{"id":181665,"date":"2026-05-22T18:24:54","date_gmt":"2026-05-22T16:24:54","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/vo-freebsd-ustraneno-4-uyazvimosti-pozvolyayushhie-podnyat-privilegii-i-odna-udalyonnaya-root-uyazvimost"},"modified":"2026-05-22T18:24:54","modified_gmt":"2026-05-22T16:24:54","slug":"vo-freebsd-ustraneno-4-uyazvimosti-pozvolyayushhie-podnyat-privilegii-i-odna-udalyonnaya-root-uyazvimost","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/vo-freebsd-ustraneno-4-uyazvimosti-pozvolyayushhie-podnyat-privilegii-i-odna-udalyonnaya-root-uyazvimost","title":{"rendered":"4 vulnerabilitete jan\u00eb eliminuar n\u00eb FreeBSD q\u00eb lejojn\u00eb rritjen e privilegjeve dhe nj\u00eb vulnerabilitet root n\u00eb distanc\u00eb","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb FreeBSD jan\u00eb eliminuar 7 vulnerabilitete, nga t\u00eb cilat nj\u00eb lejon ekzekutimin e kodit nga distanca me t\u00eb drejta root, dhe kat\u00ebr rritin privilegjet n\u00eb sistem. Vulnerabilitetet jan\u00eb eliminuar n\u00eb p\u00ebrdit\u00ebsimet FreeBSD 15.0-RELEASE-p9, 14.4-RELEASE-p5 dhe 14.3-RELEASE-p14. <\/p>\n<ul>\n<li class=\"l\"> CVE-2026-45255 \u2014 n\u00eb instaluesin bsdinstall dhe konfiguratorin bsdconfig mungonte mbrojtja e karaktereve speciale n\u00eb skriptin e shell-it, i cili tregon p\u00ebrdoruesit list\u00ebn e rrjeteve t\u00eb disponueshme p\u00ebr t'u lidhur, t\u00eb cilat jan\u00eb p\u00ebrcaktuar si pasoj\u00eb e skanimit. Nj\u00eb sulmues mund t\u00eb krijoj\u00eb nj\u00eb pik\u00eb qasjeje t\u00eb rreme dhe t\u00eb caktoj\u00eb nj\u00eb identifikues rrjeti (SSID) t\u00eb formuar posa\u00e7\u00ebrisht, q\u00eb p\u00ebrmban komanda q\u00eb ekzekutohen n\u00eb shell (p.sh., \u00abtest`id`\u00bb. Kur p\u00ebrdoruesi th\u00ebrret funksionin p\u00ebr t\u00eb k\u00ebrkuar rrjete t\u00eb paq\u00ebna, komandat e shell-it t\u00eb futura nga sulmuesi do t\u00eb ekzekutohen n\u00eb sistemin e p\u00ebrdoruesit me t\u00eb drejta root (zgjedhja ose lidhja me rrjetin e sulmuesit nuk k\u00ebrkohet, mjafton thjesht t\u00eb filloni skanimin e rrjeteve).\n<li class=\"l\"> CVE-2026-45250 \u2014 mbushja e stack-ut n\u00eb thirrjen e sistemit setcred, e cila lejon nj\u00eb p\u00ebrdorues lokal pa privilegje t\u00eb arrij\u00eb ekzekutimin e kodit t\u00eb tij n\u00eb nivelin e b\u00ebrtham\u00ebs. Problemi shkaktohet nga kontrolli i pap\u00ebrshtatsh\u00ebm i madh\u00ebsis\u00eb s\u00eb t\u00eb dh\u00ebnave t\u00eb vendosura n\u00eb tampon \u2014 n\u00eb vend t\u00eb \u00absizeof(gid_t)\u00bb u tregua \u00absizeof(*groups)\u00bb. P\u00ebr t\u00eb thirrur thirrjen e sistemit setcred k\u00ebrkohen privilegje t\u00eb rritur, por vulnerabiliteti ekziston n\u00eb kodin e kopjimit fillestar n\u00eb nj\u00eb tampon t\u00eb ve\u00e7ant\u00eb t\u00eb list\u00ebs s\u00eb grupeve t\u00eb d\u00ebrguara nga p\u00ebrdoruesi, q\u00eb ekzekutohet para kontrollit t\u00eb privilegjeve.\n<li class=\"l\"> CVE-2026-45251 \u2014 referimi n\u00eb memorie t\u00eb liruar tashm\u00eb (use-after-free) n\u00eb thirrjet sistemike select dhe poll, q\u00eb ndodh n\u00eb rast t\u00eb mbylljes s\u00eb deskriptorit t\u00eb dosjes t\u00eb d\u00ebrguar n\u00eb momentin para \u00e7lirimit t\u00eb fillimit, q\u00eb pret dosjet nga thirrjet sistemike select dhe poll. Ekspozimi i suksessh\u00ebm lejon nj\u00eb p\u00ebrdorues pa privilegje t\u00eb ekzekutoj\u00eb kod n\u00eb nivelin e b\u00ebrtham\u00ebs.\n<li class=\"l\"> CVE-2026-45253 \u2014 mungesa e kontrollit t\u00eb duhur t\u00eb parametrave t\u00eb d\u00ebrguar n\u00eb thirrjen e sistemit ptrace gjat\u00eb realizimit t\u00eb operacionit PT_SC_REMOTE. Vulnerabiliteti i lejon nj\u00eb p\u00ebrdoruesi pa privilegje t\u00eb organizoj\u00eb ekzekutimin e kodit t\u00eb rast\u00ebsish\u00ebm n\u00eb b\u00ebrtham\u00eb, madje edhe n\u00ebse procesi i q\u00eblluar n\u00eb debug nuk ka privilegje speciale.\n<li class=\"l\"> CVE-2026-39461 \u2014 nj\u00eb mbushje steke n\u00eb bibliotek\u00ebn libcasper, e cila ofron aplikacioneve t\u00eb izoluara p\u00ebrmes mekanizmit Capsicum qasje n\u00eb nd\u00ebrfaqet sistemore. Gjat\u00eb nd\u00ebrveprimit me menaxherin n\u00ebp\u00ebrmjet soketeve UNIX, biblioteka p\u00ebrdor thirrjen sistemore select p\u00ebr t\u00eb pritur t\u00eb dh\u00ebna, por nuk kontrollon p\u00ebrputhshm\u00ebrin\u00eb e descriptorit t\u00eb soketit me limitin aktual n\u00eb select FD_SETSIZE (1024). Nj\u00eb sulmues mund t\u00eb nxis\u00eb dh\u00ebnien e deskriptor\u00ebve t\u00eb m\u00ebdhenj t\u00eb skedar\u00ebve n\u00eb nj\u00eb aplikacion mbi libcasper dhe t\u00eb shkaktoj\u00eb mbushje steke. Me manipulime t\u00eb tilla me programet setuid root, mund t\u00eb arrihet ekzekutimi i kodit me t\u00eb drejtat root.