17 ms·
Linux: Vulnerabilities in nf_tables cause privilege escalation, information leak
- bckr 5y agoAs an early career developer I feel helpless with the vast world of cyber security looming all around me, and not that many people thinking very much about it. It feels kind of like COVID in 2022. Obviously everywhere. Probably not going to hurt me? Could end my career.
- pjmlp 5y agoDon't worry, embrace the lack of care writing secure systems, plenty of job opportunities in cyber security until the culture finally changes.
- perlgeek 5y ago> Could end my career. Very unlikely. Stick to good practices. If you are asked to do something that's bad for security, raise your objections in written form (email/tickets). Security isn't only your responsibility; it's also the product manager's and the security team's responsibility. All together this means that it's very hard for a company to convincingly blame a single developer for an incident. Maybe they fire you as a scapegoat, but that isn't very likely, and it should be far from career ending.
- spacemanmatt 5y ago> Security isn't only your responsibility This. As a developer, your security-aligned goals should include code review, readable/auditable code, configuration options that support testing/QA, features that operate on a principle of least surprise to the user, and other things like these. Security is ultimately a blended practice.
- INTPenis 5y agoJust being practical and communicative will get you farther than you think.
- pmontra 5y ago> Could end my career If it does half of us would be jobless. Do reasonable choices, agree them with the team and the stakeholders. For extra safety do not accept jobs above your level of knowledge of security issues.
- jasongill 5y agoI felt the same way back when my career started in the late 90's, with what felt like daily new kernel updates for security issues and tons of realizations that the "old way" of doing things was insecure. You'll make it. There will be bad times and there will be very long nights and weekends, and you'll probably have a few events in your life that will make you say "ok, I'm done" but you'll survive and make it through. Try to be mindful of your mental and physical health as dealing with these issues can take a toll on you, but do know that you will survive and make it through.
- hluska 5y agoI’m an old developer and I’ve been worried about the same thing for most of my career. We’ll either be fine or you’ll have a far easier time switching careers than me. :) But we’ll likely be fine. Just keep a healthy respect for security, keep learning and think through best practices.
- TruthWillHurt 5y agoI'm going back to kernel 2.6 .
- jasongill 5y agoIt sounds crazy, but our CentOS 6 servers (which run 2.6.32) using CloudLinux 6 ELS (which provides kernel hot patching for vulnerabilities like this, plus continued security updates for Apache, PHP, MySQL, Glibc, OpenSSL, OpenSSH, etc through 2024) are our most reliable ones. It's given us a couple years more breathing room to let the Alma/Rocky debate settle and work on migrating legacy applications to newer platforms without having to stress about being on an unsupported release.
- lanstin 5y agoIt is ok until new hardware is purchased that won’t run on the older kernels. For pure VM stuff, the 2.6.32 s fine (Go supports it without patches) but the newer kernels have much better scheduler and other cpu optimizations. I saw about a 25% efficiency gain from upgrading to 4 series kernels after specter etc.
- kafkaIncarnate 5y agohttps://nvd.nist.gov/vuln/detail/CVE-2022-1015 https://nvd.nist.gov/vuln/detail/CVE-2022-1015 https://nvd.nist.gov/vuln/detail/CVE-2022-1016 https://nvd.nist.gov/vuln/detail/CVE-2022-1016 https://access.redhat.com/security/cve/CVE-2022-1015 https://access.redhat.com/security/cve/CVE-2022-1015 https://access.redhat.com/security/cve/CVE-2022-1016 https://access.redhat.com/security/cve/CVE-2022-1016 https://ubuntu.com/security/CVE-2022-1015 https://ubuntu.com/security/CVE-2022-1015 https://ubuntu.com/security/CVE-2022-1016 https://ubuntu.com/security/CVE-2022-1016 https://security-tracker.debian.org/tracker/CVE-2022-1015 https://security-tracker.debian.org/tracker/CVE-2022-1015 https://security-tracker.debian.org/tracker/CVE-2022-1016 https://security-tracker.debian.org/tracker/CVE-2022-1016 I just spent the whole weekend patching whatever the last kernel vuln was and had to plan around like 20 people's schedules. I thought Meltdown/Spectre was bad, this year is already feeling like that year in repeat. 15 years as a sysadmin, anyone have suggestions for my next career move? Thanks.
