{"id":172668,"date":"2026-05-19T06:24:52","date_gmt":"2026-05-19T04:24:52","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/v-linux-zakryta-uyazvimost-ssh-keysign-pwn-pozvolyayushhaya-lokalnym-polzovatelyam-chitat-root-fajly"},"modified":"2026-05-19T12:52:18","modified_gmt":"2026-05-19T10:52:18","slug":"v-linux-zakryta-uyazvimost-ssh-keysign-pwn-pozvolyayushhaya-lokalnym-polzovatelyam-chitat-root-fajly","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/v-linux-zakryta-uyazvimost-ssh-keysign-pwn-pozvolyayushhaya-lokalnym-polzovatelyam-chitat-root-fajly","title":{"rendered":"N\u00eb Linux \u00ebsht\u00eb mbyllur nj\u00eb dob\u00ebsi ssh-keysign-pwn q\u00eb lejon p\u00ebrdoruesit lokal\u00eb t\u00eb lexojn\u00eb skedar\u00ebt e root.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb kernelin e Linux \u00ebsht\u00eb rregulluar nj\u00eb dob\u00ebsi, e cila ka marr\u00eb emrin jozyrtar <strong>ssh-keysign-pwn<\/strong>. Problemi lejon nj\u00eb p\u00ebrdorues lokal pa privilegje t\u00eb lexoj\u00eb skedar\u00eb q\u00eb duhet t\u00eb jen\u00eb t\u00eb aksesuesh\u00ebm vet\u00ebm nga root, duke p\u00ebrfshir\u00eb \u00e7el\u00ebsat privat\u00eb SSH host dhe, n\u00eb skenar\u00eb t\u00eb caktuar, \/etc\/shadow. N\u00eb momentin e publikimit, nj\u00eb CVE i ve\u00e7ant\u00eb p\u00ebr problemin nuk ishte akoma caktuar.<\/p>\n<p>  <noindex><noindex><\/p>\n<p>Pavar\u00ebsisht emrit, nuk b\u00ebhet fjal\u00eb p\u00ebr nj\u00eb gabim n\u00eb OpenSSH si nj\u00eb server rrjeti sshd, por p\u00ebr nj\u00eb <a rel=\"nofollow\" href=\"https:\/\/github.com\/torvalds\/linux\/commit\/31e62c2ebbfdc3fe3dbdf5e02c92a9dc67087a3a\">defekt<\/a> n\u00eb logjik\u00ebn e kernelit t\u00eb Linux, n\u00eb lidhje me verifikimet ptrace dhe aksesin n\u00eb descriptor\u00ebt e skedar\u00ebve t\u00eb nj\u00eb procesi tjet\u00ebr p\u00ebrmes pidfd_getfd(2). Utilitari OpenSSH ssh-keysign doli t\u00eb ishte nj\u00eb nga shembujt e p\u00ebrshtatsh\u00ebm t\u00eb shfryt\u00ebzimit, sepse punon me \u00e7el\u00ebsat privat\u00eb host, t\u00eb cil\u00ebt zakonisht i p\u00ebrkasin root dhe nuk jan\u00eb t\u00eb aksesuesh\u00ebm p\u00ebr p\u00ebrdoruesit e zakonsh\u00ebm.<\/p>\n<p><\/noindex><\/noindex> <noindex><\/p>\n<p><a rel=\"nofollow\" href=\"https:\/\/github.com\/0xdeadbeefnetwork\/ssh-keysign-pwn\">Thelbi i gabimit<\/a> ka funksioni __ptrace_may_access() trajton ndryshe gjendjen e nj\u00eb procesi, i cili tashm\u00eb ka humbur struktur\u00ebn e memories mm, por ende ka ende deshifruese t\u00eb hapura. Gjat\u00eb p\u00ebrfundimit t\u00eb procesit, b\u00ebrthama th\u00ebrret exit_mm() m\u00eb her\u00ebt se sa mbyll,,,, skedar\u00ebt p\u00ebrmes exit_files(). N\u00eb k\u00ebt\u00eb interval t\u00eb shkurt\u00ebr, procesi duket se nuk ka nj\u00eb hap\u00ebsir\u00eb adrese normale t\u00eb p\u00ebrdoruesit, por skedar\u00ebt e tij t\u00eb hapur ende ekzistojn\u00eb. P\u00ebr shkak t\u00eb k\u00ebsaj, kontrolli i gjendjes 'dumpable' mund t\u00eb anashkalohet, nd\u00ebrsa pidfd_getfd() mund t\u00eb aksesoj\u00eb nj\u00eb deshifruese t\u00eb huaj n\u00eb rast t\u00eb nj\u00eb UID q\u00eb p\u00ebrputhet.