7 ื ื™ื™ืข ืฉื•ื•ืึทื›ืงื™ื™ื˜ืŸ ืื™ืŸ FreeBSD

ื“ืขื 20ืกื˜ืŸ ืžืื™, 2026, ื”ืื‘ืŸ FreeBSD ื“ืขื•ื•ืขืœืึธืคึผืขืจืก ื’ืขืžืืœื“ืŸ ืคึผืึทื˜ืฉืึทื– ืคึฟืึทืจ ื–ื™ื‘ืŸ ื ื™ื™ืข ืฉื•ื•ืึทื›ืงื™ื™ื˜ืŸ ืื™ืŸ ื“ืขืจ ืกื™ืกื˜ืขื. ื ื™ืฉื˜ ืึทืœืข ืคื•ืŸ โ€‹โ€‹ื–ื™ื™ ื–ืขื ืขืŸ ื’ืœื™ื™ืš ื’ืขืคืขืจืœืขืš, ืึธื‘ืขืจ ืขื˜ืœืขื›ืข ื–ืขื ืขืŸ ื’ืึธืจ ืฉืœืขื›ื˜.

CVE-2026-45251 โ€” ื ื™ืฆืŸ-ื ืืš-ืคืจื™ื™ ืื™ืŸ ืกืขืœืขืงื˜-ืขื ืœืขื›ืข ืกื™ืกืงืืœืก ืื•ื™ื‘ ื–ื™ื™ืขืจ ื•ื•ืืจื˜-ืœื™ืกื˜ืข ืื ื˜ื”ืืœื˜ ืคืจืืฆืขืก ื“ืขืกืงืจื™ืคึผื˜ืืจืŸ (ืื™ืŸ FreeBSD 15, ื–ืขื ืขืŸ ืื•ื™ืš ื“ื ื ื™ื™ืข ื“ื–ืฉื™ื™ืœ ื“ืขืกืงืจื™ืคึผื˜ืืจืŸ), ืื•ืŸ ื“ื™ ื“ืขืกืงืจื™ืคึผื˜ืืจืŸ ื–ืขื ืขืŸ ืคืืจืžืื›ื˜ ื’ืขื•ื•ืืจืŸ ืื™ืŸ ืืŸ ืื ื“ืขืจ ืืฉื›ื•ืœ ื‘ืฉืขืช ื“ืขืจ ื•ื•ืืจื˜ื ื“ื™ืงืขืจ ืกื™ืกืงืืœ ื”ืื˜ ื ืืš ื’ืขื•ื•ืืจื˜. ืื•ื™ื‘ ืžืขืŸ ืžืฉืคื˜'ื˜ ืœื•ื™ื˜ ื“ื™ ื“ืื–ื™ื’ืข ืงืืžื™ื˜ื“ืขืกืงืจื™ืคึผื˜ืึธืจืŸ ืฉื™ื™ืš ืฆื• ื ืขื˜ืžืึทืคึผ (ื“ืขืจ ื ืขืฅ ืึทื“ืึทืคึผื˜ืขืจ ื“ืจื™ื™ื•ื•ืขืจ ืคึฟืึทืจ ืึทืงืกืขืœืขืจื™ืจื˜ ื“ื™ืจืขืงื˜ ืึทืงืกืขืก) ื–ืขื ืขืŸ ืื•ื™ืš ืึทืคืขืงื˜ื™ืจื˜, ืึธื‘ืขืจ ืขืก ืื™ื– ื ื™ืฉื˜ืึธ ืงื™ื™ืŸ ืืคื™ืฆื™ืขืœืข ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ืขื. ืคึผืจืึธืฆืขืก ื“ืขืกืงืจื™ืคึผื˜ืึธืจืŸ ื–ืขื ืขืŸ ืื™ื™ื ื’ืขืคื™ืจื˜ ื’ืขื•ื•ืึธืจืŸ ืื™ืŸ FreeBSD 9, ืึทื–ื•ื™ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืขืงื–ื™ืกื˜ื™ืจื˜ ืžืกืชึผืžื ื–ื™ื ื˜ ื“ืขืžืึธืœื˜. ื“ื™ ืืคื™ืฆื™ืขืœืข ื“ืขืจืงืœืขืจื•ื ื’ ื–ืึธื’ื˜ ืึทื– ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ื“ืขืจืžืขื’ืœืขื›ื˜ ืกื•ืคึผืขืจื™ื•ื–ืขืจ ืคึผืจื™ื•ื•ื™ืœืขื’ื™ืขืก ืฆื• ื•ื•ืขืจืŸ ื‘ืึทืงื•ืžืขืŸ. ืขืก ืื™ื– ื ื™ืฉื˜ืึธ ืงื™ื™ืŸ ื•ื•ืขื’ ืฆื• ืคึฟืึทืจืžื™ื ื“ืขืจืŸ ืขืก ืึธืŸ ืึท ืคึผืึทื˜ืฉ ืึธื“ืขืจ ืึทืคึผื“ื™ื™ื˜.

