Linux KernelÐÅϢй¶©¶´£¨CVE-2020-28588£©
Ðû²¼Ê±¼ä 2021-04-280x00 ©¶´¸ÅÊö
CVE ID | CVE-2020-28588 | ʱ ¼ä | 2021-04-28 |
Àà ÐÍ | ÐÅϢй¶ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | Ó°Ï췶Χ | ||
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà |
0x01 ©¶´ÏêÇé
2021Äê04ÔÂ27ÈÕ£¬Cisco Talos¹ûÈ»Åû¶ÁËÔÚLinuxÄÚºËÖз¢ÏÖµÄÒ»¸öÐÅϢй¶©¶´ £¨CVE-2020-28588£©¡£¸Ã©¶´´æÔÚÓÚÔËÐÐLinuxµÄ32λARMÉ豸µÄ/proc/pid/syscall¹¦Ð§ÖУ¬ÓÉÓÚÊýÖµÀàÐÍÖ®¼äµÄ´íÎóת»»£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¶ÁÈ¡/proc/<pid>/syscallÎļþÀ´ÀûÓôË©¶´£¬ÒÔ¼ì²ìÄں˶ÑÕ»ÄÚ´æÐÅÏ¢»òͨ¹ý´Ë©¶´À´ÀûÓÃÆäËüδÐÞ¸´µÄLinux©¶´¡£
´ËÍ⣬¹¥»÷Õß»¹¿ÉÒÔͨ¹ý´ËÐÅϢй¶©¶´ÈƹýKASLR¡£Äں˵ØÖ·¿Õ¼ä½á¹¹Ëæ»ú»¯£¨KASLR£©ÊÇÒ»ÖÖ·´ÀûÓü¼Êõ£¬¿ÉÒÔ½«ÖÖÖÖ¹¤¾ßËæ»ú·ÅÖã¬ÒÔ·ÀÖ¹±»¹¥»÷ÕßÍÆ²â¡£
©¶´Ï¸½Ú
/ProcÊÇÀàUnixϵͳÖеÄÒ»¸öÌØÊâµÄÐéÄâÎļþϵͳ£¬ÓÃÓÚ¶¯Ì¬µØ·ÃÎÊÄÚºËÖеĽø³ÌÊý¾Ý¡£ËüÒÔÀàËÆÓÚÎļþµÄÌõÀí½á¹¹ÏÔʾÓйؽø³ÌµÄÐÅÏ¢ºÍÆäËüϵͳÐÅÏ¢¡£ÀýÈ磬Ëü°üÂÞ/proc/[pid]×ÓĿ¼£¬Ã¿¸ö×ÓĿ¼¶¼°üÂÞÎļþºÍ×ÓĿ¼£¬ÕâЩÎļþºÍ×ÓĿ¼°üÂÞÁËÓйØÌض¨½ø³ÌµÄÐÅÏ¢£¬¶øÕâЩÐÅÏ¢¿ÉÒÔͨ¹ýʹÓÃÏàÓ¦µÄ½ø³ÌIDÀ´¶ÁÈ¡¡£syscall ÎļþÊÇÒ»¸öºÏ·¨µÄLinuxϵͳÎļþ£¬Ëü°üÂÞÄÚºËʹÓõÄϵͳµ÷ÓÃÈÕÖ¾¡£
/proc/pid/syscallÎļþ»á̻¶ϵͳµ÷ÓúÅÂëºÍµ±Ç°½ø³ÌÕýÔÚÖ´ÐеÄϵͳµ÷ÓõIJÎÊý¼Ä´æÆ÷£¬ÒÔ¼°¶ÑÕ»Ö¸ÕëºÍ·¨Ê½¼ÆÊýÆ÷¼Ä´æÆ÷µÄÖµ¡£ËäÈ»´ó¶àÊýϵͳµ÷ÓÃʹÓõļĴæÆ÷½ÏÉÙ£¬µ«ËùÓеÄÁù¸ö²ÎÊý¼Ä´æÆ÷µÄÖµ¶¼Êб»Ì»Â¶¡£
¹¥»÷Õß¿ÉÒÔͨ¹ý¶ÁÈ¡/proc/<pid>/syscallÎļþÀ´¼ì²ìÄÚºËÄÚ´æÐÅÏ¢£¬Õâ¿ÉÒÔÔÚÄÚºËÅäÖÃÁËCONFIG_HAVE_ARCH_TRACEHOOKµÄÈκÎÌØ¶¨LinuxϵͳÉÏ¿´µ½Êä³ö£¬µ«¹¥»÷ÎÞ·¨ÔÚÔ¶³ÌÍøÂçÉϽøÐмì²â¡£
´¥·¢¸Ã©¶´µÄshellÃüÁîΪ£º
# echo 0 > /proc/sys/kernel/randomize_va_space (# only needed for a cleaner output)
$ while true; do cat /proc/self/syscall; done | uniq (# waits for changes)
$ while true; do free &>/dev/null; done (# triggers changes)
Ñо¿ÈËÔ±Ê×ÏÈÔÚAzure SphereÉ豸£¨°æ±¾20.10£¬32λARMÉ豸£©ÉÏ·¢ÏÖÁËÕâ¸ö©¶´£¬¸ÃÉ豸ÔËÐдòÁËÒ»¸ö²¹¶¡µÄLinuxÄںˡ£Õâ¸ö©¶´ÔÚv5.1-rc4£¨ÌύΪ631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0£©ÖÐÒѾ±»ÒýÈ룬µ«ÔÚv5.10-rc4ÖÐÈÔÈ»´æÔÚ£¬ËùÒÔÕâÖмäµÄËùÓа汾ºÜ¿ÉÄܶ¼Êܵ½Ó°Ïì¡£
Ó°Ï췶Χ
v5.1-rc4 - v5.10-rc4
ÒѲâÊÔ°æ±¾£º
Linux Kernel v5.10-rc4
Linux Kernel v5.4.66
Linux Kernel v5.9.8
0x02 ´¦Öý¨Òé
½¨ÒéÉý¼¶µ½×îа汾¡£
ÏÂÔØÁ´½Ó£º
https://cdn.kernel.org/pub/linux/kernel/v5.x/linux-5.12.tar.xz
0x03 ²Î¿¼Á´½Ó
https://blog.talosintelligence.com/2021/04/vuln-spotlight-linux-kernel.html
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1211
https://threatpost.com/linux-kernel-bug-wider-cyberattacks/165640/
0x04 ʱ¼äÏß
2021-04-27 Cisco Talos¹ûȻ©¶´
2021-04-28 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/