<\/p>\n<p><\/noindex> <\/p>\n<p>Nj\u00eb skenar praktik nd\u00ebrttohet rreth programeve setuid, t\u00eb cilat fillimisht hapin nj\u00eb skedar t\u00eb ndjesh\u00ebm me t\u00eb drejta root, pastaj i heqin privilegjet dhe p\u00ebrfundojn\u00eb, duke pasur ende nj\u00eb deshifruese t\u00eb hapur. N\u00eb p\u00ebrshkrimin e publikuar si shembull p\u00ebrmendet ssh-keysign: ai hap \/etc\/ssh\/ssh_host_{ecdsa,ed25519,rsa}_key, pas s\u00eb cil\u00ebs heq t\u00eb drejtat dhe mund t\u00eb p\u00ebrfundoj\u00eb n\u00ebse EnableSSHKeysign \u00ebsht\u00eb i \u00e7aktivizuar. K\u00ebto \u00e7el\u00ebsa duhet t\u00eb jen\u00eb vet\u00ebm t\u00eb aksesuesh\u00ebm nga root, pasi p\u00ebrdoren p\u00ebr autentikimin e bazuar n\u00eb host.<\/p>\n<p>Shembulli i dyt\u00eb \u2014 chage, i cili mund t\u00eb hap\u00eb \/etc\/shadow, pastaj t\u00eb rikthesoj\u00eb t\u00eb drejtat efektive dhe t\u00eb p\u00ebrfundoj\u00eb. Si rezultat, sulmi nuk i jep domosdoshm\u00ebrisht menj\u00ebher\u00eb shell me t\u00eb drejtat root, por lejon q\u00eb t\u00eb merret p\u00ebrmbajtja e skedar\u00ebve, e cila zakonisht konsiderohet kritikisht e fsheht\u00eb. Shk\u00ebputja e \/etc\/shadow \u00ebsht\u00eb e rrezikshme p\u00ebr mund\u00ebsin\u00eb e p\u00ebrshtatjes offline t\u00eb fjal\u00ebkalimeve, nd\u00ebrsa shk\u00ebputja e \u00e7el\u00ebsave privat\u00eb t\u00eb host-SSH rrezikon ndryshimin e hostit ose kryerjen e sulmeve ndaj skenar\u00ebve t\u00eb besuesh\u00ebm SSH.<\/p>\n<p>Korrigjimi \u00ebsht\u00eb pranuar tashm\u00eb n\u00eb deg\u00ebn kryesore t\u00eb Linux. Komit 31e62c2ebbfd me titullin ptrace: logjik\u00eb pak m\u00eb bashk\u00ebkohore &#8216;get_dumpable()&#8217; ndryshon sjelljen e kontrollit t\u00eb dumpabilitetit: b\u00ebrthama tani ruan gjendjen user_dumpable kur mm shuhet dhe k\u00ebrkon nj\u00eb kontroll t\u00eb sakt\u00eb t\u00eb CAP_SYS_PTRACE p\u00ebr ta kaluar. Patch-i prek include\/linux\/sched.h, kernel\/exit.c dhe kernel\/ptrace.c.<\/p>\n<p>Vulnerabiliteti u raportua nga Qualys dhe u rregullua nga Linus Torvalds m\u00eb 14 maj 2026. Phoronix tregon se, n\u00eb koh\u00ebn e publikimit, problemi prekte t\u00eb gjitha l\u00ebshimet e b\u00ebrtham\u00ebs Linux deri n\u00eb gjendjen aktuale t\u00eb deg\u00ebs mainline p\u00ebrpara se t\u00eb b\u00ebhej rregullimi. Autori i PoC gjithashtu thekson se b\u00ebrthamat vulnerable jan\u00eb ato deri n\u00eb komitin 31e62c2ebbfd, duke p\u00ebrfshir\u00eb deg\u00ebt e q\u00ebndrueshme deri m\u00eb 14 maj.<\/p>\n<p> <noindex><\/p>\n<p>\u00cbsht\u00eb e r\u00ebnd\u00ebsishme q\u00eb p\u00ebr funksionimin nuk k\u00ebrkohet ngarkimi i moduleve specifike t\u00eb b\u00ebrtham\u00ebs, si n\u00eb disa nga dob\u00ebsit\u00eb e fundit LPE. Mjafton akses lokal pa privilegje n\u00eb sistem dhe prania e nj\u00eb procesi helper me privilegje t\u00eb p\u00ebrshtatshme. Zhvilluesi i Debian, Daniel Baumann <a rel=\"nofollow\" href=\"https:\/\/blog.daniel-baumann.ch\/posts\/20260515-1.html\">vuri n\u00eb dukje<\/a>, q\u00eb ky problem duhet t\u00eb rregullohet me nj\u00eb p\u00ebrdit\u00ebsim t\u00eb b\u00ebrtham\u00ebs dhe nj\u00eb rinisje n\u00eb b\u00ebrtham\u00ebn e korrigjuar.<\/p>\n<p><\/noindex> <\/p>\n<p>N\u00eb repositorin e publikuar me demonstrim, \u00ebsht\u00eb shpallur kontrolli p\u00ebr Raspberry Pi OS Bookworm me b\u00ebrtham\u00ebn 6.12.75, Debian 13, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04, Arch dhe CentOS 9. Ky list\u00eb duhet marr\u00eb si t\u00eb dh\u00ebna nga autori i PoC, dhe jo si nj\u00eb list\u00eb p\u00ebrfundimtare: pasi gabimi ndodhet n\u00eb logjik\u00ebn e p\u00ebrgjithshme t\u00eb b\u00ebrtham\u00ebs, mbulimi real varet nga versioni i b\u00ebrtham\u00ebs dhe prishtja e backport-it n\u00eb distro t\u00eb caktuar.