CVE-2026-45250 โ€” ื ืื•ืžืจื™ื›ื˜ื™ื’ืข ื‘ืึทืคืขืจ ื’ืจื™ื™ืก ืงืึทืœืงื•ืœืึทืฆื™ืข ืื•ืŸ ื“ืขืจื ืืš ืกื˜ืขืง ืฉืจื™ื™ื‘ืŸ ืื™ืŸ ื“ืขื setcred ืกื™ืกื˜ืขื ืจื•ืฃ. ื›ืึธื˜ืฉ setcred ืึทืœื™ื™ืŸ ืคืืจืœืื ื’ื˜ ืจื•ื˜ ืคึผืจื™ื•ื•ื™ืœืขื’ื™ืขืก, ืคึผืึทืกื™ืจื˜ ื“ื™ ืกื˜ืขืง ืงืึธืจื•ืคึผืฆื™ืข ืื™ื™ื“ืขืจ ื“ื™ ืคึผืจื™ื•ื•ื™ืœืขื’ื™ืขืก ื•ื•ืขืจืŸ ืึธืคึผื’ืขืฉื˜ืขืœื˜ ืื•ืŸ ืื™ื– ื“ืขืจื™ื‘ืขืจ ืฆื•ื˜ืจื™ื˜ืœืขืš ืคึฟืึทืจ ืึทืœืขืžืขืŸ. ื“ืขืจ ืกื™ืกื˜ืขื ืจื•ืฃ ืื™ื– ื’ืขื•ื•ืขืŸ ืื™ื™ื ื’ืขืคื™ืจื˜ ืื™ืŸ FreeBSD 14.3 (ื•ื•ืึธืก ืžื™ื™ื ื˜ ืึทื– ืคืจื™ืขืจื“ื™ืงืข ื•ื•ืขืจืกื™ืขืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ืึทืคืขืงื˜ื™ืจื˜) ืื•ืŸ ื’ื™ื˜ ืึท ื•ื•ืขื’ ืฆื• ืฉื˜ืขืœืŸ ืึทืœืข ื‘ืึทื ื™ืฆืขืจ ืื•ืŸ ื’ืจื•ืคึผืข IDs ืคื•ืŸ ื“ืขื ืื™ืฆื˜ื™ืงืŸ ืคึผืจืึธืฆืขืก ืื™ืŸ ืื™ื™ืŸ ืจื•ืฃ, ืึทื ืฉื˜ืึธื˜ ืฆื• ื ื•ืฆืŸ setuid+setgid+setgroups ืื•ืŸ ืขื ืœืขื›ืข ืงืึธืžื‘ื™ื ืึทืฆื™ืขืก. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืขืจืœื•ื™ื‘ื˜ ื‘ื™ื™ื–ื•ื•ื™ืœื™ืงืข ืงืึธื“ ืฆื• ื•ื•ืขืจืŸ ืขืงืกืขืงื•ื˜ื™ืจื˜ ืื™ืŸ ื“ืขื ืงืขืจื ืขืœ ืงืึธื ื˜ืขืงืกื˜. ืขืก ืื™ื– ื ื™ืฉื˜ืึธ ืงื™ื™ืŸ ื•ื•ืขื’ ืฆื• ืคึฟืึทืจืžื™ื ื“ืขืจืŸ ืขืก ืึธืŸ ืึท ืคึผืึทื˜ืฉ ืึธื“ืขืจ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’.

