11 ms·
Linux Kernel Through 4.20.10 Found Vulnerable to Arbitrary Code Execution
- saagarjha 8y agoHooray for KASAN!
- ronjouch 8y agoDidn't know about KASAN ( https://github.com/google/kasan/wiki https://github.com/google/kasan/wiki ). "KernelAddressSanitizer (KASAN) is a dynamic memory error detector. It provides a fast and comprehensive solution for finding use-after-free and out-of-bounds bugs in Linux kernel. KASAN is available in the upstream Linux kernel starting from 4.0. Can be enabled with CONFIG_KASAN=y."
- sargun 8y agoHow does this use-after-free turn into an arbitrary code execution vuln? I don't see any jmp to the pointer?
- deleted 8y ago[deleted]
- 0x0 8y agoMaybe it can be used to write a "0" into a useful kernel structure such as a forked process' effective uid (thus escalating to uid0)
- Sohcahtoa82 8y agoWouldn't that just be a privilege escalation though, not arbitrary code execution?
- 0x0 8y agoWell if you are root then you can usually load random kernel modules and in general do whatever you want on the system.
- prudhvis 8y agoDoes that mean then, that every privilege escalation be arbitrary code execution?
- darawk 8y agoI'd say so, yes, assuming that you can then execute arbitrary code with the elevated privileges.
- Sohcahtoa82 8y agoI'd say no, because to be able to make a privilege escalation attack useful, you'd have to already have arbitrary code execution.
- darawk 8y agoNot necessarily. You could, for instance, elevate the privileges of a process you can't completely control, which might allow you to read sensitive files or disrupt a system, but not perform arbitrary actions with those privileges.
- Sohcahtoa82 8y agoI concede that privesc without code execution can be useful, but my original claim that privesc is not necessarily code execution still stands.
- darawk 8y agoI think we agree then? I said "assuming you can execute arbitrary code with the elevated privileges".
- muricula 8y agoOverwrite the return address or a function pointer instead. Then when the address/pointer is used you can execute whatever you want. Loop up Return Oriented Programming.
- altmind 8y agoI urge the mods to correct the title. Maybe: Linux<4.20.10 af_alg_release use-after-free vulnerability[CVE-2019-8912]
- cmurf 8y agohttps://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/tree/crypto/af_alg.c?h=v4.20.11 https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux... See line 126-127 and compared to the patch at the bottom of: http://patchwork.ozlabs.org/patch/1042902/ http://patchwork.ozlabs.org/patch/1042902/ Patch is not yet merged into 5.0.0rc7 either. Whereas it is in linux-next. https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/tree/crypto/af_alg.c?h=next-20190220 https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-n... Update: I expect all of the longterm kernels listed on kernel.org will get a backport.
- dang 8y agoThat's too complicated. If someone can distill this to a simple, clear, neutral title, we'll happily change it.
- viraptor 8y agoIt depends on manipulating/knowing what gets allocated in the same region. If you know what gets written to the freed space or you can try to force the right allocations to happen, you get almost-arbitrary write. For a made up example, imagine something allocates a structure with a pointer to a function struct->foo, then frees it, but still holds a reference. Now you call a function which allocates a buffer in the same place and copies your arguments into it. When you make the original code try to call struct->foo again, you can any function you want.
- kanox 8y agoAre there practical attacks for write-after-free? Controlling where the OS allocates an important structure seems very difficult and mistakes would likely result in corrupting unrelated data and a crash later on.
- viraptor 8y agoSure there are. Kernel makes this a bit easier since you have heaps for objects of a given size (which means it's much easier to overlap old structure when you know the size). Browsers (for JS -> native escape) make it a bit easier by allowing you to allocate lots of objects and having pointers everywhere. In many cases you can also spam all over the heap and hope for the best, since allocations are almost always aligned. I think most browser exploits are actually use-after-free. Check out how simple they can be: https://www.exploit-db.com/exploits/40946 https://www.exploit-db.com/exploits/40946
- mediocrejoker 8y agoWhat is the kernel-space equivalent of a root shell? presumably you wouldn't try to load your full payload into the kernel space, just try to give yourself root access somehow?
- monocasa 8y agocurrent->cred->uid = 0;
- ptrincr 8y agoLooks like this is the fix: https://github.com/torvalds/linux/commit/9060cb719e61b685ec0102574e10337fa5f445ea https://github.com/torvalds/linux/commit/9060cb719e61b685ec0...