<\/p>\n<p>P\u00ebr administrator\u00ebt, rekomandimi kryesor \u00ebsht\u00eb i thjesht\u00eb: instaloni paket\u00ebn e p\u00ebrdit\u00ebsuar t\u00eb b\u00ebrtham\u00ebs nga shp\u00ebrndarja juaj dhe rinisni sistemin. N\u00ebse ekzistojn\u00eb dyshime se n\u00eb makin\u00eb tashm\u00eb ka pasur akses lokal t\u00eb pakufizuar nga nj\u00eb sulmues, pas p\u00ebrdit\u00ebsimit rekomandohet gjithashtu rotacioni i \u00e7el\u00ebsave t\u00eb hostit SSH dhe verifikimi i regjistrimeve n\u00eb \/etc\/shadow\/, pasi vet\u00eb dob\u00ebsia lidhet sakt\u00ebsisht me leximin e skedar\u00ebve t\u00eb ndjesh\u00ebm, dhe jo vet\u00ebm me nj\u00eb kalim t\u00eb thjesht\u00eb t\u00eb kontrolleve t\u00eb aksesit.<\/p>\n<p>N\u00eb Debian ka filluar tashm\u00eb puna p\u00ebr transferimin e korigjimit: Baumann njoftoi p\u00ebr cherry-pick t\u00eb commit-it upstream n\u00eb trixie-fastforward-backports dhe p\u00ebr d\u00ebrgimin e k\u00ebrkes\u00ebs p\u00ebr bashkim p\u00ebr Debian sid. N\u00eb k\u00ebrkes\u00ebn p\u00ebr bashkim \u00ebsht\u00eb specifikuar drejtp\u00ebrdrejt se po transferohet commit-i 31e62c2 p\u00ebr t\u00eb rregulluar logjik\u00ebn e ptrace dumpability, e cila lejon leximin e skedar\u00ebve root nga nj\u00eb p\u00ebrdorues pa privilegje.<\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.linux.org.ru\/news\/security\/18293396\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u044f\u0434\u0440\u0435 Linux \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0430\u044f \u043d\u0435\u043e\u0444\u0438\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0435 \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 ssh-keysign-pwn. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0447\u0438\u0442\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0434\u043e\u043b\u0436\u043d\u044b \u0431\u044b\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b \u0442\u043e\u043b\u044c\u043a\u043e root, \u0432\u043a\u043b\u044e\u0447\u0430\u044f \u043f\u0440\u0438\u0432\u0430\u0442\u043d\u044b\u0435 SSH host-\u043a\u043b\u044e\u0447\u0438 \u0438, \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0441\u0446\u0435\u043d\u0430\u0440\u0438\u044f\u0445, \/etc\/shadow. \u041d\u0430 \u043c\u043e\u043c\u0435\u043d\u0442 \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0439 CVE \u0434\u043b\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0435\u0449\u0451 \u043d\u0435 \u0431\u044b\u043b \u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d. \u041d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435, \u0440\u0435\u0447\u044c \u0438\u0434\u0451\u0442 \u043d\u0435 \u043e\u0431 \u043e\u0448\u0438\u0431\u043a\u0435 \u0432 OpenSSH \u043a\u0430\u043a \u0441\u0435\u0442\u0435\u0432\u043e\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-172668","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0430\u044f \u043d\u0435\u043e\u0444\u0438\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0435 \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 ssh-keysign-pwn. