¡¾Â©¶´Í¨¸æ¡¿Linux Kernel µ±µØÈ¨ÏÞÌáÉý©¶´£¨CVE-2021-33909£©
Ðû²¼Ê±¼ä 2021-07-210x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-33909 | ʱ ¼ä | 2021-07-21 |
Àà ÐÍ | LPE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | Ó°Ï췶Χ | ||
¹¥»÷ÅÓ´ó¶È | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | ÒѹûÈ» | ÔÚÒ°ÀûÓà |
0x01 ©¶´ÏêÇé
2021Äê7ÔÂ20ÈÕ£¬QualysÑо¿ÍŶӹûÈ»Åû¶ÁËÔÚLinux ÄÚºËÎļþϵͳ²ãÖз¢ÏÖµÄÒ»¸öµ±µØÌáȨ©¶´£¨CVE-2021-33909£¬Ò²³ÆÎªSequoia£©ºÍsystemd (PID 1) ÖеÄÒ»¸ö¾Ü¾ø·þÎñ©¶´£¨CVE-2021-33910£© ¡£
Linux Kernel µ±µØÌáȨ©¶´£¨CVE-2021-33909£©
Linux ÄÚºËÎļþϵͳ²ãÖдæÔÚsize_t-to-int ÀàÐÍת»»Â©¶´¡£ÓÉÓÚfs/seq_file.c ûÓÐÕýÈ·ÏÞÖÆ seq »º³åÇø·ÖÅ䣬´Ó¶øµ¼ÖÂÕûÊýÒç³ö¡¢Ô½½çдÈëÒÔ¼°È¨ÏÞÌáÉý¡£¹¥»÷Õß¿ÉÒÔÔÚĬÈÏÅäÖÃÖÐÀûÓôË©¶´£¬×îÖÕ¿ÉÒÔÔÚÊÜÓ°ÏìÖ÷»úÉÏ»ñµÃroot ȨÏÞ¡£Â©¶´Ó°ÏìÁË×Ô 2014 ÄêÒÔÀ´Ðû²¼µÄËùÓÐ Linux Äں˰汾¡£
Ó°Ï췶Χ
Linux kernel 3.16 - 5.13.x£¨5.13.4֮ǰ£©
Systemd(PID 1)¾Ü¾ø·þÎñ©¶´£¨CVE-2021-33910£©
systemdÊǰüÂÞÔÚ´ó¶àÊý»ùÓÚ Linux ϵͳÖеÄÈí¼þÌ×¼þ£¬ËüÌṩÁËÒ»¸öϵͳºÍ·þÎñ¹ÜÀíÆ÷£¬×÷Ϊ PID 1 ÔËÐв¢Æô¶¯ÏµÍ³µÄÆäÓಿÃÅ¡£
¸Ã©¶´ÓÉsystemd v220£¨2015Äê4Ô£©Ìá½»µÄ7410616c£¨¡°ºËÐÄ£º·µ¹¤µ¥ÔªÃû³ÆÑéÖ¤ºÍ²Ù×÷Âß¼¡±£©ÒýÈ룬¸Ã©¶´½«¶ÑÖеÄstrdup()Ìæ»»Îª¶ÑÖеÄstrdupa()¡£ºÎ·ÇÌØÈ¨Óû§¶¼¿ÉÒÔÀûÓôË©¶´Ê¹ systemd Í߽⣬´Ó¶øÊ¹Õû¸öϵͳÍ߽⣨ÄÚºËÍ߽⣩£¬µ¼Ö¾ܾø·þÎñ¡£¸Ã©¶´Ó°ÏìÁË2015 Äê 4 ÔÂÖ®ºóÐû²¼µÄËùÓÐ systemd °æ±¾¡£
Ó°Ï췶Χ
systemd 220 ¨C 248
0x02 ´¦Öý¨Òé
ĿǰÕâЩ©¶´ÒѾÐÞ¸´¡£¼øÓÚ©¶´µÄÓ°Ï췶Χ½Ï¹ã£¬ÇÒPoCÒѾ¹ûÈ»£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶ÖÁLinux Kernel 5.13.4£¨ÓÚ2021Äê7ÔÂ20ÈÕÐû²¼£©»ò¸ü¸ß°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://www.kernel.org/
0x03 ²Î¿¼Á´½Ó
https://blog.qualys.com/vulnerabilities-threat-research/2021/07/20/sequoia-a-local-privilege-escalation-vulnerability-in-linuxs-filesystem-layer-cve-2021-33909
https://blog.qualys.com/vulnerabilities-threat-research/2021/07/20/cve-2021-33910-denial-of-service-stack-exhaustion-in-systemd-pid-1
https://www.bleepingcomputer.com/news/security/new-linux-kernel-bug-lets-you-get-root-on-most-modern-distros/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-07-21 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º