Linux KernelÐÅϢй¶©¶´£¨CVE-2020-28588£©

Ðû²¼Ê±¼ä 2021-04-28

0x00 ©¶´¸ÅÊö

CVE  ID

CVE-2020-28588

ʱ    ¼ä

2021-04-28

Àà   ÐÍ

ÐÅϢй¶

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ


Ó°Ï췶Χ


PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ


 

0x01 ©¶´ÏêÇé

image.png

2021Äê04ÔÂ27ÈÕ£¬Cisco Talos¹ûÈ»Åû¶ÁËÔÚLinuxÄÚºËÖз¢ÏÖµÄÒ»¸öÐÅϢй¶©¶´ £¨CVE-2020-28588£©¡£¸Ã©¶´´æÔÚÓÚÔËÐÐLinuxµÄ32λARMÉ豸µÄ/proc/pid/syscall¹¦Ð§ÖУ¬ÓÉÓÚÊýÖµÀàÐÍÖ®¼äµÄ´íÎóת»»£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¶ÁÈ¡/proc/<pid>/syscallÎļþÀ´ÀûÓôË©¶´£¬ÒÔ¼ì²ìÄں˶ÑÕ»ÄÚ´æÐÅÏ¢»òͨ¹ý´Ë©¶´À´ÀûÓÃÆäËüδÐÞ¸´µÄLinux©¶´¡£

´ËÍ⣬¹¥»÷Õß»¹¿ÉÒÔͨ¹ý´ËÐÅϢй¶©¶´ÈƹýKASLR¡£Äں˵ØÖ·¿Õ¼ä½á¹¹Ëæ»ú»¯£¨KASLR£©ÊÇÒ»ÖÖ·´ÀûÓü¼Êõ£¬¿ÉÒÔ½«ÖÖÖÖ¹¤¾ßËæ»ú·ÅÖã¬ÒÔ·ÀÖ¹±»¹¥»÷ÕßÍÆ²â¡£

 

©¶´Ï¸½Ú

/ProcÊÇÀàUnixϵͳÖеÄÒ»¸öÌØÊâµÄÐéÄâÎļþϵͳ£¬ÓÃÓÚ¶¯Ì¬µØ·ÃÎÊÄÚºËÖеĽø³ÌÊý¾Ý¡£ËüÒÔÀàËÆÓÚÎļþµÄÌõÀí½á¹¹ÏÔʾÓйؽø³ÌµÄÐÅÏ¢ºÍÆäËüϵͳÐÅÏ¢¡£ÀýÈ磬Ëü°üÂÞ/proc/[pid]×ÓĿ¼£¬Ã¿¸ö×ÓĿ¼¶¼°üÂÞÎļþºÍ×ÓĿ¼£¬ÕâЩÎļþºÍ×ÓĿ¼°üÂÞÁËÓйØÌض¨½ø³ÌµÄÐÅÏ¢£¬¶øÕâЩÐÅÏ¢¿ÉÒÔͨ¹ýʹÓÃÏàÓ¦µÄ½ø³ÌIDÀ´¶ÁÈ¡¡£syscall ÎļþÊÇÒ»¸öºÏ·¨µÄLinuxϵͳÎļþ£¬Ëü°üÂÞÄÚºËʹÓõÄϵͳµ÷ÓÃÈÕÖ¾¡£

/proc/pid/syscallÎļþ»á̻¶ϵͳµ÷ÓúÅÂëºÍµ±Ç°½ø³ÌÕýÔÚÖ´ÐеÄϵͳµ÷ÓõIJÎÊý¼Ä´æÆ÷£¬ÒÔ¼°¶ÑÕ»Ö¸ÕëºÍ·¨Ê½¼ÆÊýÆ÷¼Ä´æÆ÷µÄÖµ¡£ËäÈ»´ó¶àÊýϵͳµ÷ÓÃʹÓõļĴæÆ÷½ÏÉÙ£¬µ«ËùÓеÄÁù¸ö²ÎÊý¼Ä´æÆ÷µÄÖµ¶¼Êб»Ì»Â¶¡£

¹¥»÷Õß¿ÉÒÔͨ¹ý¶ÁÈ¡/proc/<pid>/syscallÎļþÀ´¼ì²ìÄÚºËÄÚ´æÐÅÏ¢£¬Õâ¿ÉÒÔÔÚÄÚºËÅäÖÃÁËCONFIG_HAVE_ARCH_TRACEHOOKµÄÈκÎÌØ¶¨LinuxϵͳÉÏ¿´µ½Êä³ö£¬µ«¹¥»÷ÎÞ·¨ÔÚÔ¶³ÌÍøÂçÉϽøÐмì²â¡£

´¥·¢¸Ã©¶´µÄshellÃüÁîΪ£º

# echo 0 > /proc/sys/kernel/randomize_va_space (# only needed for a cleaner output)

$ while true; do cat /proc/self/syscall; done | uniq (# waits for changes)

$ while true; do free &>/dev/null; done (# triggers changes)

 

Ñо¿ÈËÔ±Ê×ÏÈÔÚAzure SphereÉ豸£¨°æ±¾20.10£¬32λARMÉ豸£©ÉÏ·¢ÏÖÁËÕâ¸ö©¶´£¬¸ÃÉ豸ÔËÐдòÁËÒ»¸ö²¹¶¡µÄLinuxÄںˡ£Õâ¸ö©¶´ÔÚv5.1-rc4£¨ÌύΪ631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0£©ÖÐÒѾ­±»ÒýÈ룬µ«ÔÚv5.10-rc4ÖÐÈÔÈ»´æÔÚ£¬ËùÒÔÕâÖмäµÄËùÓа汾ºÜ¿ÉÄܶ¼Êܵ½Ó°Ïì¡£

 

Ó°Ï췶Χ

v5.1-rc4 - v5.10-rc4

ÒѲâÊÔ°æ±¾£º

Linux Kernel v5.10-rc4

Linux Kernel v5.4.66

Linux Kernel v5.9.8

 

0x02 ´¦Öý¨Òé

½¨ÒéÉý¼¶µ½×îа汾¡£

ÏÂÔØÁ´½Ó£º

https://cdn.kernel.org/pub/linux/kernel/v5.x/linux-5.12.tar.xz

 

0x03 ²Î¿¼Á´½Ó

https://blog.talosintelligence.com/2021/04/vuln-spotlight-linux-kernel.html

https://talosintelligence.com/vulnerability_reports/TALOS-2020-1211

https://threatpost.com/linux-kernel-bug-wider-cyberattacks/165640/

 

0x04 ʱ¼äÏß

2021-04-27  Cisco Talos¹ûȻ©¶´

2021-04-28  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png