ืฉื•ื•ืึทื›ืงื™ื™ื˜ ืื™ืŸ Linux- ื“ื™ pidfd ืกื•ื‘ืกื™ืกื˜ืขื, ื•ื•ืึธืก ืขืจืœื•ื™ื‘ื˜ ืœื™ื™ืขื ืขืŸ ื˜ืขืงืขืก ื•ื•ืึธืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ืฆื•ื˜ืจื™ื˜ืœืขืš ืคึฟืึทืจืŸ ื‘ืึทื ื™ืฆืขืจ

ืื™ืŸ ืงืขืจืŸ Linux ื“ื™ ืคื™ื ืคื˜ืข (1, 2, 3) ืงืจื™ื˜ื™ืฉืข ืฉื•ื•ืื›ืงื™ื™ื˜ ืื™ืŸ ื“ื™ ืœืขืฆื˜ืข ืฆื•ื•ื™ื™ ื•ื•ืึธื›ืŸ ืื™ื– ืื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจื˜ ื’ืขื•ื•ืึธืจืŸ, ื•ื•ืึธืก ืขืจืœื•ื™ื‘ื˜ ืึท ื‘ืึทื ื™ืฆืขืจ ืฆื• ืคึฟืึทืจื’ืจืขืกืขืจืŸ ื–ื™ื™ืขืจืข ืคึผืจื™ื•ื•ื™ืœืขื’ื™ืขืก ืื™ืŸ ืกื™ืกื˜ืขื. ืฆื•ื•ื™ื™ ืึทืจื‘ืขื˜ื ื“ื™ืงืข ืขืงืกืคึผืœื•ื™ื˜ืก ื–ืขื ืขืŸ ืคืึทืจืขืคึฟื ื˜ืœืขื›ื˜ ื’ืขื•ื•ืึธืจืŸ: sshkeysign_pwn ืขืจืœื•ื™ื‘ื˜ ืึทืŸ ืึทื ืคึผืจื™ื•ื•ื™ืœืขื’ื™ืจื˜ืŸ ื‘ืึทื ื™ืฆืขืจ ืฆื• ืœื™ื™ืขื ืขืŸ ื“ืขื ืื™ื ื”ืึทืœื˜ ืคึฟื•ืŸ ืคึผืจื™ื•ื•ืึทื˜ืข ื”ืึธืกื˜ SSH ืฉืœื™ืกืœืขืŸ /etc/ssh/ssh_host_*_key, ืื•ืŸ chage_pwn ืขืจืœื•ื™ื‘ื˜ ืึทืŸ ืึทื ืคึผืจื™ื•ื•ื™ืœืขื’ื™ืจื˜ืŸ ื‘ืึทื ื™ืฆืขืจ ืฆื• ืœื™ื™ืขื ืขืŸ ื“ืขื ืื™ื ื”ืึทืœื˜ ืคึฟื•ืŸ ื“ืขืจ /etc/shadow ื˜ืขืงืข ื•ื•ืึธืก ื›ึผื•ืœืœ ื‘ืึทื ื™ืฆืขืจ ืคึผืึทืจืึธืœ ื”ืขืฉื™ื–.

