{"id":182539,"date":"2026-07-08T10:54:16","date_gmt":"2026-07-08T08:54:16","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/bad-epoll-v-linux-i-android-nashli-uyazvimost-dlya-polucheniya-root-dostupa"},"modified":"2026-07-08T10:54:16","modified_gmt":"2026-07-08T08:54:16","slug":"bad-epoll-v-linux-i-android-nashli-uyazvimost-dlya-polucheniya-root-dostupa","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/bad-epoll-v-linux-i-android-nashli-uyazvimost-dlya-polucheniya-root-dostupa","title":{"rendered":"Bad Epoll: u zbulua nj\u00eb vulnerabilitet n\u00eb Linux dhe Android q\u00eb mund\u00ebson akses root.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" src=\"\/wp-content\/uploads\/2026\/07\/55dd8eda44f5f48052b033a5c9bcab2d.jpg\" style=\"display:block;margin: 0 auto;\" \/>                                  <noindex>          <a rel=\"nofollow\" id=\"memories_button\" href=\"#\" title=\"Monitoro\"><i class=\"icon-bell\"><\/i><\/a><br \/>1                            <noindex><\/p>\n<p>Nj\u00eb vulnerabilitet \u00ebsht\u00eb zbuluar n\u00eb kernelin Linux <strong>Bad Epoll<\/strong>, e regjistruar si <a rel=\"nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-46242\">CVE-2026-46242<\/a>. Ajo lejon nj\u00eb p\u00ebrdorues lokal normal pa t\u00eb drejta speciale t\u00eb rris\u00eb privilegjet deri n\u00eb root. Sipas autorit t\u00eb studimit, Jayona Chung, problemi prek jo vet\u00ebm desktop\u00ebt dhe server\u00ebt Linux, por edhe disa pajisje Android me versionet e reja t\u00eb kernel-it \u2014 kjo theksohet ve\u00e7mas n\u00eb <a rel=\"nofollow\" href=\"https:\/\/github.com\/J-jaeyoung\/bad-epoll\">p\u00ebrshkrimin e Bad Epoll<\/a>.<\/p>\n<p><\/noindex> <noindex><\/p>\n<p>Gabimi ndodhet n\u00eb n\u00ebn-sistemin <strong>epoll<\/strong> \u2014 mekanizmi standard i Linux p\u00ebr ndjekjen e shum\u00eb descriptor\u00ebve t\u00eb skedar\u00ebve, lidhjeve rrjeti dhe ngjarjeve t\u00eb input-output. Mekanizma t\u00eb till\u00eb p\u00ebrdoren gjer\u00ebsisht nga server\u00ebt, shfletuesit dhe sh\u00ebrbimet e rrjetit, prandaj thjesht \u00e7aktivizimi i epoll-it nuk \u00ebsht\u00eb i mundur. N\u00eb <a rel=\"nofollow\" href=\"https:\/\/github.com\/J-jaeyoung\/security-research\/blob\/submit-cve-2026-46242\/pocs\/linux\/kernelctf\/CVE-2026-46242_lts_cos\/docs\/vulnerability.md\">analiz\u00ebn teknike<\/a> vulnerabiliteti p\u00ebrshkruhet si nj\u00eb gar\u00eb, q\u00eb \u00e7on n\u00eb <strong>use-after-free<\/strong>: me mbylljen e nj\u00ebkohshme t\u00eb objekteve t\u00eb lidhura epoll, nj\u00eb rrjedh\u00eb lirohet nga strukturat e brendshme, nd\u00ebrsa nj\u00eb tjet\u00ebr vazhdon t'i qaset atyre.<\/p>\n<p><\/noindex> <\/p>\n<p>N\u00ebse jemi m\u00eb t\u00eb sakt\u00eb, problemi shfaqet n\u00eb situat\u00ebn kur nj\u00eb descriptor epoll ndjek nj\u00eb tjet\u00ebr, dhe t\u00eb dy descriptor\u00ebt mbyllen paralelisht. Pas thirrjes __ep_remove(), fusha file-&gt;f_ep p\u00ebrkoh\u00ebsisht nullohet, dhe __fput() konkurruese mund t\u00eb vendos\u00eb se pastrimi shtes\u00eb tashm\u00eb nuk \u00ebsht\u00eb i nevojsh\u00ebm. Si rezultat, objekti struct eventpoll ose lidhja e tij struct file lirohet shum\u00eb her\u00ebt, por kodi vazhdon t\u00eb funksionoj\u00eb me tregues n\u00eb kujtes\u00ebn e dor\u00ebzuar tashm\u00eb. Kjo e jep pik\u00ebrisht sulmuesit nj\u00eb primitiv p\u00ebr d\u00ebmtimin e memories n\u00eb kernel.<\/p>\n<p> <noindex><\/p>\n<p>P\u00ebr sulmin nuk nevojiten kapacitete shtes\u00eb dhe nuk k\u00ebrkohen hap\u00ebsira p\u00ebrdoruesish \u2014 mjafton prania e CONFIG_EPOLL, e cila e b\u00ebn problemin ve\u00e7an\u00ebrisht t\u00eb pak\u00ebndsh\u00ebm p\u00ebr sistemet e zakonshme Linux. Sipas <a rel=\"nofollow\" href=\"https:\/\/github.com\/J-jaeyoung\/security-research\/blob\/submit-cve-2026-46242\/pocs\/linux\/kernelctf\/CVE-2026-46242_lts_cos\/docs\/vulnerability.md\">raportit fillestar t\u00eb hulumtuesit<\/a>, gabimi u p\u00ebrfshi n\u00eb kernel me komitin <a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=58c9b016e128\">58c9b016e128<\/a> n\u00eb vitin 2023, dhe u korrigjua me komitin <a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=a6dc643c693\">a6dc643c693<\/a>.<\/p>\n<p><\/noindex> <noindex><\/p>\n<p>Pavar\u00ebsisht nga nj\u00eb dritare shum\u00eb e ngusht\u00eb gare, hulumtuesi p\u00ebrgatiti nj\u00eb shfryt\u00ebzim funksional p\u00ebr Google kernelCTF. N\u00eb <a rel=\"nofollow\" href=\"https:\/\/github.com\/J-jaeyoung\/security-research\/blob\/submit-cve-2026-46242\/pocs\/linux\/kernelctf\/CVE-2026-46242_lts_cos\/docs\/exploit.md\">p\u00ebrshkrimin e shfryt\u00ebzimit<\/a> tregohet se si gabimi shnd\u00ebrrohet n\u00eb nj\u00eb shkrim 8-byte n\u00eb struktur\u00ebn e dor\u00ebzuar, pastaj n\u00eb nj\u00eb rrjedh\u00eb memories n\u00eb kernel p\u00ebrmes \/proc\/self\/fdinfo, kapje e file-&gt;f_op-&gt;poll dhe nj\u00eb zinxhir ROP p\u00ebr t\u00eb marr\u00eb root. P\u00ebr objektin lts-6.12.67, \u00ebsht\u00eb deklaruar nj\u00eb besueshm\u00ebri rreth 99%, p\u00ebr COS rreth 98%; shfryt\u00ebzimi p\u00ebr Android, sipas autorit, \u00ebsht\u00eb ende n\u00eb pun\u00eb.