Linux PolkitȨÏÞÌáÉýÎó²î£¨CVE-2021-3560£©

Ðû²¼Ê±¼ä 2021-06-11

0x00 Îó²î¸ÅÊö

CVE   ID

CVE-2021-3560

ʱ    ¼ä

2021-06-11

Àà    ÐÍ

LPE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

·ñ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

µÍ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

PolkitÊÇÐí¶àLinux ¿¯ÐаæÉÏĬÈÏ×°ÖõÄϵͳЧÀÍ £¬£¬£¬£¬Ëü±»systemdʹÓà £¬£¬£¬£¬ÒÔÊÇÈκÎʹÓÃsystemdµÄLinux¿¯Ðа涼»áʹÓÃpolkit¡£¡£¡£

2021Äê06ÔÂ03ÈÕ £¬£¬£¬£¬RedHatÐû²¼Ç徲ͨ¸æ £¬£¬£¬£¬ÐÞ¸´ÁËLinux  PolkitÖÐÒ»¸ö±£´æÁË7ÄêµÄȨÏÞÌáÉýÎó²î£¨CVE-2021-3560£© £¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8 £¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»»ñµÃϵͳÉ쵀 root ȨÏÞ¡£¡£¡£ÏÖÔÚGitHubµÄÇå¾²Ñо¿Ô±ÒѾ­¹ûÕæÅû¶ÁË´ËÎó²îµÄϸ½ÚºÍPoC¡£¡£¡£

 

Îó²îϸ½Ú

¸ÃÎó²îÊÇÓÉÓÚµ±ÇëÇóÀú³ÌÔÚŲÓÃpolkit_system_bus_name_get_creds_sync ֮ǰÓë dbus-daemon ¶Ï¿ªÅþÁ¬Ê± £¬£¬£¬£¬¸ÃÀú³ÌÎÞ·¨»ñµÃÀú³ÌµÄΨһuidºÍpid £¬£¬£¬£¬Ò²ÎÞ·¨ÑéÖ¤ÇëÇóÀú³ÌµÄȨÏÞ¡£¡£¡£

¿ÉÒÔͨ¹ýÆô¶¯dbus-sendÏÂÁÔÚ polkit ÈÔÔÚ´¦Öóͷ£ÇëÇóµÄÀú³ÌÖÐÖÕÖ¹ËüÀ´´¥·¢´ËÎó²î £¬£¬£¬£¬ÔÚÈÏÖ¤ÇëÇóÖÐÖÕÖ¹dbus-send£¨Ò»¸öÀú³Ì¼äͨѶÏÂÁ»áµ¼ÖÂÒ»¸ö¹ýʧ £¬£¬£¬£¬ÓÉÓÚpolkit½«ÒªÇóÌṩһ¸ö²»ÔÙ±£´æµÄÅþÁ¬µÄUID£¨ÓÉÓÚ¸ÃÅþÁ¬Òѱ»ÖÕÖ¹£©¡£¡£¡£¶øpolkit»áÒÔÒ»ÖÖ¹ýʧµÄ·½·¨´¦Öóͷ£´ËÎÊÌ⣺Ëü²»»á¾Ü¾øÕâ¸öÅþÁ¬ÇëÇó £¬£¬£¬£¬¶øÊǰÑÕâ¸öÇëÇóÊÓΪÀ´×ÔUIDΪ0µÄÀú³Ì¡£¡£¡£

Ñо¿Ö°Ô±ÌåÏÖ £¬£¬£¬£¬¸ÃÎó²îºÜÈÝÒ×±»Ê¹Óà £¬£¬£¬£¬Ö»ÐèҪʹÓà bash¡¢kill ºÍ dbus-send µÈ±ê×¼Öն˹¤¾ßÖ´Ðм¸ÌõÏÂÁî¼´¿É¡£¡£¡£

 

Ó°Ïì¹æÄ£

RHEL 8

Fedora 21¼°¸ü¸ß°æ±¾

Debian testing (¡°bullseye¡±)

Ubuntu 20.04

 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ´ËÎó²îÒѾ­ÐÞ¸´ £¬£¬£¬£¬½¨Òé²Î¿¼Linux¸÷¿¯Ðа汾µÄ¹Ù·½Í¨¸æÊµÊ±Éý¼¶¸üÐÂ:

RHEL 8£º

https://access.redhat.com/security/cve/CVE-2021-3560


Fedora 21¼°¸ü¸ß°æ±¾£º

https://bugzilla.redhat.com/show_bug.cgi?id=1967424


Debian testing (¡°bullseye¡±)£º

https://security-tracker.debian.org/tracker/CVE-2021-3560


Ubuntu 20.04£º

https://ubuntu.com/security/CVE-2021-3560

 

0x03 ²Î¿¼Á´½Ó

https://access.redhat.com/security/cve/CVE-2021-3560

https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/

https://www.theregister.com/2021/06/11/linux_polkit_package_patched/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3560

 

0x04 ʱ¼äÏß

2021-06-03  RedHatÐû²¼Ç徲ͨ¸æ

2021-06-11  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png