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0447\u0438\u0442\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0434\u043e\u043b\u0436\u043d\u044b \u0431\u044b\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b \u0442\u043e\u043b\u044c\u043a\u043e root, \u0432\u043a\u043b\u044e\u0447\u0430\u044f \u043f\u0440\u0438\u0432\u0430\u0442\u043d\u044b\u0435 SSH host-\u043a\u043b\u044e\u0447\u0438 \u0438, \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0441\u0446\u0435\u043d\u0430\u0440\u0438\u044f\u0445, \/etc\/shadow. \u041d\u0430 \u043c\u043e\u043c\u0435\u043d\u0442 \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0439 CVE \u0434\u043b\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0435\u0449\u0451 \u043d\u0435 \u0431\u044b\u043b \u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d. \u041d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435, \u0440\u0435\u0447\u044c \u0438\u0434\u0451\u0442 \u043d\u0435 \u043e\u0431 \u043e\u0448\u0438\u0431\u043a\u0435 \u0432 OpenSSH \u043a\u0430\u043a \u0441\u0435\u0442\u0435\u0432\u043e\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0435\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/v-linux-zakryta-uyazvimost-ssh-keysign-pwn-pozvolyayushhaya-lokalnym-polzovatelyam-chitat-root-fajly\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 Linux \u0437\u0430\u043a\u0440\u044b\u0442\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c ssh-keysign-pwn, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u044b\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u043c \u0447\u0438\u0442\u0430\u0442\u044c root-\u0444\u0430\u0439\u043b\u044b | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0430\u044f \u043d\u0435\u043e\u0444\u0438\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0435 \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 ssh-keysign-pwn. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0447\u0438\u0442\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0434\u043e\u043b\u0436\u043d\u044b \u0431\u044b\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b \u0442\u043e\u043b\u044c\u043a\u043e root, \u0432\u043a\u043b\u044e\u0447\u0430\u044f \u043f\u0440\u0438\u0432\u0430\u0442\u043d\u044b\u0435 SSH host-\u043a\u043b\u044e\u0447\u0438 \u0438, \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0441\u0446\u0435\u043d\u0430\u0440\u0438\u044f\u0445, \/etc\/shadow. \u041d\u0430 \u043c\u043e\u043c\u0435\u043d\u0442 \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0439 CVE \u0434\u043b\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0435\u0449\u0451 \u043d\u0435 \u0431\u044b\u043b \u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d. \u041d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435, \u0440\u0435\u0447\u044c \u0438\u0434\u0451\u0442 \u043d\u0435 \u043e\u0431 \u043e\u0448\u0438\u0431\u043a\u0435 \u0432 OpenSSH \u043a\u0430\u043a \u0441\u0435\u0442\u0435\u0432\u043e\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0435\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/v-linux-zakryta-uyazvimost-ssh-keysign-pwn-pozvolyayushhaya-lokalnym-polzovatelyam-chitat-root-fajly\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-05-19T04:24:52+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-05-19T10:52:18+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 N\u00eb Linux \u00ebsht\u00eb mbyllur dob\u00ebsia ssh-keysign-pwn, e cila lejon p\u00ebrdoruesit lokal\u00eb t\u00eb lexojn\u00eb skedar\u00ebt e root-it | ProHoster","description":"Nj\u00eb dob\u00ebsi \u00ebsht\u00eb korrigjuar n\u00eb kernelin