CVE-2026-45252 โ€” ืงื™ื™ืŸ ืงืึธื ื˜ืจืึธืœ ืคึฟืึทืจ ืึท ื˜ืขืจืžื™ื ื™ืจื ื“ื™ืงืŸ ื ื•ืœ ืื™ื™ื“ืขืจ ืงืึธืคึผื™ืจืŸ ืึท ืกื˜ืจื™ื ื’ ื‘ืึทืงื•ืžืขืŸ ืคึฟื•ืŸ ื“ืขื ืคึฟื™ื•ื– ื“ืึทืขืžืึธืŸ ืฆื• ืึท ื ื™ื™ืขื ื‘ืึทืคึฟืขืจ. ืึธื‘ืขืจ, ืขืก ืื™ื– ื“ืึธ ืึท ืงืึธื ื˜ืจืึธืœ ืคึฟืึทืจ ื“ื™ ืžืึทืงืกื™ืžื•ื ืงืึธืคึผื™ืข ื’ืจื™ื™ืก, ืื•ืŸ ืขืก ืื™ื– ืื•ืžืžืขื’ืœืขืš ืฆื• ืœื™ื™ืขื ืขืŸ ืžืขืจ ื•ื•ื™ 253 ืขืงืกื˜ืจืข ื‘ื™ื™ื˜ืก ืคึฟื•ืŸ ืงืขืจื ืขืœ ื–ื›ึผืจื•ืŸ. ืขืก ืื™ื– ืื•ื™ืš ืžืขื’ืœืขืš ืฆื• ืฉืจื™ื™ึทื‘ืŸ ื‘ื™ื– 250 ื‘ื™ื™ื˜ืก ืฆื• "ื ื™ืฉื˜-ืึทืœืึธืงื™ืจื˜ ืงืขืจื ืขืœ ื”ื™ืคึผ ืคึผืœืึทืฅ." ื“ื•ืจืš ื“ื™ืคืึธืœื˜, ืคึฟืึทืจื”ื™ื˜ FreeBSD ื ื™ืฉื˜-ืจื•ื˜ ื‘ืึทื ื™ืฆืขืจ ืคึฟื•ืŸ ืžืึธื•ื ื˜ืŸ ืคึฟื™ื™ืœ-ืกื™ืกื˜ืขืžืขืŸ, ื•ื•ืึธืก ืžื™ื™ื ื˜ ืึทื– ืื™ื ืกื˜ืึทืœื™ืจืŸ ืึท ื‘ื™ื™ื–ื•ื•ื™ืœื™ืงืŸ ืคึฟื™ื•ื– ื“ืึทืขืžืึธืŸ ืื™ืŸ ื“ืขื ืงืขืจื ืขืœ ื“ืึทืจืฃ ืจื•ื˜ ืึทืงืกืขืก. ืึธื‘ืขืจ, ืื•ื™ื‘ sysctl vfs.usermount=1, ื•ื•ืขืจื˜ ื“ื™ ืกื™ืกื˜ืขื ืื•ื™ืš ืคึฟืึทืจื•ื•ืื•ื ื“ืœืขืš ืคึฟืึทืจ ืจืขื’ื•ืœืขืจืข ื‘ืึทื ื™ืฆืขืจ. ืขืก ืื™ื– ืื•ื™ืš ื•ื•ืขืจื˜ ืฆื• ื‘ืึทื˜ืจืึทื›ื˜ืŸ ื“ื™ ื’ืขืคึฟืึทืจ ืคึฟื•ืŸ ื“ืขื ืคึฟื™ื•ื– ื“ืึทืขืžืึธืŸ ืื™ืŸ ื“ื–ืฉืึทื™ืœ, ื•ื•ื•ึผ ืขืก ืงืขืŸ ื–ื™ื™ืŸ ืจื•ื˜ (ื›ืึธื˜ืฉ ื“ืึธืก ืื™ื– ืื•ื™ืš ืคึฟืึทืจื•ื•ืขืจื˜ ื“ื•ืจืš ื“ื™ืคืึธืœื˜).

