Linux PolkitȨÏÞÌáÉýÎó²î£¨CVE-2021-3560£©
Ðû²¼Ê±¼ä 2021-06-110x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-3560 | ʱ ¼ä | 2021-06-11 |
Àà ÐÍ | LPE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ·ñ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | µÍ |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà |
0x01 Îó²îÏêÇé
PolkitÊÇÐí¶àLinux ¿¯ÐаæÉÏĬÈÏ×°ÖõÄϵͳЧÀÍ£¬£¬£¬£¬Ëü±»systemdʹÓ㬣¬£¬£¬ÒÔÊÇÈκÎʹÓÃsystemdµÄLinux¿¯Ðа涼»áʹÓÃpolkit¡£¡£¡£
2021Äê06ÔÂ03ÈÕ£¬£¬£¬£¬RedHatÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬ÐÞ¸´ÁËLinux PolkitÖÐÒ»¸ö±£´æÁË7ÄêµÄȨÏÞÌáÉýÎó²î£¨CVE-2021-3560£©£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»»ñµÃϵͳÉ쵀 root ȨÏÞ¡£¡£¡£ÏÖÔÚGitHubµÄÇå¾²Ñо¿Ô±ÒѾ¹ûÕæÅû¶ÁË´ËÎó²îµÄϸ½ÚºÍPoC¡£¡£¡£
Îó²îϸ½Ú
¸ÃÎó²îÊÇÓÉÓÚµ±ÇëÇóÀú³ÌÔÚŲÓÃpolkit_system_bus_name_get_creds_sync ֮ǰÓë dbus-daemon ¶Ï¿ªÅþÁ¬Ê±£¬£¬£¬£¬¸ÃÀú³ÌÎÞ·¨»ñµÃÀú³ÌµÄΨһuidºÍpid£¬£¬£¬£¬Ò²ÎÞ·¨ÑéÖ¤ÇëÇóÀú³ÌµÄȨÏÞ¡£¡£¡£
¿ÉÒÔͨ¹ýÆô¶¯dbus-sendÏÂÁÔÚ polkit ÈÔÔÚ´¦Öóͷ£ÇëÇóµÄÀú³ÌÖÐÖÕÖ¹ËüÀ´´¥·¢´ËÎó²î£¬£¬£¬£¬ÔÚÈÏÖ¤ÇëÇóÖÐÖÕÖ¹dbus-send£¨Ò»¸öÀú³Ì¼äͨѶÏÂÁ»áµ¼ÖÂÒ»¸ö¹ýʧ£¬£¬£¬£¬ÓÉÓÚpolkit½«ÒªÇóÌṩһ¸ö²»ÔÙ±£´æµÄÅþÁ¬µÄUID£¨ÓÉÓÚ¸ÃÅþÁ¬Òѱ»ÖÕÖ¹£©¡£¡£¡£¶øpolkit»áÒÔÒ»ÖÖ¹ýʧµÄ·½·¨´¦Öóͷ£´ËÎÊÌ⣺Ëü²»»á¾Ü¾øÕâ¸öÅþÁ¬ÇëÇ󣬣¬£¬£¬¶øÊǰÑÕâ¸öÇëÇóÊÓΪÀ´×ÔUIDΪ0µÄÀú³Ì¡£¡£¡£
Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬¸ÃÎó²îºÜÈÝÒ×±»Ê¹Ó㬣¬£¬£¬Ö»ÐèҪʹÓà bash¡¢kill ºÍ dbus-send µÈ±ê×¼Öն˹¤¾ßÖ´Ðм¸ÌõÏÂÁî¼´¿É¡£¡£¡£
Ó°Ïì¹æÄ£
RHEL 8
Fedora 21¼°¸ü¸ß°æ±¾
Debian testing (¡°bullseye¡±)
Ubuntu 20.04
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ´ËÎó²îÒѾÐÞ¸´£¬£¬£¬£¬½¨Òé²Î¿¼Linux¸÷¿¯Ðа汾µÄ¹Ù·½Í¨¸æÊµÊ±Éý¼¶¸üÐÂ:
RHEL 8£º
https://access.redhat.com/security/cve/CVE-2021-3560
Fedora 21¼°¸ü¸ß°æ±¾£º
https://bugzilla.redhat.com/show_bug.cgi?id=1967424
Debian testing (¡°bullseye¡±)£º
https://security-tracker.debian.org/tracker/CVE-2021-3560
Ubuntu 20.04£º
https://ubuntu.com/security/CVE-2021-3560
0x03 ²Î¿¼Á´½Ó
https://access.redhat.com/security/cve/CVE-2021-3560
https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/
https://www.theregister.com/2021/06/11/linux_polkit_package_patched/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3560
0x04 ʱ¼äÏß
2021-06-03 RedHatÐû²¼Ç徲ͨ¸æ
2021-06-11 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/