Linux, e njohur jozyrtarisht si ssh-keysign-pwn. Problemi i lejon p\u00ebrdoruesve lokal\u00eb t\u00eb pa privilegjuar t\u00eb lexojn\u00eb skedar\u00eb q\u00eb duhet t\u00eb jen\u00eb t\u00eb disponuesh\u00ebm vet\u00ebm p\u00ebr root, p\u00ebrfshir\u00eb \u00e7el\u00ebsat privat\u00eb t\u00eb hostit SSH dhe, n\u00eb disa skenare, \/etc\/shadow. N\u00eb momentin e publikimit, nj\u00eb CVE e ve\u00e7ant\u00eb p\u00ebr problemin ende nuk ishte caktuar. Megjithat\u00eb, p\u00ebrkund\u00ebr emrit, nuk b\u00ebhet fjal\u00eb p\u00ebr nj\u00eb gabim n\u00eb OpenSSH si nj\u00eb server rrjeti.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/v-linux-zakryta-uyazvimost-ssh-keysign-pwn-pozvolyayushhaya-lokalnym-polzovatelyam-chitat-root-fajly","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 Linux \u0437\u0430\u043a\u0440\u044b\u0442\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c ssh-keysign-pwn, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u044b\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u043c \u0447\u0438\u0442\u0430\u0442\u044c root-\u0444\u0430\u0439\u043b\u044b | ProHoster","og:description":"\u0412 \u044f\u0434\u0440\u0435 Linux \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0430\u044f \u043d\u0435\u043e\u0444\u0438\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0435 \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 ssh-keysign-pwn. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0447\u0438\u0442\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0434\u043e\u043b\u0436\u043d\u044b \u0431\u044b\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b \u0442\u043e\u043b\u044c\u043a\u043e root, \u0432\u043a\u043b\u044e\u0447\u0430\u044f \u043f\u0440\u0438\u0432\u0430\u0442\u043d\u044b\u0435 SSH host-\u043a\u043b\u044e\u0447\u0438 \u0438, \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0441\u0446\u0435\u043d\u0430\u0440\u0438\u044f\u0445, \/etc\/shadow. \u041d\u0430 \u043c\u043e\u043c\u0435\u043d\u0442 \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0439 CVE \u0434\u043b\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0435\u0449\u0451 \u043d\u0435 \u0431\u044b\u043b \u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d. \u041d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435, \u0440\u0435\u0447\u044c \u0438\u0434\u0451\u0442 \u043d\u0435 \u043e\u0431 \u043e\u0448\u0438\u0431\u043a\u0435 \u0432 OpenSSH \u043a\u0430\u043a \u0441\u0435\u0442\u0435\u0432\u043e\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0435","og:url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/v-linux-zakryta-uyazvimost-ssh-keysign-pwn-pozvolyayushhaya-lokalnym-polzovatelyam-chitat-root-fajly","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-05-19T04:24:52+00:00","article:modified_time":"2026-05-19T10:52:18+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/172668","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=172668"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/172668\/revisions"}],"predecessor-version":[{"id":172737,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/172668\/revisions\/172737"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=172668"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=172668"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=172668"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}