¡¾Îó²îͨ¸æ¡¿Linux Kernel ÍâµØÈ¨ÏÞÌáÉýÎó²î£¨CVE-2021-33909£©

Ðû²¼Ê±¼ä 2021-07-21

0x00 Îó²î¸ÅÊö

CVE     ID

CVE-2021-33909

ʱ      ¼ä

2021-07-21

Àà     ÐÍ

LPE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ


Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

 

2021Äê7ÔÂ20ÈÕ£¬£¬£¬£¬QualysÑо¿ÍŶӹûÕæÅû¶ÁËÔÚLinux ÄÚºËÎļþϵͳ²ãÖз¢Ã÷µÄÒ»¸öÍâµØÌáȨÎó²î£¨CVE-2021-33909£¬£¬£¬£¬Ò²³ÆÎªSequoia£©ºÍsystemd (PID 1) ÖеÄÒ»¸ö¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2021-33910£© ¡£¡£¡£¡£

Linux Kernel ÍâµØÌáȨÎó²î£¨CVE-2021-33909£©

Linux ÄÚºËÎļþϵͳ²ãÖб£´æsize_t-to-int ÀàÐÍת»»Îó²î¡£¡£¡£¡£ÓÉÓÚfs/seq_file.c ûÓÐ׼ȷÏÞÖÆ seq »º³åÇø·ÖÅÉ£¬£¬£¬£¬´Ó¶øµ¼ÖÂÕûÊýÒç³ö¡¢Ô½½çдÈëÒÔ¼°È¨ÏÞÌáÉý¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÔÚĬÈÏÉèÖÃÖÐʹÓôËÎó²î£¬£¬£¬£¬×îÖÕ¿ÉÒÔÔÚÊÜÓ°ÏìÖ÷»úÉÏ»ñµÃroot ȨÏÞ¡£¡£¡£¡£Îó²îÓ°ÏìÁË×Ô 2014 ÄêÒÔÀ´Ðû²¼µÄËùÓÐ Linux Äں˰汾¡£¡£¡£¡£

Ó°Ïì¹æÄ£

Linux kernel 3.16 - 5.13.x£¨5.13.4֮ǰ£©

 

Systemd(PID 1)¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2021-33910£©

systemdÊǰüÀ¨ÔÚ´ó´ó¶¼»ùÓÚ Linux ϵͳÖеÄÈí¼þÌ×¼þ£¬£¬£¬£¬ËüÌṩÁËÒ»¸öϵͳºÍЧÀÍÖÎÀíÆ÷£¬£¬£¬£¬×÷Ϊ PID 1 ÔËÐв¢Æô¶¯ÏµÍ³µÄÆäÓಿ·Ö¡£¡£¡£¡£

¸ÃÎó²îÓÉsystemd v220£¨2015Äê4Ô£©Ìá½»µÄ7410616c£¨¡°½¹µã£º·µ¹¤µ¥Î»Ãû³ÆÑéÖ¤ºÍ²Ù×÷Âß¼­¡±£©ÒýÈ룬£¬£¬£¬¸ÃÎó²î½«¶ÑÖеÄstrdup()Ìæ»»Îª¶ÑÖеÄstrdupa()¡£¡£¡£¡£ºÎ·ÇÌØÈ¨Óû§¶¼¿ÉÒÔʹÓôËÎó²îʹ systemd Í߽⣬£¬£¬£¬´Ó¶øÊ¹Õû¸öϵͳÍ߽⣨ÄÚºËÍ߽⣩£¬£¬£¬£¬µ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁË2015 Äê 4 ÔÂÖ®ºóÐû²¼µÄËùÓÐ systemd °æ±¾¡£¡£¡£¡£

Ó°Ïì¹æÄ£

systemd 220 ¨C 248

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÕâЩÎó²îÒѾ­ÐÞ¸´¡£¡£¡£¡£¼øÓÚÎó²îµÄÓ°Ïì¹æÄ£½Ï¹ã£¬£¬£¬£¬ÇÒPoCÒѾ­¹ûÕæ£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶ÖÁLinux Kernel 5.13.4£¨ÓÚ2021Äê7ÔÂ20ÈÕÐû²¼£©»ò¸ü¸ß°æ±¾¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://www.kernel.org/

 

0x03 ²Î¿¼Á´½Ó

https://blog.qualys.com/vulnerabilities-threat-research/2021/07/20/sequoia-a-local-privilege-escalation-vulnerability-in-linuxs-filesystem-layer-cve-2021-33909

https://blog.qualys.com/vulnerabilities-threat-research/2021/07/20/cve-2021-33910-denial-of-service-stack-exhaustion-in-systemd-pid-1

https://www.bleepingcomputer.com/news/security/new-linux-kernel-bug-lets-you-get-root-on-most-modern-distros/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-07-21

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ¼øºÚµ£±£Íø

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png         image.png