Linux kernelÍâµØÌáȨÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-30

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13272£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º7.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Linux Kernel < 5.1.17


Îó²î¸ÅÊö


Linux kernelÊÇÃÀ¹úLinux»ù½ð»áÐû²¼µÄ¿ªÔ´²Ù×÷ϵͳLinuxËùʹÓõÄÄںˡ£¡£¡£¡£¡£¡£


Linux kernel 5.1.17֮ǰ°æ±¾Öб£´æÇå¾²Îó²î£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚkernel/ptrace.cÎļþµÄptrace_linkûÓÐ׼ȷ´¦Öóͷ£¶Ôƾ֤µÄ¼Í¼¡£¡£¡£¡£¡£¡£


µ±Å²ÓÃPTRACE_TRACEMEʱ£¬£¬£¬£¬ptrace_linkº¯Êý½«»ñµÃ¶Ô¸¸Àú³Ìƾ֤µÄRCUÒýÓ㬣¬£¬£¬È»ºó½«¸ÃÖ¸ÕëÖ¸Ïòget_credº¯Êý¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬¹¤¾ßstruct credµÄÉúÑÄÖÜÆÚ¹æÔò²»ÔÊÐíÎÞÌõ¼þµØ½«RCUÒýÓÃת»»ÎªÎȹÌÒýÓᣡ£¡£¡£¡£¡£


PTRACE_TRACEME»ñÈ¡¸¸Àú³ÌµÄƾ֤£¬£¬£¬£¬Ê¹ÆäÄܹ»Ïñ¸¸Àú³ÌÒ»ÑùÖ´Ðи¸Àú³ÌÄܹ»Ö´ÐеÄÖݪֲÙ×÷¡£¡£¡£¡£¡£¡£ÈôÊǶñÒâµÍȨÏÞ×ÓÀú³ÌʹÓÃPTRACE_TRACEME²¢ÇÒ¸Ã×ÓÀú³ÌµÄ¸¸Àú³Ì¾ßÓиßȨÏÞ£¬£¬£¬£¬¸Ã×ÓÀú³Ì¿É»ñÈ¡Æä¸¸Àú³ÌµÄ¿ØÖÆÈ¨²¢ÇÒʹÓÃÆä¸¸Àú³ÌµÄȨÏÞŲÓÃexecveº¯Êý½¨ÉèÒ»¸öеĸßȨÏÞÀú³Ì¡£¡£¡£¡£¡£¡£


¹¥»÷Õß×îÖÕ¿ØÖƾßÓиßȨÏÞµÄÁ½¸öÀú³Ìptrace¹ØÏµ£¬£¬£¬£¬¿ÉÒÔ±»ÓÃÀ´ptrace suid¶þ½øÖÆÎļþ²¢»ñµÃrootȨÏÞ¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


EXP£ºhttps://cxsecurity.com/issue/WLB-2019070127


ÐÞ¸´½¨Òé


1.ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6994eefb0053799d2e07cd140df6c2ea106c41ee


2.Éý¼¶Linux kernelÖÁ5.1.17ÒÔÉϰ汾¡£¡£¡£¡£¡£¡£

²Î¿¼Á´½Ó


https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6994eefb0053799d2e07cd140df6c2ea106c41ee