10 ms·
Linux Kernel Ksmbd Use-After-Free Remote Code Execution Vulnerability
- enasterosophes 4y agoIt's like a bunch of people correctly predicted a few months ago that maybe this kind of attack surface shouldn't be added into the kernel: https://news.ycombinator.com/item?id=28355754 https://news.ycombinator.com/item?id=28355754
- rektide 4y ago[flagged]
- tpush 4y agoSincerely, what the hell are you even talking about? You are literally commenting on a kernel RCE enabled by putting this stuff in the kernel!
- anonymousiam 4y agoIt's obviously a GPT-3 generated comment.
- jacquesm 4y agoIf you're lucky.
- rektide 4y agoFor an extremely limited number of users who rely on one specific use of this feature. It'll get fixed, quickly, and we'll move on. Your reaction seems way overblown to me. Maybe you are sticking to your guns here. But to me, considering the real scope of damage & threat here, this seems unfortunate, sad, avoidable, and bad, but for a new implementation of a massive sprawling wild protocol, I'd far rather we try than just throw up our hands & let bravery fold. We should do hard things, even when we can't have absolute confidence in total success.
- rektide 4y agoSo much downvoting! Make a case. Why do you all disagree so vehemently? What has you so very very concerned?
- bombcar 4y agoMaybe if you want to do SMB in kernel-space they should be using the rust bindings
- flatiron 4y agoRust is driver only…for now
- sanxiyn 4y agoWell, one thing written to test-drive Rust for Linux was in-kernel server for 9P, which is probably the closest thing to ksmbd, in-kernel server for SMB, without being identical: https://lwn.net/Articles/907685/ https://lwn.net/Articles/907685/
- ilyt 4y agoThis is hilarious: > Initially, he had started trying to replace the ksmbd server, but that turned out to not be an ideal project. if only he perservered...
- deleted 4y ago[deleted]
- howinteresting 4y agoQuite frankly any new kernel code that interacts with the network, or untrusted data in general, should use Rust to the greatest extent possible.
- dinkumthinkum 4y agoWhy? Is it because you think Rust code in the kernel is memory safe?
- howinteresting 4y agoIt is definitely, undisputably memory safer.
- usr1106 4y agoSo if it weren't in the kernel it would need to run as root, wouldn't it? That gives the attacker nearly the same rights but a much more convenient programming environment.
- fragmede 4y agoWith CAP_NET_BIND_SERVICE, it doesn't need to be run as root.
- ilyt 4y agoAnd without it can just bind socket then change UID
- usr1106 4y agoBinding to a low socket is one thing. But as a file server it needs to access many users' files. That can be done without being root, too. Reducing the attack surface on one end but weakening things a bit on the other. A net gain I might concede, but not completely black and white.
- fh973 4y agoThe kernel desperately needs a product manager, who says no.
- _8j50 4y agoSMB is a complex network protocol, implementing it without a serious bug somewhere is a serious challenge. Kerberos is another complicated protocol. You have user space FS modules, perhaps it would have been better to make it one? But at the same time you have stuff like TLS ans wireguard in the kernel (SMB is still more complicated imho). Linux being monolithic and all, I don't think there is a good answer. Hope Microkernels make a comeback.
- ryao 4y agoI am not sure what was so bad about Samba. It was performing better than ksmbd in the sequential access patterns that it typically has: https://samba.plus/blog/detail/ksmbd-a-new-in-kernel-smb-server https://samba.plus/blog/detail/ksmbd-a-new-in-kernel-smb-ser...
- _8j50 4y agoSamba also had many severe rce vulns over the years.
- ryao 4y agoIt is almost as if Linux is trying to catch up to Windows in attack surface: https://arstechnica.com/information-technology/2022/12/critical-windows-code-execution-vulnerability-went-undetected-until-now/ https://arstechnica.com/information-technology/2022/12/criti...
- trasz3 4y agoSimilar incentives and assumptions lead to similar results.
- xuhu 4y agoDo any shares have to be defined or just the module enabled for this to work ?
- ZiiS 4y agoNot my area; but it looks to me like you have to be able to mount a share; so it is only unauthenticated if you have public shares defined.
