¡¾Â©¶´Í¨¸æ¡¿Linux Kernel µ±µØÈ¨ÏÞÌáÉý©¶´£¨CVE-2021-33909£©

Ðû²¼Ê±¼ä 2021-07-21

0x00 ©¶´¸ÅÊö

CVE     ID

CVE-2021-33909

ʱ      ¼ä

2021-07-21

Àà     ÐÍ

LPE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ


Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP

ÒѹûÈ»

ÔÚÒ°ÀûÓÃ


 

0x01 ©¶´ÏêÇé

image.png

 

2021Äê7ÔÂ20ÈÕ£¬QualysÑо¿ÍŶӹûÈ»Åû¶ÁËÔÚLinux ÄÚºËÎļþϵͳ²ãÖз¢ÏÖµÄÒ»¸öµ±µØÌáȨ©¶´£¨CVE-2021-33909£¬Ò²³ÆÎªSequoia£©ºÍsystemd (PID 1) ÖеÄÒ»¸ö¾Ü¾ø·þÎñ©¶´£¨CVE-2021-33910£© ¡£

Linux Kernel µ±µØÌáȨ©¶´£¨CVE-2021-33909£©

Linux ÄÚºËÎļþϵͳ²ãÖдæÔÚsize_t-to-int ÀàÐÍת»»Â©¶´¡£ÓÉÓÚfs/seq_file.c ûÓÐÕýÈ·ÏÞÖÆ seq »º³åÇø·ÖÅ䣬´Ó¶øµ¼ÖÂÕûÊýÒç³ö¡¢Ô½½çдÈëÒÔ¼°È¨ÏÞÌáÉý¡£¹¥»÷Õß¿ÉÒÔÔÚĬÈÏÅäÖÃÖÐÀûÓôË©¶´£¬×îÖÕ¿ÉÒÔÔÚÊÜÓ°ÏìÖ÷»úÉÏ»ñµÃroot ȨÏÞ¡£Â©¶´Ó°ÏìÁË×Ô 2014 ÄêÒÔÀ´Ðû²¼µÄËùÓÐ Linux Äں˰汾¡£

Ó°Ï췶Χ

Linux kernel 3.16 - 5.13.x£¨5.13.4֮ǰ£©

 

Systemd(PID 1)¾Ü¾ø·þÎñ©¶´£¨CVE-2021-33910£©

systemdÊǰüÂÞÔÚ´ó¶àÊý»ùÓÚ Linux ϵͳÖеÄÈí¼þÌ×¼þ£¬ËüÌṩÁËÒ»¸öϵͳºÍ·þÎñ¹ÜÀíÆ÷£¬×÷Ϊ PID 1 ÔËÐв¢Æô¶¯ÏµÍ³µÄÆäÓಿÃÅ¡£

¸Ã©¶´ÓÉsystemd v220£¨2015Äê4Ô£©Ìá½»µÄ7410616c£¨¡°ºËÐÄ£º·µ¹¤µ¥ÔªÃû³ÆÑéÖ¤ºÍ²Ù×÷Âß¼­¡±£©ÒýÈ룬¸Ã©¶´½«¶ÑÖеÄstrdup()Ìæ»»Îª¶ÑÖеÄstrdupa()¡£ºÎ·ÇÌØÈ¨Óû§¶¼¿ÉÒÔÀûÓôË©¶´Ê¹ systemd Í߽⣬´Ó¶øÊ¹Õû¸öϵͳÍ߽⣨ÄÚºËÍ߽⣩£¬µ¼Ö¾ܾø·þÎñ¡£¸Ã©¶´Ó°ÏìÁË2015 Äê 4 ÔÂÖ®ºóÐû²¼µÄËùÓÐ systemd °æ±¾¡£

Ó°Ï췶Χ

systemd 220 ¨C 248

 

0x02 ´¦Öý¨Òé

ĿǰÕâЩ©¶´ÒѾ­ÐÞ¸´¡£¼øÓÚ©¶´µÄÓ°Ï췶Χ½Ï¹ã£¬ÇÒPoCÒѾ­¹ûÈ»£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶ÖÁLinux Kernel 5.13.4£¨ÓÚ2021Äê7ÔÂ20ÈÕÐû²¼£©»ò¸ü¸ß°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://www.kernel.org/

 

0x03 ²Î¿¼Á´½Ó

https://blog.qualys.com/vulnerabilities-threat-research/2021/07/20/sequoia-a-local-privilege-escalation-vulnerability-in-linuxs-filesystem-layer-cve-2021-33909

https://blog.qualys.com/vulnerabilities-threat-research/2021/07/20/cve-2021-33910-denial-of-service-stack-exhaustion-in-systemd-pid-1

https://www.bleepingcomputer.com/news/security/new-linux-kernel-bug-lets-you-get-root-on-most-modern-distros/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-07-21

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png         image.png