- bigiain 5y ago> anyone have suggestions for my next career move? I'm keeping my eyes open on circus website careers pages. I reckon I'd have way fewer clowns to deal with if I was an actual clown car driver... :sigh:
- jamal-kumar 5y agoInfosec
- iso1210 5y agoBuild systems that can cope with the loss of nodes and ideally self-heal if you kill a node.
- WestCoastJustin 5y ago> 15 years as a sysadmin, anyone have suggestions for my next career move? I made the switch to Technical Product Marketing after 15+ years doing linux sysadmin stuff. This might seem weird at first but all tech companies have complex products that they are trying to sell to a technical audience. Marketing needs technical folks embedded that can translate between the tech stack and marketing speak. You can probably 2x your sysadmin compensation quite easily and offers tons of career growth (developer relations, tons of conference speaker opportunities, become some industry expert, etc). No idea about your skill set or area of expertise but here's an example from vmware [1]. Just search for "Technical Marketing". The job typically involves doing technical reviews of competitors, something you'll already do when deciding to choose a product as a sysadmin, reviewing internal marketing content to make sure people are telling the truth, doing talks/training, recording demos, interacting with PM/Eng about product releases, testing and writing about new releases, etc. If you like the technical side and don't mind teaching this can be a good transition. You basically leverage all the skills you've built over 15 years and apply them to something else quickly. The kicker here is that you can just apply to companies where you already use their products and know them inside and out (giving you a massive advantage compared to other people applying). Say, you do tons of AWS stuff, well who better to work with marketing on the technical side then a sysadmin who breaths this stuff everyday, or maybe you're doing stuff on cisco switches [2], or maybe some netapp storage fabric expert [3], same thing. All these companies have technical roles in marketing that want you and it can range from mega corps to cool startups like GitLab [4]. [1] https://careers.vmware.com/main/jobs/R2204162?lang=en-us https://careers.vmware.com/main/jobs/R2204162?lang=en-us [2] https://jobs.cisco.com/jobs/ProjectDetail/Technical-Marketing-Engineer-Full-Time-United-States/1338944 https://jobs.cisco.com/jobs/ProjectDetail/Technical-Marketin... [3] https://jobs.netapp.com/job/Bangalore%2C-Karnataka-Technical-Marketing-Engineer-560071/843643500/ https://jobs.netapp.com/job/Bangalore%2C-Karnataka-Technical... [4] https://about.gitlab.com/job-families/marketing/technical-marketing-manager/ https://about.gitlab.com/job-families/marketing/technical-ma...
- StillBored 5y agoIts yet another int overflow bug too. Something like a kernel should probably be built with saturating arithmetic rather than the stupid C overflow behavior.
- saagarjha 5y agoSaturating arithmetic is not free from problems, although typically better than two’s complement that some languages have settled on. I’d rather it just panicked, to be honest.
- StillBored 5y agoWhich on x86, one could trap on overflow. That is one of those legacy options people complain about because they aren't used by C. I'm not sure that is as easy on Arm/etc because IIRC there isn't an integer overflow exception. For whatever reason most newer languages (say rust) don't actually solve this problem either. They could diverge from the normal and do saturating (which arm does have) ints, or throw exceptions on overflow/underflow, but they don't because that would be to hard when they have to manually check overflow on each operation because its not a common feature of many processor arches. edit: although LEA is one of the instructions which avoids flags updates, so even if you wanted to trap it probably wouldn't.
- Munksgaard 5y agoRust does in fact have a story around overflows: https://doc.rust-lang.org/book/ch03-02-data-types.html#integer-overflow https://doc.rust-lang.org/book/ch03-02-data-types.html#integ...
- StillBored 5y agoBut the rust story is basically the same as the C story, which is use something other than the normal operators to do your arithmetic. There are tons of checked_add()_sub/_mul macros or functions floating around. At least in C++ one could override the global operators if needed.
- woodruffw 5y agoExploitable uninitialized stack variables in 2022! Remarkable.