- deleted 4y ago[deleted]
- mappu 4y agoSamba outperforms ksmbd anyway - https://samba.plus/blog/detail/ksmbd-a-new-in-kernel-smb-server https://samba.plus/blog/detail/ksmbd-a-new-in-kernel-smb-ser... The main reason to use ksmbd is if you can't use GPLv3 Samba. Most PC SMB servers will still be using Samba instead of ksmbd for this reason. Ksmbd is mostly used on NAS boxes.
- anderspitman 4y agoMy main reason for wanting ksmbd is that it's tiny (a few hundred k I believe). The smallest Samba build I've seen is ~40MB, and not very portable at all. I pretty much had to use buildroot to make it work. My use case is shipping minimal Linux kernels + initramfs that can be run with QEMU. I need file sharing and SMB is the most universal protocol. I can ship the entire kernel (~5MB) and QEMU (~15MB) in less space than Samba. I would love a minimal build.
- jart 4y agoWhere can I get copies of your kernel builds and how can I run them? What's the tiniest possible one you've made?
- anderspitman 4y agoI don't have them hosted anywhere. I'd recommend playing with buildroot. It's very simple and mostly just works. Using the provided QEMU config yields a kernel that's about 5MB. I believe user space (a la BusyBox) was about another 5MB. Haven't done much tuning beyond that. Feel free to email me if you have questions.
- topspin 4y ago> My main reason for wanting ksmbd is that it's tiny That's a fine reason. Does it have to be in the kernel to be small though? From what I can see ksmpd is small because it delivers only a minimal SMB3, not because it's in-kernel. Why would a user space SMB3 be appreciably larger? Also, the performance hopes for ksmbd don't appear valid either. By adopting io_uring and splice(2) Samba now outperforms[1] ksmbd by a wide margin. Those results are a year old and may be out of date, but still, I suspect we're getting so close to the limits of hardware that it doesn't matter. Another argument for in-kernel is SMB Direct: SMB over RDMA. Yet here[2] we see io_uring is receiving the bits needed for that as well. Finally, the license issue: I can't think of a reason a GPL2/Berkeley licensed SMB3 couldn't be in user space. Where am I wrong? Is there a valid reason for this to be in kernel? I don't see one. [1] https://samba.plus/blog/detail/ksmbd-a-new-in-kernel-smb-server https://samba.plus/blog/detail/ksmbd-a-new-in-kernel-smb-ser... [2] https://lwn.net/Articles/879724/ https://lwn.net/Articles/879724/ Edit: looks like the ksmbd SMB Direct work predates the io_uring RDMA capability by a few years, so at that time SMB Direct was a legitimate reason. On the other hand send(..., MSG_ZEROCOPY) predates ksmbd...
- snvzz 4y agoYet another vulnerability and exploit that just wouldn't be possible on a well-designed system, such as Genode[0] with seL4[1]. Monolithic UNIX clones are an anachronism we are well past the time to get rid of. 0. https://genode.org/ https://genode.org/ 1. https://sel4.systems/ https://sel4.systems/
- jacquesm 4y agoPity to see this downvoted because it is a valid point. We are stuck in the past with these macro kernels and this sort of thing is a direct consequence of using them. If anything having a macro kernel makes it quite hard to shut down a module like this to determine if it was well behaved with respect to memory and because it is in the kernel any kind of compromise immediately has far reaching consequences because it breaches all of the barriers in one fell swoop.
- yjftsjthsd-h 4y ago> If anything having a macro kernel makes it quite hard to shut down a module like this to determine if it was well behaved with respect to memory Unloading modules is generally possible, but I'm not quite following what shutting it down has to do with checking memory use?
- jacquesm 4y agoUse-after-free bugs are pretty easy to figure out on shutdown because you can free the remainder of your working memory and if it turns out that you have a use-after-free there likely will be a double free in there somewhere. If not then the problem is more insidious but I've found plenty of use-after-free bugs that way.