<\/p>\n<p><\/noindex> <noindex><\/p>\n<p>N\u00eb rrezik jan\u00eb kernel\u00ebt e bazuar n\u00eb deg\u00ebn <strong>6.4 dhe m\u00eb t\u00eb reja<\/strong>, n\u00ebse n\u00eb to nuk \u00ebsht\u00eb transferuar korigjimi. Pajisjet e vjetra Android n\u00eb kernel\u00ebt 6.1, duke p\u00ebrfshir\u00eb Pixel 8 dhe modele t\u00eb ngjashme, autori <a rel=\"nofollow\" href=\"https:\/\/github.com\/J-jaeyoung\/bad-epoll\">i konsideron t\u00eb paprekura<\/a>. P\u00ebrdoruesit dhe administrator\u00ebt kan\u00eb nj\u00eb mund\u00ebsi t\u00eb vetme normale mbrojtjeje - t\u00eb instalojn\u00eb p\u00ebrdit\u00ebsimin e b\u00ebrtham\u00ebs nga distribucioni ose ofruesi i pajisjes s\u00eb tyre.<\/p>\n<p><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.linux.org.ru\/news\/security\/18335032\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>1 \u0412 \u044f\u0434\u0440\u0435 Linux \u0440\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c Bad Epoll, \u0437\u0430\u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u0430\u044f \u043a\u0430\u043a CVE-2026-46242. \u041e\u043d\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043e\u0431\u044b\u0447\u043d\u043e\u043c\u0443 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0431\u0435\u0437 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0445 \u043f\u0440\u0430\u0432 \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0434\u043e root. \u041f\u043e \u0434\u0430\u043d\u043d\u044b\u043c \u0430\u0432\u0442\u043e\u0440\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f \u0414\u0436\u044d\u0451\u043d\u0430 \u0427\u043e\u043d\u0430, \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u043d\u0435 \u0442\u043e\u043b\u044c\u043a\u043e Linux-\u0434\u0435\u0441\u043a\u0442\u043e\u043f\u044b \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u044b, \u043d\u043e \u0438 \u0447\u0430\u0441\u0442\u044c Android-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 \u043d\u0430 \u043d\u043e\u0432\u044b\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u044f\u0434\u0440\u0430 \u2014 \u044d\u0442\u043e \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e \u043f\u043e\u0434\u0447\u0451\u0440\u043a\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0432 \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0438 Bad Epoll. \u041e\u0448\u0438\u0431\u043a\u0430 \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":9,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-182539","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Emin Berklin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/bad-epoll-v-linux-i-android-nashli-uyazvimost-dlya-polucheniya-root-dostupa\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Bad Epoll: \u0432 Linux \u0438 Android \u043d\u0430\u0448\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0434\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f root-\u0434\u043e\u0441\u0442\u0443\u043f\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/bad-epoll-v-linux-i-android-nashli-uyazvimost-dlya-polucheniya-root-dostupa\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-07-08T08:54:16+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-08T08:54:16+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Bad Epoll: u zbulua nj\u00eb vuln\u00ebrabilitet n\u00eb Linux dhe Android p\u00ebr t\u00eb fituar akses root | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/bad-epoll-v-linux-i-android-nashli-uyazvimost-dlya-polucheniya-root-dostupa","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Bad Epoll: \u0432 Linux \u0438 Android \u043d\u0430\u0448\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0434\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f root-\u0434\u043e\u0441\u0442\u0443\u043f\u0430 | ProHoster","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/bad-epoll-v-linux-i-android-nashli-uyazvimost-dlya-polucheniya-root-dostupa","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-07-08T08:54:16+00:00","article:modified_time":"2026-07-08T08:54:16+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"182539","title":null,"description":null,"keywords":null,"keyphrases":{"focus":[],"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-08-05 12:22:07","updated":"2026-08-05 12:22:07","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/182539","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=182539"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/182539\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=182539"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=182539"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=182539"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}