{"id":53560,"date":"2019-12-04T00:00:00","date_gmt":"2019-12-03T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/15-uyazvimostej-v-usb-drajverah-postavlyaemyh-v-yadre-linux"},"modified":"2020-02-18T14:01:28","modified_gmt":"2020-02-18T11:01:28","slug":"15-uyazvimostej-v-usb-drajverah-postavlyaemyh-v-yadre-linux","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/15-uyazvimostej-v-usb-drajverah-postavlyaemyh-v-yadre-linux","title":{"rendered":"15 dob\u00ebsi n\u00eb drejtuesit USB, t\u00eb ofruar n\u00eb b\u00ebrtham\u00ebn Linux","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/xairy\">Andi Konovalov<\/a><\/noindex> nga kompania Google  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/12\/03\/4\">publikoi<\/a><\/noindex> raporti mbi identifikimin e 15 vulnerabiliteteve t\u00eb reja (CVE-2019-19523 &#8212; CVE-2019-19537) n\u00eb driverat USB, t\u00eb ofruar n\u00eb kernelin Linux. Kjo \u00ebsht\u00eb sasia e tret\u00eb e problemeve t\u00eb gjetura gjat\u00eb testimeve fuzzing n\u00eb stekun USB n\u00eb paket\u00ebn <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/google\/syzkaller\/blob\/master\/docs\/linux\/external_fuzzing_usb.md\">syzkaller<\/a><\/noindex> &#8212; m\u00eb par\u00eb ky hulumtues <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=47523\">jan\u00eb<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51333\">njoftoi<\/a><\/noindex> p\u00ebr prani t\u00eb 29 vulnerabiliteteve. <\/p>\n<p>K\u00ebt\u00eb her\u00eb n\u00eb list\u00eb jan\u00eb p\u00ebrfshir\u00eb vet\u00ebm vulnerabilitetet e shkaktuara nga qasja n\u00eb zona t\u00eb kujtes\u00ebs q\u00eb jan\u00eb liruar m\u00eb par\u00eb (use-after-free) ose q\u00eb \u00e7ojn\u00eb n\u00eb rrjedhje t\u00eb t\u00eb dh\u00ebnave nga memoria e b\u00ebrtham\u00ebs. Problemet q\u00eb mund t\u00eb p\u00ebrdoren p\u00ebr t\u00eb shkaktuar mosfunksionim nuk jan\u00eb p\u00ebrfshir\u00eb n\u00eb raport. Vulnerabilitetet potencialisht mund t\u00eb eksploatohen kur lidhen me kompjuterin pajisje USB t\u00eb p\u00ebrgatitura posa\u00e7\u00ebrisht. Rregullimet p\u00ebr t\u00eb gjitha problemet e p\u00ebrmendura n\u00eb raport tashm\u00eb jan\u00eb p\u00ebrfshir\u00eb n\u00eb b\u00ebrtham\u00eb, por disa q\u00eb nuk jan\u00eb p\u00ebrfshir\u00eb n\u00eb raport <noindex><a rel=\"nofollow\" href=\"https:\/\/syzkaller.appspot.com\/upstream?manager=ci2-upstream-usb\">gabimit<\/a><\/noindex> ende mbeten t\u00eb palosura.<\/p>\n<p>Vulnerabilitetet m\u00eb t\u00eb rrezikshme t\u00eb klas\u00ebs &#171;use-after-free&#187;, q\u00eb mund t\u00eb \u00e7ojn\u00eb n\u00eb ekzekutimin e kodit nga sulmuesi, jan\u00eb eliminuar n\u00eb driverat adutux, ff-memless, ieee802154, pn533, hiddev, iowarrior, mcba_usb dhe yurex. N\u00eb CVE-2019-19532 jan\u00eb regjistruar gjithashtu 14 vulnerabilitete n\u00eb driverat HID, t\u00eb shkaktuara nga gabimet q\u00eb lejojn\u00eb shkrimin jasht\u00eb kufijve t\u00eb bufferit (out-of-bounds write). N\u00eb driverat ttusb_dec, pcan_usb_fd dhe pcan_usb_pro jan\u00eb gjetur probleme q\u00eb \u00e7ojn\u00eb n\u00eb rrjedhjen e t\u00eb dh\u00ebnave nga memoria e kernelit. N\u00eb kodin e stekut USB p\u00ebr pun\u00ebn me pajisje simbolike \u00ebsht\u00eb identifikuar nj\u00eb problem (CVE-2019-19537), i shkaktuar nga nj\u00eb gjendje garash (race condition).<\/p>\n<p>Gjithashtu mund t\u00eb theksohet<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/11\/22\/1\">identifikimi<\/a><\/noindex> kat\u00ebr vulnerabilitetet (CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901) n\u00eb drejtorin p\u00ebr \u00e7ipet wireless Marvell, t\u00eb cilat mund t\u00eb \u00e7ojn\u00eb n\u00eb mbushje t\u00eb tamponit. Sulmi mund t\u00eb kryhet nga distanca p\u00ebrmes d\u00ebrgimit t\u00eb kadrove t\u00eb formuluara n\u00eb m\u00ebnyr\u00eb t\u00eb caktuar kur lidhen me nj\u00eb pik\u00eb akses wireless nga nj\u00eb sulmues. Si rreziku m\u00eb i mundsh\u00ebm sh\u00ebnohet mosfunksionimi i larg\u00ebt (d\u00ebshtimi i b\u00ebrtham\u00ebs), por nuk p\u00ebrjashtohet as mund\u00ebsia e ekzekutimit t\u00eb kodit n\u00eb sistem.