5 ms·
Did you update the addresses of commit_creds() and prepare_kernel_cred() to match your running kernel before you compiled/ran it?
by 16 11y ago
Did you update the addresses of commit_creds() and prepare_kernel_cred() to match your running kernel before you compiled/ran it?
- javanix 11y agoHow do you find those addresses?
- agwa 11y agoGrep for commit_creds and prepare_kernel_cred in /proc/kallsyms. The address is in the first column.
- fuuuuuuuuu 11y agohttps://gist.github.com/gcmurphy/1c91644718d28695da2d https://gist.github.com/gcmurphy/1c91644718d28695da2d ^-- this version should do that automatically
- wfn 11y agoBy looking at /proc/kallsyms: grep commit_creds /proc/kallsyms grep prepare_kernel_cred /proc/kallsyms Then update addresses as shown in one of the code snippets: _commit_creds commit_creds = 0xffffffff81094250; _prepare_kernel_cred prepare_kernel_cred = 0xffffffff81094550;
- javanix 11y agoThanks, that worked.
- Maran 11y agoQuestion for you. As a normal user, grepping these values I actually get 0000000000000000. I can't imagine these being the actual values. Is it possible that because I remount my /proc with the hidepid=2 option the values are not visible for normal non-root accounts?
- baghira 11y agoThat only hides the pid directories of others users, and indeed on my system remounting /proc with hidepid=2 I'm still able to see the same values for kallsyms. Maybe your kernel is compiled without the CONFIG_KEYS=y option? (I'm spitballing here).
- Maran 11y agoIt is indeed compiled with CONFIG_KEYS=y. Does this protect me against this issue? I'm not sure what this means.
- baghira 11y agoNo, the bug is in the kernel keyring facility, so if I'm not mistaken compiling with CONFIG_KEYS=n option should protect you (I haven't tested though). As for the /proc/kallsyms, I honestly don't know how come you only get zeroes. EDIT: The obvious question I should have asked is which distro you are running. Also, as others have pointed out, hoping that the attacker can't read kallsyms from the machine he's attacking is not really a good defense plan.
- Maran 11y agoI'm running Ubuntu 14.04 which should be affected. I just hoped it would be harder without having the correct kallsyms version. It seems I will have no options except to reboot my cluster :)
- altendo 11y agomake sure you have privileges to read that file. I ran grep without sudo and got that address on Ubuntu 15.10, but with sudo it will display an actual address.
- Maran 11y agoAs I understand it the whole idea of this exploit is getting sudo access from a normal user. Exploiting from root to root doesn't make a lot of sense. If the values are not retrievable as normal user this exploit can't be used.. Right?