Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | GNU Inetutils telnetd ÇéÐαäÁ¿×¢ÈëÌáȨÎó²î |
CVE ID | CVE-2026-28372 |
Îó²îÀàÐÍ | ȨÏÞÌáÉý | ·¢Ã÷ʱ¼ä | 2026-3-2 |
Îó²îÆÀ·Ö | 7.4 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍâµØ | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | ¸ß | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Telnet ÊÇÒ»ÖÖ»ùÓÚTCPµÄÔ¶³ÌÖÕ¶Ë»á¼ûЧÀÍÓëÓ¦ÓòãÐÒ飬£¬£¬£¬£¬Ä¬ÈÏʹÓÃ23¶Ë¿Ú£¬£¬£¬£¬£¬ÔÊÐíÓû§Í¨¹ýÍøÂçÔÚµ±ÌïÖ÷»úÉÏÔ¶³ÌµÇ¼²¢²Ù×÷Áíһ̨ЧÀÍÆ÷¡£¡£¡£Telnet½ÓÄÉÃ÷ÎÄ·½·¨´«ÊäÓû§Ãû¡¢¿ÚÁî¼°»á»°Êý¾Ý£¬£¬£¬£¬£¬ÔçÆÚÆÕ±éÓÃÓÚÀàUnixϵͳµÄÔ¶³ÌÖÎÀíÓë×°±¸ÔËά¡£¡£¡£ÓÉÓÚȱ·¦¼ÓÃܺÍÍêÕûµÄÉí·Ý±£»£»£»¤»úÖÆ£¬£¬£¬£¬£¬TelnetÈÝÒ×ÔâÊÜÇÔÌý¡¢ÖطźÍÖÐÐÄÈ˹¥»÷£¬£¬£¬£¬£¬Ç徲Σº¦½Ï¸ß¡£¡£¡£Ëæ×ÅÇå¾²ÐèÇóµÄÌáÉý£¬£¬£¬£¬£¬TelnetÒÑÖð²½±»SSHµÈ¼ÓÃÜÔ¶³ÌÖÎÀíÐÒéËùÈ¡´ú£¬£¬£¬£¬£¬Í¨³£½öÔÚÊܿصÄÄÚÍøÇéÐλòÌØÊâ¼æÈݳ¡¾°ÖÐʹÓᣡ£¡£
2026Äê3ÔÂ2ÈÕ£¬£¬£¬£¬£¬°ÙÀÖ²©Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½GNU InetutilsÖÐtelnetd×é¼þ±£´æÇéÐαäÁ¿×¢ÈëÌáȨÎó²î¡£¡£¡£¸ÃÎó²îÔ´ÓÚtelnetd¶Ô¿Í»§¶Ë¿É¿ØÇéÐαäÁ¿£¨ÈçCREDENTIALS_DIRECTORY£©¹ýÂ˲»ÑϿᣬ£¬£¬£¬£¬Î´½ÓÄÉÑÏ¿áµÄ°×Ãûµ¥»úÖÆ¾ÙÐÐÏÞÖÆ¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÉèÖÃCREDENTIALS_DIRECTORY£¬£¬£¬£¬£¬²¢ÔÚ¶ÔӦĿ¼Öн¨Éè°üÀ¨Ìض¨ÄÚÈݵÄlogin.noauthÎļþ£¬£¬£¬£¬£¬ÓÕʹÒÔrootȨÏÞÖ´ÐеÄ/bin/loginÌø¹ýÕý³£Éí·ÝÈÏÖ¤Á÷³Ì£¬£¬£¬£¬£¬×îÖÕ»ñÈ¡rootȨÏÞ¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
GNU Inetutils <= 2.7
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£Debian sid/forky£ºinetutils >= 2:2.7-3Debian trixie (security)£ºinetutils >= 2:2.6-3+deb13u2
3.2 ÔÝʱ²½·¥
½ûÓÃtelnetЧÀÍ¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://lists.gnu.org/archive/html/bug-inetutils/2026-02/msg00000.html/https://www.openwall.com/lists/oss-security/2026/02/24/1/https://nvd.nist.gov/vuln/detail/CVE-2026-28372