ื“ื™ ืฉื•ื•ืึทื›ืงื™ื™ื˜ ืื™ื– ื ื™ืฉื˜ ื’ืขื•ื•ืขืŸ ื‘ื“ืขื” ืคึฟืึทืจ ืึทื ื˜ืคึผืœืขืงื•ื ื’, ืึธื‘ืขืจ ืึท ื–ื™ื›ืขืจื”ื™ื™ื˜ืก-ืคืึธืจืฉืขืจ ืื™ื– ื’ืขื•ื•ืขืŸ ื‘ื™ื›ื•ืœืช ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ื“ื™ ืฉื•ื•ืึทื›ืงื™ื™ื˜, ื‘ืึทื–ื™ืจื˜ ืื•ื™ืฃ ืึท ืคึฟืึธืจื’ืขืœื™ื™ื’ื˜ืŸ ืงืขืจื ืขืœ-ืคึผืึทื˜ืฉ, ื•ื•ืึธืก ื”ืึธื˜ ื“ืขืจืžืขื’ืœืขื›ื˜ ื“ืึธืก ืœื™ื™ืขื ืขืŸ ืคึฟื•ืŸ ื˜ืขืงืขืก ื•ื•ืึธืก ื–ืขื ืขืŸ ืฆื•ื˜ืจื™ื˜ืœืขืš ื ืึธืจ ืคึฟืึทืจืŸ ื•ื•ืึธืจืฆืœ-ื‘ืึทื ื™ืฆืขืจ, ื•ื•ื™ /etc/shadow. ื“ื™ ืงืขืจื ืขืœ-ืขื ื“ืขืจื•ื ื’ ื”ืึธื˜ ืฆื•ื’ืขืคึผืึทืกื˜ ื“ื™ ืœืึธื’ื™ืง ืคึฟืึทืจ ื ื•ืฆืŸ ื“ื™ get_dumpable() ืคึฟื•ื ืงืฆื™ืข ืื™ืŸ ptrace ื•ื•ืขืŸ ืžืขืŸ ื‘ืึทืฉื˜ื™ืžื˜ ืฆื•ื˜ืจื™ื˜-ืœืขื•ื•ืขืœืก ืื™ืŸ ื“ืขืจ ptrace_may_access() ืคึฟื•ื ืงืฆื™ืข.

ื“ื™ ืฉื•ื•ืึทื›ืงื™ื™ื˜ ื•ื•ืขืจื˜ ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืึท ืจืึทืกืข ืฆื•ืฉื˜ืึทื ื“ ื•ื•ืึธืก ืขืจืœื•ื™ื‘ื˜ ื ื™ืฉื˜-ืคึผืจื™ื•ื•ื™ืœืขื’ื™ืจื˜ืŸ ืฆื•ื˜ืจื™ื˜ ืฆื•ื pidfd ื˜ืขืงืข ื“ืขืกืงืจื™ืคึผื˜ืึธืจ ื ืึธืš ืฆื•ื˜ืจื™ื˜ ืฆื• ืึท ื˜ืขืงืข ืคึฟื•ืŸ ืึท suid ื•ื•ืึธืจืฆืœ ืคึผืจืึธืฆืขืก. ืฆื•ื•ื™ืฉืŸ ืขืคึฟืขื ืขืŸ ื“ืขื ื˜ืขืงืข ืื•ืŸ ืฆื•ืจื™ืงืฉื˜ืขืœืŸ ืคึผืจื™ื•ื•ื™ืœืขื’ื™ืขืก ืื™ืŸ ื“ืขื suid ืคึผืจืึธื’ืจืึทื (ืœืžืฉืœ, ื“ื•ืจืš ื“ื™ setreuid ืคึฟื•ื ืงืฆื™ืข), ืขื ื˜ืฉื˜ื™ื™ื˜ ืึท ืกื™ื˜ื•ืึทืฆื™ืข ื•ื•ืื• ืึทืŸ ืึทืคึผืœื™ืงืึทืฆื™ืข ื•ื•ืึธืก ืœื•ื™ืคึฟื˜ ื“ืขื suid ื•ื•ืึธืจืฆืœ ืคึผืจืึธื’ืจืึทื ืงืขืŸ ืฆื•ื˜ืจื™ื˜ืŸ ืึท ื˜ืขืงืข ื’ืขืขืคึฟื ื˜ ื“ื•ืจืš ื“ืขื suid ืคึผืจืึธื’ืจืึทื ื“ื•ืจืš ื“ืขื pidfd ื“ืขืกืงืจื™ืคึผื˜ืึธืจ, ืืคื™ืœื• ืื•ื™ื‘ ื“ื™ ื˜ืขืงืข'ืก ืคึผืขืจืžื™ืฉืึทื ื– ื“ืขืจืœื•ื™ื‘ืŸ ืขืก ื ื™ืฉื˜.

