9.Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

كشفت (كيوليس) عن (سي في سي إف 2026-46333)، عيب تصاعدي للامتيازات في (لينكس كينيل) وتسمح المتفجرات للمستعملين غير الممنوحين بقراءة الملفات الحساسة وتنفيذ الأوامر التعسفية على أنها جذور.

9.Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros
VE-2026-46333، وهو عيب منطقي في شركة لينكس للكرينل (Lenux kernels code. ptrace may -access processing/cocode. function that permits an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major distributions. وأقامت الحشرة في خط لينكس الرئيسي منذ تشرين الثاني/نوفمبر 2016 (v4.10-rc1). ويمكن بالفعل الحصول على المواصفات الأولية والتحديثات المتعلقة بالتوزيع. ويجري تعميم المستغلات في العمل علنا، وينبغي أن يطبق المسؤولون الإداريون تحديثات المبيعات دون تأخير. The vulnerability is a race condition during process exit. The code.do exit Making/code. function runs code.exit mm. يمكن أن تنجح هذه النوافذ عندما يطابق جهاز الاتصال الهدف، مما يسمح لمهاجم أن يلتقط ملفاً مفتوحاً من عملية احتياطية. Tested on Debian 13, Ubuntu 24.04, Ubuntu 26.04, Fedora 43, and Fedora 44./li. Tested on Debian 13, Ubuntu 24.04, and Ubuntu 26.04. /li.法.》p.pkexec/strong. (set-uid-root): executes arbitrary commands as root. Tested on Debian 13, Ubuntu Desktop 24.04 and 26.04, and Fedora Workstation 43 and 44./li. Tested on Debian 13, Fedora Workstation 43, and Fedora Workstation 44. تطبيق تحديث الكينل من توزيعك. ويمكن الحصول على حزم مدفعية من ديبيان وفيدورا وغيرها من البائعين الرئيسيين. Interim mitigation: raise code).kernel.yama.ptrace scope/code). to 2 (admin-only attach). تناوب مفاتيح مضيفة SSH واستعراض وثائق التفويض المموَّلة على المستضيفين المتضررين

Request a scoping call · Penetration testing services