\n<li class=\"l\"> CVE-2026-45254 \u2014 mund\u00ebsia e anashkalimit t\u00eb kufijve cap_net n\u00eb aplikacion p\u00ebr shkak se \u00e7el\u00ebsi q\u00eb mungon perceptohet si \"lejo \u00e7do\" n\u00eb vend q\u00eb t\u00eb bllokohet.\n<li class=\"l\"> CVE-2026-45252 \u2014 mbushje buferi n\u00eb modulit fusefs gjat\u00eb trajtimit t\u00eb mesazheve FUSE_LISTXATTR, e cila lejon t\u00eb lexoni deri n\u00eb 253 byte nga memoria e b\u00ebrtham\u00ebs jasht\u00eb buferit ose t\u00eb shkruani deri n\u00eb 250 byte n\u00eb nj\u00eb zon\u00eb t\u00eb pap\u00ebrdorur t\u00eb grumbullit.\n<\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65497\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043e 7 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0434\u043d\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root, \u0430 \u0447\u0435\u0442\u044b\u0440\u0435 \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0432 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f\u0445 FreeBSD 15.0-RELEASE-p9, 14.4-RELEASE-p5 \u0438 14.3-RELEASE-p14. CVE-2026-45255 &#8212; \u0432 \u0438\u043d\u0441\u0442\u0430\u043b\u043b\u044f\u0442\u043e\u0440\u0435 bsdinstall \u0438 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0442\u043e\u0440\u0435 bsdconfig \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u043b\u043e \u044d\u043a\u0440\u0430\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0441\u043f\u0435\u0446\u0441\u0438\u043c\u0432\u043e\u043b\u043e\u0432 \u0432 shell-\u0441\u043a\u0440\u0438\u043f\u0442\u0435, \u043f\u043e\u043a\u0430\u0437\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0441\u043f\u0438\u0441\u043e\u043a \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b\u0445 \u0434\u043b\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0435\u0442\u0435\u0439, \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u044b\u0445 \u0432 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-181665","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043e 7 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0434\u043d\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root, \u0430 \u0447\u0435\u0442\u044b\u0440\u0435 \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/vo-freebsd-ustraneno-4-uyazvimosti-pozvolyayushhie-podnyat-privilegii-i-odna-udalyonnaya-root-uyazvimost\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043e 4 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438, \u0438 \u043e\u0434\u043d\u0430 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u0430\u044f root-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043e 7 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0434\u043d\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root, \u0430 \u0447\u0435\u0442\u044b\u0440\u0435 \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/vo-freebsd-ustraneno-4-uyazvimosti-pozvolyayushhie-podnyat-privilegii-i-odna-udalyonnaya-root-uyazvimost\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-05-22T16:24:54+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-05-22T16:24:54+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47N\u00eb FreeBSD jan\u00eb eliminuar 4 vulnerabilitete q\u00eb lejojn\u00eb rritjen e privilegjeve, dhe nj\u00eb vulnerabilitet i larg\u00ebt me privilegje root | ProHoster","description":"N\u00eb FreeBSD jan\u00eb eliminuar 7 Vulnerabilitete, nga t\u00eb cilat nj\u00ebra lejon ekzekutimin e kodit n\u00eb distanc\u00eb me privilegje root, dhe kat\u00ebr t\u00eb tjera rrisin privilegjet n\u00eb sistem.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/vo-freebsd-ustraneno-4-uyazvimosti-pozvolyayushhie-podnyat-privilegii-i-odna-udalyonnaya-root-uyazvimost","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043e 4 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438, \u0438 \u043e\u0434\u043d\u0430 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u0430\u044f root-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c | ProHoster","og:description":"\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043e 7 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0434\u043d\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root, \u0430 \u0447\u0435\u0442\u044b\u0440\u0435 \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/vo-freebsd-ustraneno-4-uyazvimosti-pozvolyayushhie-podnyat-privilegii-i-odna-udalyonnaya-root-uyazvimost","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-05-22T16:24:54+00:00","article:modified_time":"2026-05-22T16:24:54+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/181665","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=181665"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/181665\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=181665"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=181665"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=181665"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}