°²×¿ÍâµØÌáȨÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-10-06Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-2215£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
¸ÃÎó²îÒÑÓÚ2017Äê12ÔÂÔÚ°²×¿ÄÚºË3.18¡¢4.14¡¢4.4¡¢4.9ÖÐÐÞ¸´£¬£¬£¬µ«ÔÚºóÐø°æ±¾ÖÐÓÖÖØÐÂÒýÓᣡ£¡£¡£Æ¾Ö¤Project ZeroС×éͳ¼Æ£¬£¬£¬ÏÖÔÚ¸ÃÎó²îÆÕ±é±£´æÓÚÒÔÏÂ×°±¸ÖУº
°²×¿9ºÍ°²×¿10Ô¤ÀÀ°æ Pixel 2
»ªÎª P20
ºìÃ× 5A
ºìÃ× Note 5
СÃ× A1
Oppo A3
ĦÍÐÂÞÀ Z3
Oreo LG ϵÁÐ
ÈýÐÇ S7¡¢S8¡¢S9
×¢£ºÔËÐÐ×îа²×¿kernel°æ±¾µÄPixel 3, 3 XL, 3a²»ÊܸÃÎó²îµÄÓ°Ïì¡£¡£¡£¡£
Îó²î¸ÅÊö
¸Ã0dayÎó²îÊÇÓɹȸè Project ZeroÍŶӷ¢Ã÷µÄ£¬£¬£¬ËæºóÓɹȸèÍþвÆÊÎöÍÅ¶Ó (TAG) ֤ʵ¡£¡£¡£¡£TAGÌåÏÖ¸ÃÎó²îʹÓÿÉÄܸúÒ»¼Ò³öÊÛÎó²îºÍʹÓù¤¾ßµÄÒÔÉ«Áй«Ë¾NSOÓйأ¬£¬£¬ËæºóNSO¼¯Í޲»°È˹ûÕæ·ñ¶¨Óë¸ÃÎó²î±£´æÈκιØÏµ¡£¡£¡£¡£
¸ÃÎó²îʵÖÊÊÇÄں˴úÂëÒ»´¦UAFÎó²î£¬£¬£¬ÀÖ³ÉʹÓÿÉÒÔÔì³ÉÍâµØÈ¨ÏÞÌáÉý£¬£¬£¬²¢ÓпÉÄÜÍêÈ«¿ØÖÆÓû§×°±¸¡£¡£¡£¡£µ«ÒªÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬ÐèÒªÖª×ãÄ³Ð©ÌØ¶¨Ìõ¼þ¡£¡£¡£¡£
°²×¿¿ªÔ´ÏîÄ¿£¨AOSP£©Ò»Î»½²»°ÈËÌåÏÖ£º¡°ÔÚ°²×¿×°±¸ÉÏ£¬£¬£¬¸ÃÎó²îµÄÑÏÖØÐԺܸߣ¬£¬£¬µ«Ëü×Ô¼ºÐèҪװÖöñÒâÓ¦ÓóÌÐòÒÔ¾ÙÐÐDZÔÚʹÓᣡ£¡£¡£¹ØÓÚÆäËüǰÑÔÏòÁ¿£¬£¬£¬ÀýÈçͨ¹ýwebä¯ÀÀÆ÷£¬£¬£¬ÐèÒª¸½¼ÓÌØÁíÍâÎó²îʹÓóÌÐò×é³É¹¥»÷Á´¡£¡£¡£¡£
Îó²îÑéÖ¤
¸ÃÎó²î±£´æÓÚandroid-msm-wahoo-4.4-pie·ÖÖ§»ò¸ü¶àµÄÆäËüµØ·½£¬£¬£¬Îó²î´¥·¢ÔÚ/drivers/android/binder.cÎļþÖС£¡£¡£¡£
ÏÂͼÊÇÔÚÔËÐа²×¿10£¨Çå¾²²¹¶¡ÈÕÆÚΪ2019Äê9Ô£©µÄPixel 2Éè±¹ØÁ¬ÄPoCÑÝʾ£º
POC´úÂëÈçÏ£º
ÐÞ¸´½¨Òé
ƾ֤AOSPÉùÃ÷¸ÃÎó²îÒѾ֪ͨ¸÷°²×¿ÏàÖúͬ°é£¬£¬£¬²¹¶¡ÒÑÔÚAndroid Common KernelÉÏÌṩ¡£¡£¡£¡£Ô¤¼Æ¸÷³§É̽«ÔÚδÀ´¼¸ÌìÄÚÂ½ÐøÐû²¼¸üÐÂÐÞ²¹Îó²î¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://thehackernews.com/2019/10/android-kernel-vulnerability.html


¾©¹«Íø°²±¸11010802024551ºÅ