ื“ื™ ืื•ื™ืกื ื™ืฆื‘ืืจืข ืคืขื ืฆื˜ืขืจ ืขื ื˜ืฉื˜ื™ื™ื˜ ื•ื•ื™ื™ืœ ื“ื™ "__ptrace_may_access()" ืคื•ื ืงืฆื™ืข ืœืื–ื˜ ืื•ื™ืก ืงืื ื˜ืจืืœื™ืจืŸ ืคืืจ ืคื™ื™ืœ ืฆื•ื˜ืจื™ื˜ ืื•ื™ื‘ ื“ืืก task->mm ืคืขืœื“ ืื™ื– ื’ืขืฉื˜ืขืœื˜ ืฆื• NULL ื ืืš exit_mm() ืื‘ืขืจ ืคืืจ exit_files() ื•ื•ืขืจื˜ ื’ืขืจื•ืคืŸ. ืื™ืฆื˜, ื ืขืžื˜ ื“ืขืจ pidfd_getfd ืกื™ืกื˜ืขื ืจื•ืฃ ืืŸ ืื– ื“ืขืจ ืจื•ืคึฟื ื“ื™ืงืขืจ ืคึผืจืึธืฆืขืก'ืก ื‘ืึทื ื™ืฆืขืจ ID (uid) ืคึผืึทืกื˜ ืฆื• ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ID ื•ื•ืึธืก ืื™ื– ื‘ืืจืขื›ื˜ื™ื’ื˜ ืฆื• ืฆื•ื˜ืจื™ื˜ืŸ ื“ื™ ืคื™ื™ืœ. ืขืก ืื™ื– ื•ื•ืขืจื˜ ืฆื• ื‘ืึทืžืขืจืงืŸ ืึทื– ื“ืึธืก ืคึผืจืึธื‘ืœืขื ืื™ื– ืคืจื™ืขืจ ืึทื“ืจืขืกื™ืจื˜ ื’ืขื•ื•ืึธืจืŸ ืื™ืŸ 2020, ืึธื‘ืขืจ ืขืก ื‘ืœื™ื™ื‘ื˜ ื ื™ืฉื˜ ืคืึทืจืจื™ื›ื˜.

ืื™ืŸ ื“ืขื ืขืงืกืคึผืœื•ื™ื˜ ื•ื•ืึธืก ื‘ืึทืงื•ืžื˜ ื“ืขื ืื™ื ื”ืึทืœื˜ ืคึฟื•ืŸ /etc/shadow, ื‘ืึทืฉื˜ื™ื™ื˜ ื“ื™ ืึทื˜ืึทืงืข ืคึฟื•ืŸ ืื™ื‘ืขืจื—ื–ืจืŸ ืœืึธื ื˜ืฉื™ื ื’ ื“ื™ /usr/bin/chage ืึทืคึผืœื™ืงืึทืฆื™ืข ื“ื•ืจืš fork+execl ืžื™ื˜ืŸ suid root ืคึฟืึธืŸ, ื•ื•ืึธืก ืœื™ื™ืขื ื˜ ื“ืขื ืื™ื ื”ืึทืœื˜ ืคึฟื•ืŸ /etc/shadow. ื ืึธื›ื“ืขื ื•ื•ื™ ื“ืขืจ ืคึผืจืึธืฆืขืก ืคึฟืึธืจืงื˜ ื–ื™ืš, ื•ื•ืขืจื˜ ื“ืขืจ pidfd_open ืกื™ืกื˜ืขื ืจื•ืฃ ืขืงืกืขืงื•ื˜ื™ืจื˜, ืื•ืŸ ืึท ืฉืœื™ื™ืฃ ืคึฟื•ืŸ ืคึฟืึทืจืึทืŸ pidfd ื“ืขืกืงืจื™ืคึผื˜ืึธืจืŸ ื•ื•ืขืจื˜ ื“ื•ืจื›ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ื“ืขื pidfd_getfd ืกื™ืกื˜ืขื ืจื•ืฃ ืื•ืŸ ื–ื™ื™ืขืจ ื•ื•ืขืจื™ืคึฟื™ืงืึทืฆื™ืข ื“ื•ืจืš /proc/self/fd. ืื™ืŸ ื“ืขื sshkeysign_pwn ืขืงืกืคึผืœื•ื™ื˜, ื•ื•ืขืจืŸ ืขื ืœืขื›ืข ืžืึทื ื™ืคึผื•ืœืึทืฆื™ืขืก ื“ื•ืจื›ื’ืขืคึฟื™ืจื˜ ืžื™ื˜ืŸ suid root ssh-keysign ืคึผืจืึธื’ืจืึทื.

