Linux KernelÐÅϢй¶·ì϶£¨CVE-2020-28588£©

°ä²¼¹¦·ò 2021-04-28

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2020-28588

ʱ    ¼ä

2021-04-28

Àà   ÐÍ

ÐÅϢй¶

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ


Ó°ÏìÁìÓò


PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

2021Äê04ÔÂ27ÈÕ£¬Cisco Talos¹«¿ªÅû¶ÁËÔÚLinuxÄÚºËÖз¢ÏÖµÄÒ»¸öÐÅϢй¶·ì϶ £¨CVE-2020-28588£©¡£¸Ã·ì϶´æÔÚÓÚÔËÐÐLinuxµÄ32λARMÉ豸µÄ/proc/pid/syscallÖ°ÄÜÖУ¬ÓÉÓÚÊýÖ·àÐÍÖ®¼äµÄÃýÎóת»»£¬¹¥»÷ÕßÄܹ»Í¨¹ý¶ÁÈ¡/proc/<pid>/syscallÎļþÀ´ÀûÓô˷ì϶£¬ÒԲ鿴Äں˲ֿâÄÚ´æÐÅÏ¢»òͨ¹ý´Ë·ì϶À´ÀûÓÃÆäËü佨¸´µÄLinux·ì϶¡£

´Ë±í£¬¹¥»÷Õß»¹Äܹ»Í¨¹ý´ËÐÅϢй¶·ìÏ¶ÈÆ¹ýKASLR¡£Äں˵ØÖ·¿Õ¼ä²¼¾ÖËæ»ú»¯£¨KASLR£©ÊÇÒ»ÖÖ·´ÀûÓü¼Êõ£¬Äܹ»½«¸÷Àà¶ÔÏóËæ»ú¸éÖã¬ÒÔÔ¤·À±»¹¥»÷Õ߲²â¡£

 

·ì϶ϸ½Ú

/ProcÊÇÀàUnixϵͳÖеÄÒ»¸öÌØÊâµÄÐé¹¹Îļþϵͳ£¬ÓÃÓÚ¶¯Ì¬µØ½Ó¼ûÄÚºËÖеĹý³ÌÊý¾Ý¡£ËüÒÔÀàËÆÓÚÎļþµÄµµ´Î½á¹¹ÏÔʾÓйعý³ÌµÄÐÅÏ¢ºÍÆäËüϵͳÐÅÏ¢¡£ÀýÈ磬ËüÔ̺¬/proc/[pid]×ÓĿ¼£¬Ã¿¸ö×ÓĿ¼¶¼Ô̺¬ÎļþºÍ×ÓĿ¼£¬ÕâЩÎļþºÍ×ÓĿ¼Ô̺¬ÁËÓйØÌض¨¹ý³ÌµÄÐÅÏ¢£¬¶øÕâЩÐÅÏ¢Äܹ»Í¨¹ýʹÓÃÏàÓ¦µÄ¹ý³ÌIDÀ´¶ÁÈ¡¡£syscall ÎļþÊÇÒ»¸öºÏ·¨µÄLinuxϵͳÎļþ£¬ËüÔ̺¬ÄÚºËʹÓõÄϵͳŲÓÃÈÕÖ¾¡£

/proc/pid/syscallÎļþ»á¶³öϵͳŲÓúÅÂëºÍµ±Ç°¹ý³ÌÔÚÖ´ÐеÄϵͳŲÓõIJÎÊý¼Ä·ÅÆ÷£¬ÒÔ¼°²Ö¿âÖ¸ÕëºÍ·¨Ê½¼ÆÊýÆ÷¼Ä·ÅÆ÷µÄÖµ¡£¹ÌÈ»´óÎÞÊýϵͳŲÓÃʹÓÃµÄ¼Ä·ÅÆ÷½ÏÉÙ£¬µ«ËùÓеÄÁù¸ö²ÎÊý¼Ä·ÅÆ÷µÄÖµ³ÇÊб»Â¶³ö¡£

¹¥»÷ÕßÄܹ»Í¨¹ý¶ÁÈ¡/proc/<pid>/syscallÎļþÀ´²é¿´ÄÚºËÄÚ´æÐÅÏ¢£¬ÕâÄܹ»ÔÚÄÚºËÅäÖÃÁËCONFIG_HAVE_ARCH_TRACEHOOKµÄÈκÎÌØ¶¨LinuxϵͳÉÏ¿´µ½Êä³ö£¬µ«¹¥»÷ÎÞ·¨ÔÚÔ¶³ÌÍøÂçÉϽøÐмì²â¡£

´¥·¢¸Ã·ì϶µÄshellºÅÁîΪ£º

# echo 0 > /proc/sys/kernel/randomize_va_space (# only needed for a cleaner output)

$ while true; do cat /proc/self/syscall; done | uniq (# waits for changes)

$ while true; do free &>/dev/null; done (# triggers changes)

 

×êÑÐÈËÔ±Ê×ÏÈÔÚAzure SphereÉ豸£¨°æ±¾20.10£¬32λARMÉ豸£©ÉÏ·¢ÏÖÁËÕâ¸ö·ì϶£¬¸ÃÉ豸ÔËÐдòÁËÒ»¸ö²¹¶¡µÄLinuxÄںˡ£Õâ¸ö·ì϶ÔÚv5.1-rc4£¨ÌύΪ631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0£©ÖÐÒѾ­±»ÒýÈ룬µ«ÔÚv5.10-rc4ÖÐÒÀÈ»´æÔÚ£¬ËùÒÔÕâÖÐÑëµÄËùÓа汾ºÜ¿ÉÄܶ¼Êܵ½Ó°Ïì¡£

 

Ó°ÏìÁìÓò

v5.1-rc4 - v5.10-rc4

ÒѲâÊÔ°æ±¾£º

Linux Kernel v5.10-rc4

Linux Kernel v5.4.66

Linux Kernel v5.9.8

 

0x02 ´ëÖý¨Òé

½¨ÒéÉý¼¶µ½×îа汾¡£

ÏÂÔØÁ´½Ó£º

https://cdn.kernel.org/pub/linux/kernel/v5.x/linux-5.12.tar.xz

 

0x03 ²Î¿¼Á´½Ó

https://blog.talosintelligence.com/2021/04/vuln-spotlight-linux-kernel.html

https://talosintelligence.com/vulnerability_reports/TALOS-2020-1211

https://threatpost.com/linux-kernel-bug-wider-cyberattacks/165640/

 

0x04 ¹¦·òÏß

2021-04-27  Cisco Talos¹«¿ª·ì϶

2021-04-28  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png