- worthless-trash 5y agoApparently nobody wants to take the 'secure default' performance hit of setting CONFIG_INIT_STACK_ALL_ZERO , as it will look slower compared to other distros.
- mustache_kimono 5y agoYeesh.
- pjmlp 5y agoAndroid and Windows do take that hit. https://android-developers.googleblog.com/2020/06/system-hardening-in-android-11.html?m=1 https://android-developers.googleblog.com/2020/06/system-har... https://msrc-blog.microsoft.com/2020/05/13/solving-uninitialized-stack-memory-on-windows/ https://msrc-blog.microsoft.com/2020/05/13/solving-uninitial...
- josefx 5y agoAs far as I can find that flag seems to be clang specific? Which distros even use clang? Also since the Kernel is not pure C not all safety options are safe, at one point a few distros enabled stack overflow protection, only to end up with a kernel that randomly corrupted application stacks.
- deleted 5y ago[deleted]
- rvz 5y agoOut of bounds access, uninitialized stack data with an extremely weak language that doesn’t check any of that and happily compiles that hidden footgun gives you an escalation of privileges vulnerability. Perhaps Rust would have prevented this in the first place. But the entirety of Linux and the ancient UNIX philosophy is a giant labyrinth full of cobwebs riddled with hidden traps, landmines and trip-wires beyond exploring. Must be the worlds largest and endless minesweeper game discovering all those C style vulnerabilities in the Linux kernel.
- pjmlp 5y agoPlenty of languages older than C would have caught that.
- nyberg 5y agoRust doesn't provide integer overflow safety unless explicitly requested. This is something refinement types which ATS2 provides would catch.
- mustache_kimono 5y agoThis isn't exactly true. Rust doesn't include such checks when compiled in '--release' mode. And Rust provides plenty of methods to make the programmer's intent clear and perform 'safer' arithmetic ops. See: https://doc.rust-lang.org/book/ch03-02-data-types.html?highlight=integer%20overflow#integer-overflow https://doc.rust-lang.org/book/ch03-02-data-types.html?highl...
- staticassertion 5y agoAnd unless there's an unsafe block integer overflow can not lead to a memory safety issue.
- chjj 5y agoI'm starting to get sick of the neverending "rust good, c bad" sentiment on HN. Bugs occur in rust code too. It's not a silver bullet to fix all problems associated with software development. Each language will have its own set of issues and quirks. It's easy to pick on C because it's been around far longer than most things. Give it 40 years and people will be saying "rust bad, new thing good".
- encryptluks2 5y agoHere comes the Rust people saying... should build everything in Rust it will fix all your problems and solve world hunger.
- kevingadd 5y agoYou could also just compile your kernel with things like stack zeroing enabled and eat the 0.1% performance hit in exchange for not getting owned by classic exploits :(
- pjmlp 5y agoThe safe systems programming people would rather point out to the list of systems programming languages since JOVIAL in 1958, and make a point that Multics, Burroughs and VAX/VMS actually had higher security assessements than UNIX, primarly by not having C powering their kernels, rather systems language whose security was part of the whole OS design.
- staticassertion 5y agoYeah, and I'll never stop saying we should use memory safe languages. Deal with it.
- KSPAtlas 5y agoMakes sense for a program which uses the command nft /s
- Xunjin 5y agoI know you are probably getting downvoted, tho your comment made me chuckle really hard, thank you for that. People, sometimes, forget how sarcasm is a nice tool in criticism (tho here is just for the fun)
- throwaway71271 5y agoYou can't have privilege escalation if everyone is root, modern problems require modern solutions.
- staticassertion 5y agoIronically, this privesc is in fact only possible because everyone now has root via user namespaces.
- deleted 5y ago[deleted]
- eptcyka 5y agoI don't understand, does this lead to privilege escalation by parsing a crafted netfilter rule? I am under the impression that I need NET_CAP_ADMIN or root privs to do this on my machines to load said rule anyway, right? So this affects deployments where regular users are able to do send netfilter rules to the kernel, right?