ื“ื™ ืคืจืื‘ืœืขื ืื™ื– ื ืื›ื ื™ืฉื˜ ืฆื•ื’ืขื˜ื™ื™ืœื˜ ื’ืขื•ื•ืืจืŸ ืงื™ื™ืŸ CVE ืื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืขืจ, ืื•ืŸ ืงืขืจื ืขืœ ืื•ืŸ ืคืขืงืœ ืืคื“ืขื™ื˜ืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ืืจื•ื™ืกื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืืจืŸ ืื™ืŸ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื–. ื“ื™ ืฉื•ื•ืื›ืงื™ื™ื˜ ื‘ืœื™ื™ื‘ื˜ ื ื™ืฉื˜ ื’ืขืคืขื˜ืฉื˜ ืื™ืŸ ืงืขืจื ืขืœืก 7.0.7, 6.18.30, ืื•ืŸ 6.12.88, ืืจื•ื™ืกื’ืขื’ืขื‘ืŸ ืžื™ื˜ ื ืคืืจ ืฉืขื” ืฆื•ืจื™ืง. ืื™ืŸ ื“ืขืจ ืฆื™ื™ื˜ ืคื•ืŸ ืฉืจื™ื™ื‘ืŸ, ืงืขืŸ ื ืืจ ื“ืขืจ ืคืขื˜ืฉ ื’ืขื ื•ืฆื˜ ื•ื•ืขืจืŸ. ืžืขื’ืœืขื›ืข ืืจื•ืžื’ื™ื™ืŸ ื•ื•ืขืจืŸ ื“ื™ืกืงื•ื˜ื™ืจื˜, ื•ื•ื™ ืœืžืฉืœ ืฉื˜ืขืœืŸ sysctl kernel.yama.ptrace_scope=3 ืื“ืขืจ ืืจืืคื ืขืžืขืŸ ื“ืขื suid root ืคืืŸ ืคื•ืŸ ืขืงืกืขืงื™ื•ื˜ืขื‘ืœืก ืื™ืŸ ืกื™ืกื˜ืขื (ืœืคื—ื•ืช ืคื•ืŸ ื“ื™ ssh-keysign ืื•ืŸ change ื™ื•ื˜ื™ืœื™ื˜ื™ืก ื’ืขื ื•ืฆื˜ ืื™ืŸ ืขืงืกืคืœื•ื™ื˜ืก).

ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’: ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืฆื•ื’ืขื˜ื™ื™ืœื˜ ื’ืขื•ื•ืึธืจืŸ ืžื™ื˜ืŸ ืื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืขืจ CVE-2026-46333. ืงืขืจื ืขืœ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ื–ืขื ืขืŸ ื’ืขื ืขืจื™ืจื˜ ื’ืขื•ื•ืึธืจืŸ. Linux 7.0.8, 6.18.31, 6.12.89, 6.6.139, 6.1.173, 5.15.207, ืื•ืŸ 5.10.256 ืžื™ื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืคื™ืงืกื™ื–. ื“ืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืคื™ืงืกื™ื– ืกื˜ืึทื˜ื•ืก ืคึฟืึทืจ ื“ื™ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– ืงืขืŸ ื–ื™ื™ืŸ ืึทืกืกืขืกืกืขื“ ืื•ื™ืฃ ื“ื™ ื‘ืœืขื˜ืขืจ: Debian, Ubuntu, SUSE/openSUSE, RHEL, ื“ื–ืฉืขื ื˜ื•, ืึทืจื˜ืฉ, ืคืขื“ืึธืจืึท.

ืžืงื•ืจ: opennet.ru

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster