Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | GNU Inetutils telnetd ÇéÐαäÁ¿×¢ÈëÌáȨÎó²î |
CVE ID | CVE-2026-28372 |
Îó²îÀàÐÍ | ȨÏÞÌáÉý | ·¢Ã÷ʱ¼ä | 2026-3-2 |
Îó²îÆÀ·Ö | 7.4 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍâµØ | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | ¸ß | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Telnet ÊÇÒ»ÖÖ»ùÓÚTCPµÄÔ¶³ÌÖÕ¶Ë»á¼ûЧÀÍÓëÓ¦ÓòãÐÒ飬£¬£¬£¬£¬£¬£¬Ä¬ÈÏʹÓÃ23¶Ë¿Ú£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÓû§Í¨¹ýÍøÂçÔÚµ±ÌïÖ÷»úÉÏÔ¶³ÌµÇ¼²¢²Ù×÷Áíһ̨ЧÀÍÆ÷¡£¡£¡£¡£Telnet½ÓÄÉÃ÷ÎÄ·½·¨´«ÊäÓû§Ãû¡¢¿ÚÁî¼°»á»°Êý¾Ý£¬£¬£¬£¬£¬£¬£¬ÔçÆÚÆÕ±éÓÃÓÚÀàUnixϵͳµÄÔ¶³ÌÖÎÀíÓë×°±¸ÔËά¡£¡£¡£¡£ÓÉÓÚȱ·¦¼ÓÃܺÍÍêÕûµÄÉí·Ý±£»£»£»£»£»£»£»¤»úÖÆ£¬£¬£¬£¬£¬£¬£¬TelnetÈÝÒ×ÔâÊÜÇÔÌý¡¢ÖطźÍÖÐÐÄÈ˹¥»÷£¬£¬£¬£¬£¬£¬£¬Ç徲Σº¦½Ï¸ß¡£¡£¡£¡£Ëæ×ÅÇå¾²ÐèÇóµÄÌáÉý£¬£¬£¬£¬£¬£¬£¬TelnetÒÑÖð²½±»SSHµÈ¼ÓÃÜÔ¶³ÌÖÎÀíÐÒéËùÈ¡´ú£¬£¬£¬£¬£¬£¬£¬Í¨³£½öÔÚÊܿصÄÄÚÍøÇéÐλòÌØÊâ¼æÈݳ¡¾°ÖÐʹÓᣡ£¡£¡£
2026Äê3ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬£¬¿Ê±K66Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½GNU InetutilsÖÐtelnetd×é¼þ±£´æÇéÐαäÁ¿×¢ÈëÌáȨÎó²î¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚtelnetd¶Ô¿Í»§¶Ë¿É¿ØÇéÐαäÁ¿£¨ÈçCREDENTIALS_DIRECTORY£©¹ýÂ˲»ÑϿᣬ£¬£¬£¬£¬£¬£¬Î´½ÓÄÉÑÏ¿áµÄ°×Ãûµ¥»úÖÆ¾ÙÐÐÏÞÖÆ¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÉèÖÃCREDENTIALS_DIRECTORY£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ¶ÔӦĿ¼Öн¨Éè°üÀ¨Ìض¨ÄÚÈݵÄlogin.noauthÎļþ£¬£¬£¬£¬£¬£¬£¬ÓÕʹÒÔrootȨÏÞÖ´ÐеÄ/bin/loginÌø¹ýÕý³£Éí·ÝÈÏÖ¤Á÷³Ì£¬£¬£¬£¬£¬£¬£¬×îÖÕ»ñÈ¡rootȨÏÞ¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
GNU Inetutils <= 2.7
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£Debian sid/forky£ºinetutils >= 2:2.7-3Debian trixie (security)£ºinetutils >= 2:2.6-3+deb13u2
3.2 ÔÝʱ²½·¥
½ûÓÃtelnetЧÀÍ¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://lists.gnu.org/archive/html/bug-inetutils/2026-02/msg00000.html/https://www.openwall.com/lists/oss-security/2026/02/24/1/https://nvd.nist.gov/vuln/detail/CVE-2026-28372