- doctorpangloss 8y agoIs there a reason the kernel style doesn't always require curly braces after "if" statements?
- a-wu 8y ago"Do not unnecessarily use braces where a single statement will do." https://www.kernel.org/doc/html/v4.10/process/coding-style.html#placing-braces-and-spaces https://www.kernel.org/doc/html/v4.10/process/coding-style.h...
- kgwxd 8y agoA rule that should be removed from every coding style doc for every c-like language on the planet.
- shawnz 8y agoWhy? Because Apple had a critical vuln one time which was made slightly harder to spot because of it?
- thaumaturgy 8y agoWhen drafting a style guide, one of your goals is to make the code as uniform as possible. It removes ambiguity and makes it easier to enforce the rules of the style guide, hopefully with automated tooling. Mandatory bracing is a step towards more uniformity, and makes additional statements in a conditional block always safe, and at the cost of just one extra line in the code. It also makes your commits just a little bit smaller; if you do add more lines to a conditional block that was previously braceless, now you just get the new lines in the diff, instead of new lines + opening brace + closing brace. Cowboy coding of course scoffs at all this and people have different values when making tradeoffs between readability and concision, but there are good reasons for enforcing mandatory braces.
- blattimwind 8y agoBetter link: https://nvd.nist.gov/vuln/detail/CVE-2019-8912 https://nvd.nist.gov/vuln/detail/CVE-2019-8912
- cmurf 8y agoI'm not seeing the patch in 4.20.11's changelog or any of the longterm kernel versions posted today.
- tramtrist 8y agoI literally just compiled 4.20.11 for Slackware. I swear these things are popping up more often. Or more likely since spectre I've just been paying more attention
- ebeip90 8y agoMore people are fuzzing the kernel publicly, and with better tools. syzkaller.appspot.com should give you an idea how many THOUSANDS of these types of bugs exist in the current ToT kernel
- Hackbraten 8y agoWhat is ToT? I’ve found that term mentioned several times on the Chromium bug tracker but no definition.
- erichurkman 8y agoTOT = Tip of Tree.
- sjburt 8y agoTip of Tree / Top of Tree. I.e present as of the most recent commit on the main development branch.
- tetha 8y agoYup. Kind of has my mind racing. And practically speaking, at that point, it feels like I need to employ a similar aggressive approach similar to our application. Go faster, and accept pain on the outer layer. Maybe the answer is to do a daily automated recompilation of the kernel, rebuild of the edge LB and FW images followed by automated, staged rollout and rollback. If we're vulnerable anyway, let's just pick up the fixes from yesterday at least and roll back if things go wrong. That sounds really scary, but doable.
- uvesten 8y agoIs this a remote exploit? The NIST page seems to say so.
- ptrincr 8y agoI'd like to know this too. The NIST page links to this site, which suggests no exploit is known of as yet: https://www.securityfocus.com/bid/107063/exploit https://www.securityfocus.com/bid/107063/exploit
- keyme 8y agoLooking at the reproducer (in the kernel commit message for the fix), this is a PE. Unless some software allows a remote user to control the issuing of these calls (seems unlikely).
- caf 8y agoIt's local. Of course that just means you have to chain it with a browser vulnerability to make it remote.
- orblivion 8y agoI'm waiting for the day where there's one reliable place in the world where someone can look at info about a vulnerability and see very important and basic information like this. I think the interesting technical discussions for security experts get mixed in with the useful executive summary for the rest of us. Remember when Intel ME bugs started coming out and we all had to go to Hacker News and trade rumors to figure out what was really going on?
- deleted 8y ago[deleted]
- jaboutboul 8y agoCan someone please explain how exactly this is ACE?
- saagarjha 8y agoIt's a use-after-free, which can often be turned into arbitrary code execution by massaging the allocator into letting you write over memory you shouldn't be able to (like a function pointer) and using that to gain control over execution.
- pmoriarty 8y agoWhere is crypto/af_alg.c actually used? In what use cases does this vulnerability come in to play?
- amaccuish 8y agoIt's used for crpyto acceleration AFAIK. E.g. I've used it to expose a beagleboards AES acceleration to OpenVPN via OpenSSL to make a small VPN client go faster.
- sigmaris 8y agoNot totally certain, but I believe it'd be used if a userspace program used the Linux Kernel Crypto API, using a socket of type AF_ALG. https://www.kernel.org/doc/html/v4.11/crypto/userspace-if.html https://www.kernel.org/doc/html/v4.11/crypto/userspace-if.ht...