- Sirened 4y agoMost exploited UAFs don't happen in common execution paths. They're often caused by weird races and error conditions that nobody considered to even happen. It's why things like production ASan is a lot less valuable than people would imagine: most reasonably well tested software doesn't exhibit memory corruption when used normally. So, sure, your suggested technique could be a cool way to try and catch bugs that appear under normal execution but it won't put that much of a dent in the total number of bugs.
- anderspitman 4y agoSee also https://lwn.net/Articles/871866/ https://lwn.net/Articles/871866/. I would love to see this implementation succeed (Samba is too big and not portable enough for my use case), but there have definitely been challenges.
- sanxiyn 4y agoIsn't in-kernel implementation necessarily more kernel specific? How is ksmbd more portable than Samba?
- anderspitman 4y agoSorry, portable was a poor word here. Since I'm using Linux, being built in makes it easy for me to use. But if samba shipped as a small static executable that would be even easier.
- ilyt 4y agoI guess you could shove it into container. But SMB in general is complicated mess that only gets more complicated for backward compatibility sake. Comprehensive implementation almost by definition have to be complex. Small "local users only" implementation would certainly be welcome but I don't see the benefits of keeping it in kernel.
- hsbauauvhabzb 4y agoThe css doesn’t correctly overflow text on my phone meaning half the page is not rendered. Which kernel versions are vulnerable to this?
- usr1106 4y agoIt was merged in 5.15. Does any major distro configure this in?
- usr1106 4y agoLooks like already Ubuntu 20.04 has it as a loadable module. However, it can be started only by a privileged user and it requires user space tools. So I would guess it's not running unless the sysadmin has actively configured it. Even in Linux 6.1 it is marked experimental.
- skykooler 4y agoIt seems to work for me if I rotate the phone to landscape mode.
- mangix 4y agoComments here are cute. NFS has been in the kernel for ages and works roughly the same way, kernel driver with a userland component. NFS has the advantage of having been in the kernel longer with most low hanging fruit security bugs fixed. ksmbd is brand new. Quite the expectation to have it be completely bug free. edit: wait a minute, this was fixed with kernel 5.15.61 That's at least 20 releases ago.
- jacquesm 4y agoThat's a valid observation. All of the old stuff has been battle tested and reviewed many times. Newer stuff is bound to have bugs that still have not been found. And even old stuff turns up surprises every now and then. For instance https://nvd.nist.gov/vuln/detail/CVE-2021-27363 https://nvd.nist.gov/vuln/detail/CVE-2021-27363 4300 affected kernel versions has to be a record of sorts.
- ryao 4y agoI found a buffer overflow in the OpenSolaris code a few hours ago that originated in a commit made in 2007. It predates that Linux bug by at least a year. It is amazing how many old bugs have survived to the present day. :/
- nix23 4y ago>I found a buffer overflow in the OpenSolaris code a few hours ago that originated in a commit made in 2007. That's because there is no OpenSolaris anymore....
- Sirened 4y agoThe criticism isn't that anyone expects bug free code, rather that introducing new remotely accessible attack surface to the kernel in 2022 when we know it's likely unsafe is silly. Building an SMB server in the kernel because "well, NFS was secure eventually" overlooks the fact that NFS shouldn't be in the kernel either.
