{"id":170805,"date":"2026-05-16T06:24:28","date_gmt":"2026-05-16T04:24:28","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-linux-podsisteme-pidfd-pozvolyayushhaya-prochitat-nedostupnye-polzovatelyu-fajly"},"modified":"2026-05-16T06:24:28","modified_gmt":"2026-05-16T04:24:28","slug":"uyazvimost-v-linux-podsisteme-pidfd-pozvolyayushhaya-prochitat-nedostupnye-polzovatelyu-fajly","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-linux-podsisteme-pidfd-pozvolyayushhaya-prochitat-nedostupnye-polzovatelyu-fajly","title":{"rendered":"Vulnera n\u00eb n\u00ebn-sistemin pidfd t\u00eb Linux-it q\u00eb lejon leximin e skedar\u00ebve t\u00eb pap\u00ebrshkruar p\u00ebr p\u00ebrdoruesin.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nj\u00eb vulnerabilitet kritik i pest\u00eb (1, 2, 3) u zbulua n\u00eb kernelin Linux gjat\u00eb dy jav\u00ebve t\u00eb fundit, i cili lejon nj\u00eb p\u00ebrdorues t\u00eb rris\u00eb privilegjet e tij n\u00eb sistem. Jan\u00eb publikuar dy eksploit\u00eb t\u00eb funksionuar: sshkeysign_pwn lejon nj\u00eb p\u00ebrdorues pa privilegje t\u00eb lexoj\u00eb p\u00ebrmbajtjen e \u00e7el\u00ebsave t\u00eb mbyllur SSH t\u00eb hostit n\u00eb \/etc\/ssh\/ssh_host_*_key, nd\u00ebrsa chage_pwn \u2014 t\u00eb lexoj\u00eb p\u00ebrmbajtjen e skedarit \/etc\/shadow me hash-et e fjal\u00ebkalimeve t\u00eb p\u00ebrdoruesve.     <\/p>\n<p>Informacionet mbi k\u00ebt\u00eb dob\u00ebsi nuk ishin parashikuar p\u00ebr t'u zbuluar, por nj\u00eb nga hulumtuesit e siguris\u00eb, duke u bazuar n\u00eb patchin e propozuar p\u00ebr b\u00ebrtham\u00ebn, arriti t\u00eb identifikoj\u00eb thelbin e dob\u00ebsis\u00eb q\u00eb lejon leximin e skedar\u00ebve q\u00eb jan\u00eb t\u00eb aksesuesh\u00ebm vet\u00ebm p\u00ebr p\u00ebrdoruesin root, p\u00ebr shembull, \/etc\/shadow. N\u00eb ndryshimin e shtuar n\u00eb b\u00ebrtham\u00eb, logjika e p\u00ebrdorimit t\u00eb funksionit get_dumpable() n\u00eb ptrace u korrigjua gjat\u00eb p\u00ebrcaktimit t\u00eb nivelit t\u00eb aksesit n\u00eb funksionin ptrace_may_access().    <\/p>\n<p>Dob\u00ebsia e drejtp\u00ebrdrejt\u00eb shkaktohet nga nj\u00eb gjendje garancie, e cila \u00e7on n\u00eb mund\u00ebsin\u00eb e aksesit pa privilegje n\u00eb nj\u00eb deskriptori skedari pidfd pas qasjes n\u00eb nj\u00eb skedar nga procesi suid root. N\u00eb momentin midis hapjes s\u00eb skedarit dhe ofrimit t\u00eb privilegjeve n\u00eb programin suid (p\u00ebr shembull, p\u00ebrmes funksionit setreuid), ndodh nj\u00eb situat\u00eb e till\u00eb, ku aplikacioni q\u00eb ekzekuton programin suid root, p\u00ebrmes deskriptori pidfd mund t\u00eb qaset n\u00eb skedarin e hapur n\u00eb programin suid, edhe n\u00ebse kjo nuk lejohet nga t\u00eb drejtat e aksesit n\u00eb skedar.     <\/p>\n<p>Nj\u00eb dritare p\u00ebr eksploitimin lind pasi funksioni \"__ptrace_may_access()\" kalon testin e aksesit n\u00eb skedar, n\u00ebse fush\u00eb task-&gt;mm \u00ebsht\u00eb vendosur n\u00eb vler\u00ebn NULL pas ekzekutimit t\u00eb exit_mm(), por para thirrjes s\u00eb exit_files(). Momentalisht, thirrja sistemore pidfd_getfd mendon se identifikuesi i p\u00ebrdoruesit (uid) t\u00eb procesit q\u00eb th\u00ebrris, p\u00ebrputhet me identifikuesin, t\u00eb cilit i \u00ebsht\u00eb lejuar akses n\u00eb skedar. \u00cbsht\u00eb e r\u00ebnd\u00ebsishme q\u00eb problemi u v\u00ebrejt p\u00ebr her\u00eb t\u00eb par\u00eb edhe n\u00eb vitin 2020, por mbeti i pa zgjidhur.          <\/p>\n<p>N\u00eb eksploitin q\u00eb merr p\u00ebrmbajtjen e \/etc\/shadow, sulmi p\u00ebrqendrohet n\u00eb ekzekutimin ciklik p\u00ebrmes fork+execl t\u00eb aplikacionit \/usr\/bin\/chage me flamurin suid root, q\u00eb lexon p\u00ebrmbajtjen e \/etc\/shadow. Pasi procesi \u00ebsht\u00eb shp\u00ebrndar\u00eb, ekzekutohet thirrja sistemore pidfd_open dhe b\u00ebhet nj\u00eb cik\u00ebl i p\u00ebrhersh\u00ebm i p\u00ebrshkimeve t\u00eb deskriptor\u00ebve t\u00eb disponuesh\u00ebm pidfd p\u00ebrmes thirrjes sistemore pidfd_getfd dhe kontrollit t\u00eb tyre p\u00ebrmes \/proc\/self\/fd. N\u00eb eksploitin sshkeysign_pwn, manipulime t\u00eb ngjashme b\u00ebhen me programin suid root ssh-keysign.    <\/p>\n<p>Identifikuesi CVE p\u00ebr problemin ende nuk \u00ebsht\u00eb caktuar, p\u00ebrdit\u00ebsimi i b\u00ebrtham\u00ebs dhe paketave n\u00eb shp\u00ebrndarjet nuk \u00ebsht\u00eb publikuar. N\u00eb b\u00ebrthamat e l\u00ebshuara disa or\u00eb m\u00eb par\u00eb, 7.0.7, 6.18.30 dhe 6.12.88, vulnerabiliteti nuk \u00ebsht\u00eb rregulluar. N\u00eb momentin e shkruanjes s\u00eb lajmit, mund t\u00eb p\u00ebrdoret vet\u00ebm patches. Po diskutohet p\u00ebr mund\u00ebsit\u00eb e punaround-it p\u00ebr t\u00eb bllokuar vulnerabilitetin, si\u00e7 \u00ebsht\u00eb vendosja e sysctl kernel.yama.ptrace_scope=3 ose heqja e flamurit suid root nga skedar\u00ebt ekzekutiv\u00eb n\u00eb sistem (t\u00eb pakt\u00ebn nga utilitaret ssh-keysign dhe chage, t\u00eb cilat p\u00ebrdoren n\u00eb eksploitim).        <center>  <video controls=\"\" style=\"width: 700px; height: 400px; max-width:100%\"><source src=\"https:\/\/github.com\/0xdeadbeefnetwork\/ssh-keysign-pwn\/raw\/refs\/heads\/main\/demo.mp4\" type=\"video\/mp4\"><\/video>  <\/center>        <\/p>\n<p>Shtes\u00eb: Vulnerabilitetit i \u00ebsht\u00eb caktuar identifikuesi CVE-2026-46333. Jan\u00eb formuar p\u00ebrdit\u00ebsime t\u00eb b\u00ebrtham\u00ebs Linux 7.0.8, 6.18.31, 6.12.89, 6.6.139, 6.1.173, 5.15.207 dhe 5.10.256 q\u00eb rregullojn\u00eb vulnerabilitetin. Statusi i zgjidhjes s\u00eb vulnerabiliteteve n\u00eb shp\u00ebrndarjet mund t\u00eb vler\u00ebsohet n\u00eb k\u00ebto faqe: Debian, Ubuntu, SUSE\/openSUSE, RHEL, Gentoo, Arch, Fedora.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65452\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043f\u044f\u0442\u0430\u044f (1, 2, 3) \u0437\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0435 \u0434\u0432\u0435 \u043d\u0435\u0434\u0435\u043b\u0438 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043e \u0434\u0432\u0430 \u0440\u0430\u0431\u043e\u0447\u0438\u0445 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u0430: sshkeysign_pwn \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u0445\u043e\u0441\u0442\u043e\u0432\u044b\u0445 SSH-\u043a\u043b\u044e\u0447\u0435\u0439 \/etc\/ssh\/ssh_host_*_key, \u0430 chage_pwn &#8212; \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u0444\u0430\u0439\u043b\u0430 \/etc\/shadow \u0441 \u0445\u044d\u0448\u0430\u043c\u0438 \u043f\u0430\u0440\u043e\u043b\u0435\u0439 