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51974\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0410\u043d\u0434\u0440\u0435\u0439 \u041a\u043e\u043d\u043e\u0432\u0430\u043b\u043e\u0432 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Google \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b \u043e\u0442\u0447\u0451\u0442 \u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0438 \u043e\u0447\u0435\u0440\u0435\u0434\u043d\u044b\u0445 15 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 (CVE-2019-19523 &#8212; CVE-2019-19537) \u0432 USB-\u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430\u0445, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u0435\u043c\u044b\u0445 \u0432 \u044f\u0434\u0440\u0435 Linux. \u042d\u0442\u043e \u0442\u0440\u0435\u0442\u044c\u044f \u043f\u043e\u0440\u0446\u0438\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c, \u043d\u0430\u0439\u0434\u0435\u043d\u043d\u044b\u0445 \u043f\u0440\u0438 \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0438 fuzzing-\u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f USB-\u0441\u0442\u0435\u043a\u0430 \u0432 \u043f\u0430\u043a\u0435\u0442\u0435 syzkaller &#8212; \u0440\u0430\u043d\u0435\u0435 \u0434\u0430\u043d\u043d\u044b\u0439 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0443\u0436\u0435 \u0441\u043e\u043e\u0431\u0449\u0430\u043b \u043e \u043d\u0430\u043b\u0438\u0447\u0438\u0438 29 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439. \u041d\u0430 \u044d\u0442\u043e\u0442 \u0440\u0430\u0437 \u0432 \u0441\u043f\u0438\u0441\u043a\u0435 \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u044b \u0442\u043e\u043b\u044c\u043a\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0432\u044b\u0437\u0432\u0430\u043d\u043d\u044b\u0435 \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0435\u043c \u043a \u0443\u0436\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-53560","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0410\u043d\u0434\u0440\u0435\u0439 \u041a\u043e\u043d\u043e\u0432\u0430\u043b\u043e\u0432 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Google\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/15-uyazvimostej-v-usb-drajverah-postavlyaemyh-v-yadre-linux\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd4715 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 USB-\u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430\u0445, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u044b\u0445 \u0432 \u044f\u0434\u0440\u0435 Linux | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0410\u043d\u0434\u0440\u0435\u0439 \u041a\u043e\u043d\u043e\u0432\u0430\u043b\u043e\u0432 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Google\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/15-uyazvimostej-v-usb-drajverah-postavlyaemyh-v-yadre-linux\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-12-03T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:01:28+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd4715 vulnerabilitete n\u00eb drejtor\u00ebt USB, q\u00eb ofrohen n\u00eb b\u00ebrtham\u00ebn Linux | ProHoster","description":"Andrej Konovalov nga kompania Google","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/15-uyazvimostej-v-usb-drajverah-postavlyaemyh-v-yadre-linux","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd4715 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 USB-\u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430\u0445, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u044b\u0445 \u0432 \u044f\u0434\u0440\u0435 Linux | ProHoster","og:description":"\u0410\u043d\u0434\u0440\u0435\u0439 \u041a\u043e\u043d\u043e\u0432\u0430\u043b\u043e\u0432 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Google","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/15-uyazvimostej-v-usb-drajverah-postavlyaemyh-v-yadre-linux","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-12-03T21:00:00+00:00","article:modified_time":"2020-02-18T11:01:28+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"53560","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 07:52:14","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 15:20:02","updated":"2026-01-24 07:52:14","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/53560","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=53560"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/53560\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=53560"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=53560"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=53560"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}