{"id":170701,"date":"2026-05-15T12:24:29","date_gmt":"2026-05-15T10:24:29","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/fragnesia-uyazvimost-v-yadre-linux-pozvolyayushhaya-poluchit-root-cherez-izmenenie-stranichnogo-kesha"},"modified":"2026-05-15T12:24:29","modified_gmt":"2026-05-15T10:24:29","slug":"fragnesia-uyazvimost-v-yadre-linux-pozvolyayushhaya-poluchit-root-cherez-izmenenie-stranichnogo-kesha","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/fragnesia-uyazvimost-v-yadre-linux-pozvolyayushhaya-poluchit-root-cherez-izmenenie-stranichnogo-kesha","title":{"rendered":"Fragnesia \u2014 nj\u00eb cenueshm\u00ebri n\u00eb kernelin Linux q\u00eb lejon t\u00eb marr\u00ebsh root p\u00ebrmes ndryshimit t\u00eb caches s\u00eb faqeve","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb kernelin e Linux \u00ebsht\u00eb zbuluar nj\u00eb vulnerabilitet i kat\u00ebrt n\u00eb dy jav\u00ebt e fundit (CVE-2026-46300), i cili lejon nj\u00eb p\u00ebrdorues pa privilegje t\u00eb marr\u00eb t\u00eb drejtat root duke nd\u00ebrruar t\u00eb dh\u00ebnat n\u00eb cache-n e faqeve. Ky vulnerabilitet ka emrin kodues Fragnesia ose Copy Fail 3.0. Thelbi i vulnerabilitetit \u00ebsht\u00eb i ngjash\u00ebm me vulnerabilitetet e zbuluara m\u00eb par\u00eb Copy Fail dhe Dirty Frag. Ashtu si n\u00eb rastin e Dirty Frag, vulnerabiliteti i ri \u00ebsht\u00eb i pranish\u00ebm n\u00eb n\u00ebn-sistemin xfrm-ESP, por shkaktohet nga nj\u00eb gabim tjet\u00ebr dhe k\u00ebrkon nj\u00eb rregullim t\u00eb ve\u00e7ant\u00eb. Nj\u00eb exploit funksional \u00ebsht\u00eb n\u00eb dispozicion.    <\/p>\n<p>Vulnerabiliteti shfaqet n\u00eb kernel\u00ebt e Linux q\u00eb jan\u00eb l\u00ebshuar pas 5 majit, p\u00ebr shkak t\u00eb aktivizimit t\u00eb rast\u00ebsish\u00ebm nga rregullimi i vulnerabilitetit Dirty Frag. P\u00ebr t\u00eb zgjidhur vulnerabilitetin Fragnesia p\u00ebr kernelin e Linux \u00ebsht\u00eb propozuar nj\u00eb rregullim. Analiza e k\u00ebtij rregullimi tregoi se ai nuk \u00ebsht\u00eb i mjaftuesh\u00ebm, pas s\u00eb cil\u00ebs u p\u00ebrgatit nj\u00eb version i dyt\u00eb i patch-it.    <\/p>\n<p>Vulnerabiliteti \u00ebsht\u00eb i pranish\u00ebm n\u00eb n\u00ebn-sistemin xfrm n\u00eb implementimin e mekanizmit t\u00eb inkapsulimit t\u00eb protokollit ESP (Encapsulating Security Payload) n\u00eb TCP (ESP-in-TCP, RFC 8229), i p\u00ebrdorur p\u00ebr tunneling e trafikimit IPsec mbi TCP. P\u00ebr t\u00eb eliminuar bufferimin e tepruar, operacionet me algoritmin AES-GCM u kryen n\u00eb vend duke ekzekutuar operacionin XOR mbi t\u00eb dh\u00ebnat n\u00eb cache-n e faqeve. P\u00ebr shkak t\u00eb nj\u00eb gabimi logjik, krijoheshin kushte q\u00eb lejojn\u00eb t\u00eb ndryshohet 1 byte n\u00eb cache-n e faqeve n\u00eb nj\u00eb offset t\u00eb zgjedhur. Duke repetuar operacionet, mund t\u00eb ndryshohet p\u00ebrmbajtja e \u00e7do skedari n\u00eb cache-n e faqeve byte p\u00ebr byte.    <\/p>\n<p>T\u00eb gjitha operacionet e leximit nga skedar\u00ebt fillimisht kthejn\u00eb p\u00ebrmbajtjen nga cache i faqeve. N\u00eb rastin e modifikimit t\u00eb t\u00eb dh\u00ebnave n\u00eb cache-in e faqeve, operacionet e leximit nga skedari do t\u00eb sjellin informacion t\u00eb pav\u00ebrtet\u00eb q\u00eb nuk \u00ebsht\u00eb ruajtur n\u00eb ruajt\u00ebs, por t\u00eb dh\u00ebna t\u00eb z\u00ebvend\u00ebsuara. Shfryt\u00ebzimi i k\u00ebtij vulnerabiliteti p\u00ebrfshin ndryshimin e cache-it t\u00eb faqeve p\u00ebr nj\u00eb skedari ekzekutiv me flamurin suid root, i lexuar paraprakisht p\u00ebr t'u futur n\u00eb cache-in e faqeve. N\u00eb eksploatin e propozuar nga hulumtuesit, 192 bajt\u00ebt e par\u00eb t\u00eb skedarit \/usr\/bin\/su p\u00ebrz\u00ebvend\u00ebsohen me kodin p\u00ebr t\u00eb ekzekutuar \/usr\/bin\/sh. Ekzekutimi i m\u00ebvonsh\u00ebm i utilitarit 'su' rezulton n\u00eb ngarkimin n\u00eb memorie t\u00eb nj\u00eb kopjeje t\u00eb ndryshuar nga cache-i i faqeve, jo skedari origjinal i ekzekutuesh\u00ebm nga ruajt\u00ebsi.         <\/p>\n<p>P\u00ebr t\u00eb shfryt\u00ebzuar vulnerabilitetin Fragnesia, n\u00eb sistem duhet t\u00eb lejohet krijimi i hap\u00ebsirave t\u00eb emrit t\u00eb identifikuesve t\u00eb p\u00ebrdoruesve (namespace) . N\u00eb Ubuntu, nj\u00eb operacion i till\u00eb \u00ebsht\u00eb ndaluar si parazgjedhje, por mund t\u00eb lejohet p\u00ebrmes sysctl 'kernel.apparmor_restrict_unprivileged_userns=0' ose profileve t\u00eb AppArmor. N\u00eb shp\u00ebrndarje t\u00eb tjera, disponueshm\u00ebria e 'user namespace' p\u00ebr p\u00ebrdoruesit jo privilegjuar varet nga cil\u00ebsimi i sysctl 'kernel.unprivileged_userns_clone' (n\u00ebse 0, at\u00ebher\u00eb ndalohet).      <\/p>\n<p>P\u00ebrdit\u00ebsimet me rregullime p\u00ebr nucleus Linux dhe paketat e \u0109el\u00ebsit n\u00eb shp\u00ebrndarje nuk jan\u00eb publikuar ende. Statusi i eliminimit t\u00eb dob\u00ebsive n\u00eb shp\u00ebrndarje mund t\u00eb vler\u00ebsohet n\u00eb k\u00ebto faqe: Debian, Ubuntu, SUSE\/openSUSE, RHEL, Gentoo, Arch, Fedora. Si nj\u00eb m\u00ebnyr\u00eb p\u00ebr t\u00eb mbrojtur veten, mund t\u00eb bllokoni ngarkimin e moduleve t\u00eb kernelit esp4 dhe esp6:    <\/p>\n<p>     sh -c 'printf 'install esp4 \/bin\/false\ninstall esp6 \/bin\/false\n' &gt; \/etc\/modprobe.d\/dirtyfrag.conf; rmmod esp4 esp6 2&gt;\/dev\/null; true'<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65441\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0447\u0435\u0442\u0432\u0451\u0440\u0442\u0430\u044f \u0437\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0435 \u0434\u0432\u0435 \u043d\u0435\u0434\u0435\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-46300), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root, \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0430\u0432 \u0434\u0430\u043d\u043d\u044b\u0435 \u0432 \u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u043e\u043c \u043a\u044d\u0448\u0435. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f Fragnesia \u0438\u043b\u0438 Copy Fail 3.0. \u0421\u0443\u0442\u044c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0430\u043d\u0430\u043b\u043e\u0433\u0438\u0447\u043d\u0430 \u0440\u0430\u043d\u0435\u0435 \u0440\u0430\u0441\u043a\u0440\u044b\u0442\u044b\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u043c Copy Fail \u0438 Dirty Frag. \u041a\u0430\u043a \u0438 \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0441 Dirty Frag \u043d\u043e\u0432\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 xfrm-ESP, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-170701","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0447\u0435\u0442\u0432\u0451\u0440\u0442\u0430\u044f \u0437\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0435 \u0434\u0432\u0435 \u043d\u0435\u0434\u0435\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-46300), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root, \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0430\u0432 \u0434\u0430\u043d\u043d\u044b\u0435 \u0432 \u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u043e\u043c \u043a\u044d\u0448\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/fragnesia-uyazvimost-v-yadre-linux-pozvolyayushhaya-poluchit-root-cherez-izmenenie-stranichnogo-kesha\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Fragnesia \u2014 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u044f\u0434\u0440\u0435 Linux, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root \u0447\u0435\u0440\u0435\u0437 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 \u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u043e\u0433\u043e \u043a\u044d\u0448\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0447\u0435\u0442\u0432\u0451\u0440\u0442\u0430\u044f \u0437\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0435 \u0434\u0432\u0435 \u043d\u0435\u0434\u0435\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-46300), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root, \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0430\u0432 \u0434\u0430\u043d\u043d\u044b\u0435 \u0432 \u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u043e\u043c \u043a\u044d\u0448\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/fragnesia-uyazvimost-v-yadre-linux-pozvolyayushhaya-poluchit-root-cherez-izmenenie-stranichnogo-kesha\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-05-15T10:24:29+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-05-15T10:24:29+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Fragnesia \u2014 nj\u00eb dob\u00ebsi n\u00eb kernelin Linux, e cila lejon marrjen e aksesit root p\u00ebrmes ndryshimit t\u00eb cache-it t\u00eb faqeve | ProHoster","description":"N\u00eb kernelin Linux \u00ebsht\u00eb zbuluar dob\u00ebsia e kat\u00ebrt n\u00eb dy jav\u00ebt e fundit (CVE-2026-46300), e cila lejon nj\u00eb p\u00ebrdorues t\u00eb pa privilegjuar t\u00eb fitoj\u00eb t\u00eb drejta root, duke rishkruar t\u00eb dh\u00ebnat n\u00eb cache-in e faqeve.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/fragnesia-uyazvimost-v-yadre-linux-pozvolyayushhaya-poluchit-root-cherez-izmenenie-stranichnogo-kesha","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Fragnesia \u2014 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u044f\u0434\u0440\u0435 Linux, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root \u0447\u0435\u0440\u0435\u0437 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 \u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u043e\u0433\u043e \u043a\u044d\u0448\u0430 | ProHoster","og:description":"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0447\u0435\u0442\u0432\u0451\u0440\u0442\u0430\u044f \u0437\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0435 \u0434\u0432\u0435 \u043d\u0435\u0434\u0435\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-46300), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root, \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0430\u0432 \u0434\u0430\u043d\u043d\u044b\u0435 \u0432 \u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u043e\u043c \u043a\u044d\u0448\u0435.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/fragnesia-uyazvimost-v-yadre-linux-pozvolyayushhaya-poluchit-root-cherez-izmenenie-stranichnogo-kesha","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-05-15T10:24:29+00:00","article:modified_time":"2026-05-15T10:24:29+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/170701","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=170701"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/170701\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=170701"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=170701"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=170701"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}