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439. \u0421\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043d\u0435 \u0431\u044b\u043b\u0438 \u0437\u0430\u043f\u043b\u0430\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u0434\u043b\u044f \u0440\u0430\u0441\u043a\u0440\u044b\u0442\u0438\u044f, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-170805","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043f\u044f\u0442\u0430\u044f (1, 2, 3) \u0437\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0435 \u0434\u0432\u0435 \u043d\u0435\u0434\u0435\u043b\u0438 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-linux-podsisteme-pidfd-pozvolyayushhaya-prochitat-nedostupnye-polzovatelyu-fajly\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Linux-\u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 pidfd, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c \u043d\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0444\u0430\u0439\u043b\u044b | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043f\u044f\u0442\u0430\u044f (1, 2, 3) \u0437\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0435 \u0434\u0432\u0435 \u043d\u0435\u0434\u0435\u043b\u0438 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-linux-podsisteme-pidfd-pozvolyayushhaya-prochitat-nedostupnye-polzovatelyu-fajly\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-05-16T04:24:28+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-05-16T04:24:28+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabiliteti n\u00eb n\u00ebn-sistemin pidfd t\u00eb Linux-it, i cili lejon leximin e skedar\u00ebve t\u00eb pap\u00ebrshkuesh\u00ebm p\u00ebr p\u00ebrdoruesin | ProHoster","description":"N\u00eb b\u00ebrtham\u00ebn Linux \u00ebsht\u00eb zbuluar nj\u00eb vulnerabilitet kritik i pest\u00eb (1, 2, 3) gjat\u00eb dy jav\u00ebve t\u00eb fundit, i cili lejon nj\u00eb p\u00ebrdorues t\u00eb p\u00ebrmir\u00ebsoj\u00eb privilegjet e tij n\u00eb sistem.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-linux-podsisteme-pidfd-pozvolyayushhaya-prochitat-nedostupnye-polzovatelyu-fajly","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Linux-\u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 pidfd, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c \u043d\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0444\u0430\u0439\u043b\u044b | ProHoster","og:description":"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043f\u044f\u0442\u0430\u044f (1, 2, 3) \u0437\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0435 \u0434\u0432\u0435 \u043d\u0435\u0434\u0435\u043b\u0438 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-linux-podsisteme-pidfd-pozvolyayushhaya-prochitat-nedostupnye-polzovatelyu-fajly","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-05-16T04:24:28+00:00","article:modified_time":"2026-05-16T04:24:28+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/170805","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=170805"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/170805\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=170805"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=170805"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=170805"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}