- detaro 5y ago> In order for an unprivileged attacker to exploit this issue, unprivileged user- and network namespaces access is required (CLONE_NEWUSER | CLONE_NEWNET)
- viraptor 5y agoMy understanding is that you can supply netfilter code which reads/writes to a register memory which is outside of the registers struct. So the rules bytecode you provide can do out-of-bounds access when the rule is executed, rather than when parsed. You can either do this as NET_CAP_ADMIN, or when you create your own user+network namespace as an unprivileged user. (which may not be allowed on your system either)
- staticassertion 5y agoWith user namespaces all of that is accessible now. For decades upstream hasn't cared about privesc let alone root -> kernel privesc, but now everyone's root lol
- MayeulC 5y agoThis is what I gathered from looking around: 1016 comes from an uninitialized value. 1015 is an int8 overflow and out-of-bounds access. Both are C footguns (though not exclusive to C). The latter arguably might not have happened under a stable/specified ABI. 1015: Introduced in 5.12 Fixed in 6e1acfa387b9, 2022-03-17 In LTS, fixed in 5.10.109 and 5.15.32 Also, in 5.16.18 and 5.17.1 1016: Introduced in v3.13-rc1 Fixed in 4c905f6740a3, 2022-03-17 Fixed in same point releases as above, plus 5.10.109 Doesn't look fixed in older LTSes yet
- egberts1 5y agoThere are over 1.412 nodes in the nftables syntax tree (as of 2019). I know. I wrote a Vim syntax hilighter for nftables. And it is still failing. Just imagine how much untested surface area is that for the `nft` CLI. My work: https://egbert.net/blog/tags/vim.html https://egbert.net/blog/tags/vim.html
- deburo 5y agoHow odd, your website gives me "ERR_SSL_VERSION_OR_CIPHER_MISMATCH" on Win64 > Chrome.
- LinuxBender 5y agoThey have a good cert rating but ipv6 is not responding [1] and some clients will be denied based on cipher policy. I would be surprised if that applied to Chrome but one can always check. The DNS entry for ipv6 should be removed if not used. [1] - https://www.ssllabs.com/ssltest/analyze.html?d=egbert.net&hideResults=on https://www.ssllabs.com/ssltest/analyze.html?d=egbert.net&hi...
- egberts1 5y agoThank you for the input. I really don’t care for Chrome users and their inability to do pure TLSv1.3. Also, my server decides the selection of algorithms in TLSv1.3, not the web browsers: and that’s ChaCha/Poly. Yeah, it’s also a JS-free website. Migration to IPv6 is a work-in-progress. Hurricane Electric ISP also has a weird login condition; they want you to create a second account so you can pass your IPv6 certification (first was for DNS/IPv4). So I am looking for a secondary DNS provider for IPv6.
- LinuxBender 5y agoalso a JS-free website That's great. I would love to see more JS-free sites and more lightweight sites.
- lazyweb 5y ago
- hej_ewe 5y agoIs this something that only affects linux servers, or are desktop users affected as well? Apologies if this question is too noob-ish.
- cout 5y agoIs this remotely exploitable or is it only a local vulnerability?
- staticassertion 5y agoLocal
- stormbrew 5y agoYet another CLONE_NEWUSER and fly away to victory privilege escalation. Really seems like enabling that was premature.
- tedunangst 5y agoWhat's the practical exposure to CLONE_NEWUSER | CLONE_NEWNET?
- dinosaurdynasty 5y agoMost Linux distributions these days are allowing all/most users (not just root) to create these namespaces by default, which allows normal unprivileged users to access security bugs in nftables (like this one) (amongst other things).
- wavesquid 5y agoMost containers.
- infotogivenm 5y agoMost containers are going to block unshare() via seccomp, no?
- dinosaurdynasty 5y agoMost containers run as root inside the container, which means they can access nftables in the container. One of many reasons running as root inside a container is a bad idea.
- worthless-trash 5y agoWho would have thought it ! Where are these admins who demand this configuration ?
- cpuguy83 5y agoMost containers would not have CAP_NET_ADMIN and not be able to access nftables.
- lmns 5y agoMy understanding is that containers actually can access nftables with CLONE_NEWUSER even without CAP_NET_ADMIN. EDIT: Apparently the Docker default capabilities don't allow CLONE_NEWUSER: https://opensource.com/business/15/3/docker-security-tuning https://opensource.com/business/15/3/docker-security-tuning