- 4y ago
- rektide 4y agoI'm so glad ksmbd exists. It's such a lightweight, easy, simple way to interoperate. As someone who has been running OpenWRT & then other small embedded systems for a decade and a half, projects like Samba have been wonderful, but are massive everything-and-the-kitchen-sink (even when heavily stripped down) sized tools required to interoperate with the rest of the computing world. Being able to have a small kernel module built in radically increases the number of systems that can benefit from common interoperation, and it greatly eases the difficulty by being a targeted focused file-sharing implementation rather than the incredibly wide-ranging implementations we get in Samba. It's definitely been a bit of a challenge to make ksmbd happen. I want to be able to acknowledge problems, validate the fear people have had. But also, ksmbd feels like such a textbook example of what Steve Yeggie's thesis in Notes from the Mystery Magic Bus: > Software engineering has its own political axis, ranging from conservative to liberal. Starting from some definitions: > So we'll start with an operational definition of conservatism, from Jost et al.: "We regard political conservatism as an ideological belief system that is significantly (but not completely) related to motivational concerns having to do with the psychological management of uncertainty and fear." Today we see some validation of fear. There are problems. It's certainly an inconvenience for those relying on public shares functioning securely. Thusfar it's unclear how many people have been attacked via this, or what harm has been done: the scope of damage is unknown. But the conservative view is justified, in that there have been problems, ksmbd is causing those relying on it to have to update, or risk being attacked. Reciprocally though, I want to highlight how great this effort is. This is a novel new implementation of a complex protocol, that sits right at the hub of how systems can work together. There's a progressive, can do-ism here that is absolutely cherisable & excellent. That there are problems along the road is absolutely too something we should factor in, is a concern. It's up to everyone to take score, and to decide their alignment, what to go for & what not to. Even though today is a "bad" day for this enhancement, even though the road forward for it hasn't been without difficulty, I don't feel like it dooms the whole enterprise. Trying, to me, feels so worthwhile. The scope of impact, the actual harm of trying, seems so mild, and the doomsaying & fearmongering seems so overblown, to me.
- taspeotis 4y ago--- a/fs/ksmbd/smb2pdu.c +++ b/fs/ksmbd/smb2pdu.c @@ -2044,6 +2044,7 @@ int smb2_tree_disconnect(struct ksmbd_wo ksmbd_close_tree_conn_fds(work); ksmbd_tree_conn_disconnect(sess, tcon); + work->tcon = NULL; return 0; }
- titzer 4y agoThis should be in a Wasm sandbox. (if performance is so critical--otherwise keep it in userspace). Crazy we keep trading serious CVEs for a little perf.
- deleted 4y ago[deleted]
- the8472 4y agoWasm doesn't necessarily help if it's performance-critical because that comes with its own overhead. And the kernel component of ksmbd interacts with other parts of the kernel such as the vfs, sockets/rdma. If you had marshal all the objects into something safe before exposing them to a wasm sandbox (e.g. replacing pointers with some map keys) that'd increase the overhead further.
- pjmlp 4y agoThe sandbox doesn't protect against corruption inside of linear memory, nor exploits that take advantage of it to try out to influence code execution paths, triggering calls that shouldn't have happened in first place. Great the exploit cannot pown the host, it can nevertheless trigger damaging behaviours.
- ilyt 4y agoTo elaborate on point: "Great, the WASM-SMB server didn't crash the kernel, it can ONLY exfiltrate every single file it has access to, which is every important file because it is a file server. But don't worry, your /etc/shadow is safe!" And of course obligatory XKCD: https://xkcd.com/1200/ https://xkcd.com/1200/ I'm happy most HN users don't make anything security-important...
- quotemstr 4y agoHumans cannot write correct C, full stop
- deleted 4y ago[deleted]
- Gibbon1 4y agoI tend to agree. Really the C standard needs to be yeeted away from WG14's grasp. Because they're responsible for blocking safety related improvements.
- ryao 4y agoWhat do you call seL4, the Compcert C compiler and the tools for writing provably correct C at frama-c.org?
- quotemstr 4y agoThat's called a Chinese Room. :-) A human cannot write correct C. The theorem-prover-human system can. Unfortunately, the C apologists I observe around me are as opposed to formal methods as they are non-C languages. It's some kind of bizarre cowboy thing.
- Quekid5 4y agoI'd call that a straw man. Very little code is written that way, so it doesn't apply in practice, like... at all. Also: unless you have very specific requirements there are probably easier languages+tools to write proven-correct programs in.
- zefix 4y agoAnd we need to stop pretending we do.
- deleted 4y ago[deleted]
- habibur 4y agoThought : Oh! Linux Kernel is buggy and then read to see it's Samba related and was pretty new module introduced around 2020. For context Samba and NFS had historically been buggy or exploitable since the 90s.
- nix23 4y ago>For context Samba and NFS had historically been buggy or exploitable since the 90s. Cool then let's put it into the kernel, another buggy software? -> right into the kernel, webserver? -> Kernel...oh wait we had that. Database? -> Kernel