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439 (Privsep). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u043d\u0430 \u0441\u0442\u0430\u0434\u0438\u0438 \u0434\u043e \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043b\u0435\u043d\u0438\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438. \u0412\u044b\u044f\u0432\u0438\u0432\u0448\u0438\u0439 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u043f\u0440\u043e\u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043b \u0438\u043d\u0438\u0446\u0438\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0433\u043e \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u043d\u0430 SSH-\u0441\u0435\u0440\u0432\u0435\u0440 \u043e\u0434\u043d\u043e\u0433\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-164054","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Linux \u043f\u0430\u0442\u0447\u0435 gssapi.patch, \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0432 OpenSSH \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0443 \u043e\u0431\u043c\u0435\u043d\u0430 \u043a\u043b\u044e\u0447\u0435\u0439 \u043d\u0430 \u0431\u0430\u0437\u0435 GSSAPI, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-3497), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0440\u0430\u0437\u044b\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u044e \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044f, \u043f\u043e\u0432\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u044e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-gssapi-patche-k-openssh-udalyonno-ekspluatiruemaya-na-stadii-do-autentifikaczii\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 GSSAPI-\u043f\u0430\u0442\u0447\u0435 \u043a OpenSSH, \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u043d\u0430 \u0441\u0442\u0430\u0434\u0438\u0438 \u0434\u043e \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Linux \u043f\u0430\u0442\u0447\u0435 gssapi.patch, \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0432 OpenSSH \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0443 \u043e\u0431\u043c\u0435\u043d\u0430 \u043a\u043b\u044e\u0447\u0435\u0439 \u043d\u0430 \u0431\u0430\u0437\u0435 GSSAPI, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-3497), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0440\u0430\u0437\u044b\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u044e \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044f, \u043f\u043e\u0432\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u044e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-gssapi-patche-k-openssh-udalyonno-ekspluatiruemaya-na-stadii-do-autentifikaczii\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-03-13T09:12:02+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-03-13T09:12:02+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Dob\u00ebsi n\u00eb patch-in GSSAPI p\u00ebr OpenSSH, e cila shfryt\u00ebzohet nga distanca n\u00eb faz\u00ebn para autentifikimit | ProHoster","description":"N\u00eb patch-in gssapi.patch, i p\u00ebrdorur n\u00eb shum\u00eb shp\u00ebrndarje t\u00eb Linux, i cili shton n\u00eb OpenSSH mb\u00ebshtetje p\u00ebr shk\u00ebmbimin e \u00e7el\u00ebsave t\u00eb bazuar n\u00eb GSSAPI, u zbulua nj\u00eb dob\u00ebsi (CVE-2026-3497) q\u00eb \u00e7on n\u00eb dereferencimin e treguesve dhe korruptim.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-gssapi-patche-k-openssh-udalyonno-ekspluatiruemaya-na-stadii-do-autentifikaczii","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 GSSAPI-\u043f\u0430\u0442\u0447\u0435 \u043a OpenSSH, \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u043d\u0430 \u0441\u0442\u0430\u0434\u0438\u0438 \u0434\u043e \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 | ProHoster","og:description":"\u0412 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Linux \u043f\u0430\u0442\u0447\u0435 gssapi.patch, \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0432 OpenSSH \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0443 \u043e\u0431\u043c\u0435\u043d\u0430 \u043a\u043b\u044e\u0447\u0435\u0439 \u043d\u0430 \u0431\u0430\u0437\u0435 GSSAPI, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-3497), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0440\u0430\u0437\u044b\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u044e \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044f, \u043f\u043e\u0432\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u044e.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-gssapi-patche-k-openssh-udalyonno-ekspluatiruemaya-na-stadii-do-autentifikaczii","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-03-13T09:12:02+00:00","article:modified_time":"2026-03-13T09:12:02+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/164054","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=164054"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/164054\/revisions"}],"predecessor-version":[{"id":173149,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/164054\/revisions\/173149"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=164054"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=164054"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=164054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}