Linux KernelÐÅϢй¶·ì϶£¨CVE-2020-28588£©
°ä²¼¹¦·ò 2021-04-280x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-28588 | ʱ ¼ä | 2021-04-28 |
Àà ÐÍ | ÐÅϢй¶ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | Ó°ÏìÁìÓò | ||
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà |
0x01 ·ì϶ÏêÇé

2021Äê04ÔÂ27ÈÕ£¬Cisco Talos¹«¿ªÅû¶ÁËÔÚLinuxÄÚºËÖз¢ÏÖµÄÒ»¸öÐÅϢй¶·ì϶ £¨CVE-2020-28588£©¡£¸Ã·ì϶´æÔÚÓÚÔËÐÐLinuxµÄ32λARMÉ豸µÄ/proc/pid/syscallÖ°ÄÜÖУ¬ÓÉÓÚÊýÖ·àÐÍÖ®¼äµÄÃýÎóת»»£¬¹¥»÷ÕßÄܹ»Í¨¹ý¶ÁÈ¡/proc/<pid>/syscallÎļþÀ´ÀûÓô˷ì϶£¬ÒԲ鿴Äں˲ֿâÄÚ´æÐÅÏ¢»òͨ¹ý´Ë·ì϶À´ÀûÓÃÆäËü佨¸´µÄLinux·ì϶¡£
´Ë±í£¬¹¥»÷Õß»¹Äܹ»Í¨¹ý´ËÐÅϢй¶·ìÏ¶ÈÆ¹ýKASLR¡£Äں˵ØÖ·¿Õ¼ä²¼¾ÖËæ»ú»¯£¨KASLR£©ÊÇÒ»ÖÖ·´ÀûÓü¼Êõ£¬Äܹ»½«¸÷Àà¶ÔÏóËæ»ú¸éÖã¬ÒÔÔ¤·À±»¹¥»÷Õ߲²⡣
·ì϶ϸ½Ú
/ProcÊÇÀàUnixϵͳÖеÄÒ»¸öÌØÊâµÄÐé¹¹Îļþϵͳ£¬ÓÃÓÚ¶¯Ì¬µØ½Ó¼ûÄÚºËÖеĹý³ÌÊý¾Ý¡£ËüÒÔÀàËÆÓÚÎļþµÄµµ´Î½á¹¹ÏÔʾÓйعý³ÌµÄÐÅÏ¢ºÍÆäËüϵͳÐÅÏ¢¡£ÀýÈ磬ËüÔ̺¬/proc/[pid]×ÓĿ¼£¬Ã¿¸ö×ÓĿ¼¶¼Ô̺¬ÎļþºÍ×ÓĿ¼£¬ÕâЩÎļþºÍ×ÓĿ¼Ô̺¬ÁËÓйØÌض¨¹ý³ÌµÄÐÅÏ¢£¬¶øÕâЩÐÅÏ¢Äܹ»Í¨¹ýʹÓÃÏàÓ¦µÄ¹ý³ÌIDÀ´¶ÁÈ¡¡£syscall ÎļþÊÇÒ»¸öºÏ·¨µÄLinuxϵͳÎļþ£¬ËüÔ̺¬ÄÚºËʹÓõÄϵͳŲÓÃÈÕÖ¾¡£
/proc/pid/syscallÎļþ»á¶³öϵͳŲÓúÅÂëºÍµ±Ç°¹ý³ÌÔÚÖ´ÐеÄϵͳŲÓõIJÎÊý¼Ä·ÅÆ÷£¬ÒÔ¼°²Ö¿âÖ¸ÕëºÍ·¨Ê½¼ÆÊýÆ÷¼Ä·ÅÆ÷µÄÖµ¡£¹ÌÈ»´óÎÞÊýϵͳŲÓÃʹÓÃµÄ¼Ä·ÅÆ÷½ÏÉÙ£¬µ«ËùÓеÄÁù¸ö²ÎÊý¼Ä·ÅÆ÷µÄÖµ³ÇÊб»Â¶³ö¡£
¹¥»÷ÕßÄܹ»Í¨¹ý¶ÁÈ¡/proc/<pid>/syscallÎļþÀ´²é¿´ÄÚºËÄÚ´æÐÅÏ¢£¬ÕâÄܹ»ÔÚÄÚºËÅäÖÃÁËCONFIG_HAVE_ARCH_TRACEHOOKµÄÈκÎÌØ¶¨LinuxϵͳÉÏ¿´µ½Êä³ö£¬µ«¹¥»÷ÎÞ·¨ÔÚÔ¶³ÌÍøÂçÉϽøÐмì²â¡£
´¥·¢¸Ã·ì϶µÄshellºÅÁîΪ£º
# echo 0 > /proc/sys/kernel/randomize_va_space (# only needed for a cleaner output)
$ while true; do cat /proc/self/syscall; done | uniq (# waits for changes)
$ while true; do free &>/dev/null; done (# triggers changes)
×êÑÐÈËÔ±Ê×ÏÈÔÚAzure SphereÉ豸£¨°æ±¾20.10£¬32λARMÉ豸£©ÉÏ·¢ÏÖÁËÕâ¸ö·ì϶£¬¸ÃÉ豸ÔËÐдòÁËÒ»¸ö²¹¶¡µÄLinuxÄںˡ£Õâ¸ö·ì϶ÔÚv5.1-rc4£¨ÌύΪ631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0£©ÖÐÒѾ±»ÒýÈ룬µ«ÔÚv5.10-rc4ÖÐÒÀÈ»´æÔÚ£¬ËùÒÔÕâÖÐÑëµÄËùÓа汾ºÜ¿ÉÄܶ¼Êܵ½Ó°Ïì¡£
Ó°ÏìÁìÓò
v5.1-rc4 - v5.10-rc4
ÒѲâÊÔ°æ±¾£º
Linux Kernel v5.10-rc4
Linux Kernel v5.4.66
Linux Kernel v5.9.8
0x02 ´ëÖý¨Òé
½¨ÒéÉý¼¶µ½×îа汾¡£
ÏÂÔØÁ´½Ó£º
https://cdn.kernel.org/pub/linux/kernel/v5.x/linux-5.12.tar.xz
0x03 ²Î¿¼Á´½Ó
https://blog.talosintelligence.com/2021/04/vuln-spotlight-linux-kernel.html
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1211
https://threatpost.com/linux-kernel-bug-wider-cyberattacks/165640/
0x04 ¹¦·òÏß
2021-04-27 Cisco Talos¹«¿ª·ì϶
2021-04-28 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