CVE-2026-45253 โ€” ื•ื•ืขืŸ ืžืขืŸ ื ื™ืฆื˜ ptrace, ืื™ื– ื’ืขื•ื•ืขืŸ ืžืขื’ืœืขืš ืฆื• ืœืึธื ื˜ืฉืŸ ืึท ืกื™ืกื˜ืขื ืจื•ืฃ ืžื™ื˜ ืึท ืคืึทืœืฉ ื ื•ืžืขืจ ืื™ืŸ ืึท ื“ื™ื‘ืึทื’ื“ ืคึผืจืึธืฆืขืก, ื•ื•ืึธืก ื”ืึธื˜ ื’ืขืคึฟื™ืจื˜ ืฆื• ื“ืขืจ ืื•ื™ืกืคึฟื™ืจื•ื ื’ ืคึฟื•ืŸ ืงืขืจื ืขืœ ืงืึธื“ ื•ื•ืึธืก ืื™ื– ื ื™ืฉื˜ ื’ืขืžื™ื™ื ื˜ ืฆื• ื•ื•ืขืจืŸ ืื•ื™ืกืคึฟื™ืจื˜ ื•ื•ื™ ืึท ืกื™ืกื˜ืขื ืจื•ืฃ, ืžื™ื˜ ืคึผืึธื˜ืขื ืฆื™ืขืœ ืงืึทื˜ืึทืกื˜ืจืึธืคึฟืึทืœืข ืงืึทื ืกืึทืงื•ื•ืขื ืฆืŸ. ืื•ื™ื‘ security.bsd.unprivileged_proc_debug=0 ืื™ื– ื’ืขืฉื˜ืขืœื˜ (ื•ื•ืึธืก ืื™ื– ื’ื•ื˜ืข ืคึผืจืึทืงื˜ื™ืง ืคึฟืึทืจ ืกืขืจื•ื•ืขืจืก ืกื™ื™ึท ื•ื•ื™ ืกื™ื™ึท, ืื•ืŸ ื“ืขืจ ืกื™ืกื˜ืขื ืื™ื ืกื˜ืึทืœืœืขืจ ืึธืคืคืขืจื˜ ืืคื™ืœื• ื“ื™ ืึธืคึผืฆื™ืข), ื•ื•ืขืœืŸ ื‘ืึทื ื™ืฆืขืจ ืื•ืŸ ื“ื–ืฉื™ื™ื–ื“ ืคึผืจืึธืฆืขืกืŸ ื ื™ืฉื˜ ืงืขื ืขืŸ ื ื™ืฆืŸ ptrace, ืœืึธื–ื ื“ื™ืง ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืฆื•ื˜ืจื™ื˜ืœืขืš ื‘ืœื•ื™ื– ืคึฟืึทืจ ืจื•ื˜.

CVE-2026-45255 โ€” ืืจื™ื™ื ืฉืคึผืจื™ืฆืŸ ืฉืึธืœ ืงืึธืžืึทื ื“ืขืก ืžื™ื˜ ืจื•ื˜ ืคึผืจื™ื•ื•ื™ืœืขื’ื™ืขืก ืื™ืŸ bsdinstall/bsdconfig ื“ื•ืจืš ื“ื™ ื ืขืžืขืŸ ืคื•ืŸ ื‘ื™ื™ื–ื•ื•ื™ืœื™ืงืข ื•ื•ื™ื™ืจืœืขืก ื ืขื˜ื•ื•ืึธืจืงืก ื•ื•ืึธืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ื’ืขืคึผืจื™ืคื˜ ื’ืขื•ื•ืึธืจืŸ ื•ื•ืขืŸ ืžืขืŸ ื”ืึธื˜ ื’ืขืงื•ืงื˜ ืื•ื™ืฃ ื–ื™ื™ืขืจ ืœื™ืกื˜ืข. ื›ึผื“ื™ ืฆื• ืคึฟืึทืจืžื™ื™ึทื“ืŸ ื“ื™ ืฉื•ื•ืึทื›ืงื™ื™ื˜, ื–ืึธืœื˜ ืื™ืจ ืคืฉื•ื˜ ื ื™ืฉื˜ ืงื•ืงืŸ ืื•ื™ืฃ ื“ื™ ื•ื•ื™ื™ืจืœืขืก ื ืขื˜ื•ื•ืึธืจืง ืœื™ืกื˜ืข ืคึฟื•ืŸ bsdinstall/bsdconfig.

CVE-2026-39461, CVE-2026-45254 โ€” ืฉื•ื•ืึทื›ืงื™ื™ื˜ืŸ ืื™ืŸ ื“ืขืจ ืœื™ื‘ืงืึทืกืคึผืขืจ ื‘ื™ื‘ืœื™ืึธื˜ืขืง (ื ื™ืฉื˜ ืื™ืŸ ืงืขืจื ืขืœ). ื“ื™ ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืื™ื– ื“ื™ื–ื™ื™ื ื“ ืคึฟืึทืจ ื–ื™ื›ืขืจืข, ืงืึธื ืคื™ื’ื•ืจืึทื‘ืœืข ืคึผืจืึธื•ื•ื™ื–ืฉืึทื ื™ื ื’ ืคื•ืŸ ืกืขืจื•ื•ื™ืกืขืก ืฆื• ืกืึทื ื“ื‘ืึธืงืกืขื“ ืคึผืจืึธืฆืขืกืŸ. ืื™ื™ืŸ ืฉื•ื•ืึทื›ืงื™ื™ื˜ ืื™ื– ืคึฟืึทืจื‘ื•ื ื“ืŸ ืžื™ื˜ ืึท ืกื˜ืขืง ืึธื•ื•ื•ืขืจืคืœืึธื• ืื•ืŸ ืกื˜ืขืง ืงืึธืจื•ืคึผืฆื™ืข ืจืขื›ื˜ ืฆื• ื“ืขืจ ื‘ื™ื‘ืœื™ืึธื˜ืขืง'ืก ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื’ืจื•ื™ืกืข ื˜ืขืงืข ื“ืขืกืงืจื™ืคึผื˜ืึธืจ ื ื•ืžืขืจืŸ (ืขืก ืื™ื– ื“ื™ื–ื™ื™ื ื“ ืคึฟืึทืจ ื ื•ืžืขืจืŸ ื‘ื™ื– 1024, ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืœื™ืžื™ื˜ ืคึฟืึทืจ ืกื˜ืจื•ืงื˜ื•ืจืŸ ืคึฟืึทืจ ื“ื™ ืกืขืœืขืงื˜ ืกื™ืกืงืึธืœืœ). ื“ื™ ืฆื•ื•ื™ื™ื˜ืข ืฉื•ื•ืึทื›ืงื™ื™ื˜ ืื™ื– ื“ื™ ืžืขื’ืœืขื›ืงื™ื™ื˜ ืฆื• ื‘ืึทื–ื™ื™ึทื˜ื™ืงืŸ ื™ืžืคึผืึธื•ื–ื“ ืœื™ืกื˜ืขืก ืคื•ืŸ ืจื™ืกื˜ืจื™ืงืฉืึทื ื– (ื“ื™ ื‘ื™ื‘ืœื™ืึธื˜ืขืง'ืก ืคื™ืœืึธืกืึธืคึฟื™ืข ืื™ื– ืึทื– ืจื™ืกื˜ืจื™ืงืฉืึทื ื– ืึทืžืึธืœ ื™ืžืคึผืึธื•ื–ื“ ืื•ื™ืฃ ืึท ืคึผืจืึธืฆืขืก ืงืขื ืขืŸ ื ืึธืจ ื•ื•ืขืจืŸ ืฉื˜ืึทืจืงืขืจ) cap_net.

ื“ื™ ืคึผืึทื˜ืฉื˜ ื•ื•ืขืจืกื™ืขืก ืคื•ืŸ ื“ื™ ืกื™ืกื˜ืขื ื–ืขื ืขืŸ ื ื•ืžืขืจื™ืจื˜: 14.3-RELEASE-p14, 14.4-RELEASE-p5, ืื•ืŸ 15.0-RELEASE-p9. ืขืก ืื™ื– ืื•ื™ืš ื•ื•ืขืจื˜ ืฆื• ื‘ืึทืžืขืจืงืŸ ืึท ื•ื•ื™ื›ื˜ื™ืงืŸ ืคึผื•ื ืงื˜ ืคึฟืึทืจ ืขื˜ืœืขื›ืข: FreeBSD 13.5 ืื™ื– ืœืขืฆื˜ื ืก ืึธืคึผื’ืขืฉื˜ืขืœื˜ ื’ืขื•ื•ืึธืจืŸ - 30ืกื˜ืŸ ืึทืคึผืจื™ืœ, 2026 - ืื•ืŸ ืขืก ื–ืขื ืขืŸ ื ื™ืฉื˜ืึธ ืงื™ื™ืŸ ืึธืคึฟื™ืฆื™ืขืœืข ืคึฟื™ืงืกืขืก ื“ืขืจืคึฟืึทืจ (ืึธื“ืขืจ ืคึฟืึทืจ ื“ื™ 13.x ืฆื•ื•ื™ื™ึทื’ ื‘ื›ืœืœ). ืึธื‘ืขืจ, ืื•ื™ื‘ ืคึฟืึทืจ ืขืคืขืก ืึท ืกื™ื‘ื” ื•ื•ื™ืœื˜ ืื™ืจ ื ื™ืฉื˜ ื–ื™ืš ื™ืึธื’ืŸ ืฆื• ืึทืคึผื’ืจืขื™ื“ืŸ ืฆื• ื“ื™ 14.x ื•ื•ืขืจืกื™ืข, ื“ื™ ืคึผืึทื˜ืฉืขืก ืคึฟืึทืจ 14.3 ื’ื™ืœื˜ืŸ ื‘ื›ืœืœ ืคึฟืึทืจ ื“ื™ 13.5 ืงื•ื•ืึทืœ ืงืึธื“, ืื•ืŸ CVE-2026-45250 ืื™ื– ื ื™ืฉื˜ ื‘ืึทื˜ื™ื™ึทื˜ื™ืง ืคึฟืึทืจ ื“ื™ 13.x ืฆื•ื•ื™ื™ึทื’ ืฆื•ืœื™ื‘ ื“ืขื ืžืึทื ื’ืœ ืคึฟื•ืŸ setcred().

ืžืงื•ืจ: linux.org.ru

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster