{"id":33314,"date":"2022-03-14T10:03:45","date_gmt":"2022-03-14T12:03:45","guid":{"rendered":"https:\/\/teknomers.com\/fr\/un-nouveau-bogue-linux-dans-le-module-de-pare-feu-netfilter-permet-aux-attaquants-dobtenir-un-acces-root\/"},"modified":"2022-03-14T10:03:56","modified_gmt":"2022-03-14T12:03:56","slug":"un-nouveau-bogue-linux-dans-le-module-de-pare-feu-netfilter-permet-aux-attaquants-dobtenir-un-acces-root","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/un-nouveau-bogue-linux-dans-le-module-de-pare-feu-netfilter-permet-aux-attaquants-dobtenir-un-acces-root\/","title":{"rendered":"Un nouveau bogue Linux dans le module de pare-feu Netfilter permet aux attaquants d&#8217;obtenir un acc\u00e8s root"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Une faille de s\u00e9curit\u00e9 r\u00e9cemment r\u00e9v\u00e9l\u00e9e dans le noyau Linux pourrait \u00eatre exploit\u00e9e par un adversaire local pour obtenir des privil\u00e8ges \u00e9lev\u00e9s sur des syst\u00e8mes vuln\u00e9rables afin d&#8217;ex\u00e9cuter du code arbitraire, d&#8217;\u00e9chapper \u00e0 des conteneurs ou d&#8217;induire un <a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Kernel_panic\" target=\"_blank\">panique du noyau<\/a>.<\/p>\n<p>Suivi comme <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-25636\" target=\"_blank\">CVE-2022-25636<\/a> (score CVSS\u00a0: 7,8), la vuln\u00e9rabilit\u00e9 affecte les versions 5.4 \u00e0 5.6.10 du noyau Linux et r\u00e9sulte d&#8217;une \u00e9criture hors limites du tas dans le sous-composant netfilter du noyau.  Le probl\u00e8me \u00e9tait <a rel=\"nofollow noopener\" href=\"https:\/\/nickgregory.me\/linux\/security\/2022\/03\/12\/cve-2022-25636\/\" target=\"_blank\">d\u00e9couvert<\/a> par Nick Gregory, chercheur scientifique chez Capsule8.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/backhub-dm1\" target=\"_blank\" title=\"Automatic GitHub Backups\"><img loading=\"lazy\" decoding=\"async\" alt=\"Sauvegardes GitHub automatiques\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1646124018_583_Le-logiciel-malveillant-Daxin-lie-a-la-Chine-a-cible.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>&#8220;Cette faille permet \u00e0 un attaquant local disposant d&#8217;un compte utilisateur sur le syst\u00e8me d&#8217;acc\u00e9der \u00e0 la m\u00e9moire hors limites, entra\u00eenant un plantage du syst\u00e8me ou une menace d&#8217;\u00e9l\u00e9vation des privil\u00e8ges&#8221;, Red Hat <a rel=\"nofollow noopener\" href=\"https:\/\/access.redhat.com\/security\/cve\/CVE-2022-25636\" target=\"_blank\">mentionn\u00e9<\/a> dans un avis publi\u00e9 le 22 f\u00e9vrier 2022. Des alertes similaires ont \u00e9t\u00e9 publi\u00e9es par <a rel=\"nofollow noopener\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2022-25636\" target=\"_blank\">DebianName<\/a>, <a rel=\"nofollow noopener\" href=\"https:\/\/linux.oracle.com\/cve\/CVE-2022-25636.html\" target=\"_blank\">OracleLinux<\/a>, <a rel=\"nofollow noopener\" href=\"https:\/\/www.suse.com\/security\/cve\/CVE-2022-25636.html\" target=\"_blank\">SUSE<\/a>et <a rel=\"nofollow noopener\" href=\"https:\/\/ubuntu.com\/security\/CVE-2022-25636\" target=\"_blank\">Ubuntu<\/a>.<\/p>\n<p>Netfilter est un <a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Netfilter\" target=\"_blank\">cadre<\/a> fourni par le noyau Linux qui permet diverses op\u00e9rations li\u00e9es au r\u00e9seau, notamment le filtrage de paquets, la traduction d&#8217;adresses r\u00e9seau et la traduction de ports.<\/p>\n<p>Plus pr\u00e9cis\u00e9ment, CVE-2022-25636 concerne un probl\u00e8me de gestion incorrecte du framework <a rel=\"nofollow noopener\" href=\"https:\/\/lwn.net\/Articles\/809333\/\" target=\"_blank\">fonctionnalit\u00e9 de d\u00e9chargement du mat\u00e9riel<\/a> qui pourrait \u00eatre militaris\u00e9 par un attaquant local pour provoquer un d\u00e9ni de service (DoS) ou \u00e9ventuellement ex\u00e9cuter du code arbitraire.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"Prevent Data Breaches\"><img loading=\"lazy\" decoding=\"async\" alt=\"Emp\u00eacher les violations de donn\u00e9es\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1646326908_645_Correctifs-critiques-publies-pour-la-gamme-Cisco-Expressway-les-produits.jpeg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>&#8220;Bien qu&#8217;il s&#8217;agisse d&#8217;un code traitant du d\u00e9chargement mat\u00e9riel, il est accessible lorsque vous ciblez des p\u00e9riph\u00e9riques r\u00e9seau qui n&#8217;ont pas de fonctionnalit\u00e9 de d\u00e9chargement (par exemple, lo) car le bogue est d\u00e9clench\u00e9 avant l&#8217;\u00e9chec de la cr\u00e9ation de la r\u00e8gle.&#8221;  Gr\u00e9gory <a rel=\"nofollow noopener\" href=\"https:\/\/seclists.org\/oss-sec\/2022\/q1\/153\" target=\"_blank\">mentionn\u00e9<\/a>.  &#8220;De plus, alors que nftables n\u00e9cessite CAP_NET_ADMIN, nous pouvons annuler le partage dans un nouvel espace de noms r\u00e9seau pour l&#8217;obtenir en tant qu&#8217;utilisateur (normalement) non privil\u00e9gi\u00e9.&#8221;<\/p>\n<p>&#8220;Cela peut \u00eatre transform\u00e9 en noyau [<a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Return-oriented_programming\" target=\"_blank\">return-oriented programming<\/a>]\/local escalade des privil\u00e8ges sans trop de difficult\u00e9, car l&#8217;une des valeurs \u00e9crites hors limites est commod\u00e9ment un pointeur vers une structure net_device \u00bb, a ajout\u00e9 Gregory.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/03\/new-linux-bug-in-netfilter-firewall.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Une faille de s\u00e9curit\u00e9 r\u00e9cemment r\u00e9v\u00e9l\u00e9e dans le noyau Linux pourrait \u00eatre exploit\u00e9e par un adversaire local pour obtenir des privil\u00e8ges \u00e9lev\u00e9s sur des syst\u00e8mes vuln\u00e9rables afin d&#8217;ex\u00e9cuter du code arbitraire, d&#8217;\u00e9chapper \u00e0 des conteneurs ou d&#8217;induire un panique du noyau. Suivi comme CVE-2022-25636 (score CVSS\u00a0: 7,8), la vuln\u00e9rabilit\u00e9 affecte les versions 5.4 \u00e0 5.6.10 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":33315,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[15283,11865,507,6813,4168,4158,4165,4161,429,25573,4157,4159,4171,4170,18088,4167,4160,10613,26813,680,4163,4162,5467,9701,26814,4172,4169,4166,4164],"class_list":["post-33314","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-acces","tag-attaquants","tag-aux","tag-bogue","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-dans","tag-dobtenir","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-linux","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-module","tag-netfilter","tag-nouveau","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-parefeu","tag-permet","tag-root","tag-securite-informatique","tag-securite-internet","tag-violation-de-donnees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/33314","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=33314"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/33314\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/33315"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=33314"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=33314"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=33314"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}