- nyc_pizzadev 8y agoIts a kernel based crypto API. Ciphers, hashes, and keyed hashes (HMAC). It uses sockets to move data back and forth. Because its kernel based, there is going to be the usual kernel switch penalty. Sure, its hardware accelerated, but there are user space alternatives with zero kernel overhead. However, it does let you stash your private keys into kernel space and wipe those keys completely from user space. You then simply reference the keys you need to use. So in this regard, it can provide a higher level of key protection.
- ungamed 8y agoLook up man keyctl, sometimes used in disk crypto, or sharing secrets between userspace and kernel.
- EthanHeilman 8y agoIs this patched or is everything vulnerable?
- ebiggers 8y agoAFAICS, this was exposed by the addition of sockfs_setattr() in v4.10. So it's incorrect to claim that kernels older than that are vulnerable, even though the code being fixed was older. Also, note that there may not actually be a proof-of-concept exploit yet, beyond a reproducer causing a KASAN splat. When people request a CVE for a use-after-free bug they usually just assume that code execution may be possible. (Exploits can be very creative.)
- deleted 8y ago[deleted]
- shereadsthenews 8y agoFYI there has not ever been a Linux kernel that lacks an exploit available to, at least, local users. There is every reason to believe that the current kernel contains at least one such flaw.
- solarkraft 8y agoAre you just claiming that vulnerabilities exist, including undiscovered ones, or that there have been discovered flaws for all versions?
- blattimwind 8y agoBoth, which seems not just reasonable, but very much probable to me.
- ungamed 8y agoThe next big vulnerability is not an if, but a when. And all software has flaws.. there is no exception to this rule.
- vermilingua 8y agoThis likely extends to NT, BSD, Darwin, and most other kernels. Kernels are tricky beasts. You could just say “not ever been a kernel that lacks...”
- userbinator 8y agoDOS. It has no privilege escalation exploits, because by design it has no concept of different privileges. Personally, I think as a regular user of a PC, it's the remote exploits that you really need to worry about, the ones of the form "connect to the Internet and get pwned without doing anything else", fortunately quite rare; and in this era of user-hostile devices, local privilege escalation can even be friendly in terms of rooting and jailbreaks.
- pdonis 8y ago
- birbie 8y agoI haven't seen any POC exploits at all yet. Will be looking around this weekend.
- tty7 8y agohow do you "look" for POC's?
- PenguinCoder 8y agoVarious websites, shady forums, tor sites, and 'hacker spaces'. Sometimes that includes white/gray hat haunts for exploit code. Pastebin like sites, github.com, etc. 'darkweb' and OSINT searches. If there is a know vuln, there is someone out there eager to be 'first' to writing exploit code and showing off.
- gtirloni 8y agoAny place where a concrete list of such resources can be found?
- wonthegame 8y agoGoogle.
- eatbitseveryday 8y agoIt's as if these places are worth something to know about and to keep to oneself. That, or "searching for exploits" is just a phrase to sound important. How demeaning to reply with just "Google".
- IloveHN84 8y agoGoogle doesn't list dark web or shady forums
- subcosmos 8y ago
- SilasX 8y agoI really shouldn't comment on Linux kernel development, given mu lack of knowledge, but since this is a use-after-free vuln, doesn't that strengthen the case to moving to memory safe languages?
- saagarjha 8y agoThe Linux kernel has far too much C for this to be easy to do.
- IAmLiterallyAB 8y agoPerhaps a language that supports a C FFI, like Rust. Of course, Rust is probably not mature enough to be used in the kernel.
- yjftsjthsd-h 8y agoWhy isnt it mature enough? Redox seems like an argument that it can work. Granted, there are general issues with requiring a new compiler, etc.
- FartyMcFarter 8y agoDoes Rust support all the platforms the Linux kernel is available for?
- steveklabnik 8y agoNo.
- exabrial 8y agoYou would take a massive hit in performance. But there are operating systems (some commercial) like that
- SilasX 8y ago
- broknbottle 8y agoahh looks like they have updated page to include 4.20.11. I was gonna say after checking the source, both the latest and mainline are affected.
- Fnoord 8y agoFound by Huawei engineer Mao Wenan.
- skyde 8y agois it something using a safer language like Rust would have prevented ?
- apta 8y agoYes.