¡¾Îó²îͨ¸æ¡¿Linux Kernel ÍâµØÈ¨ÏÞÌáÉýÎó²î£¨CVE-2021-33909£©
Ðû²¼Ê±¼ä 2021-07-210x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-33909 | ʱ ¼ä | 2021-07-21 |
Àà ÐÍ | LPE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | Ó°Ïì¹æÄ£ | ||
¹¥»÷ÖØÆ¯ºó | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà |
0x01 Îó²îÏêÇé
2021Äê7ÔÂ20ÈÕ£¬£¬£¬£¬QualysÑо¿ÍŶӹûÕæÅû¶ÁËÔÚLinux ÄÚºËÎļþϵͳ²ãÖз¢Ã÷µÄÒ»¸öÍâµØÌáȨÎó²î£¨CVE-2021-33909£¬£¬£¬£¬Ò²³ÆÎªSequoia£©ºÍsystemd (PID 1) ÖеÄÒ»¸ö¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2021-33910£© ¡£¡£¡£¡£
Linux Kernel ÍâµØÌáȨÎó²î£¨CVE-2021-33909£©
Linux ÄÚºËÎļþϵͳ²ãÖб£´æsize_t-to-int ÀàÐÍת»»Îó²î¡£¡£¡£¡£ÓÉÓÚfs/seq_file.c ûÓÐ׼ȷÏÞÖÆ seq »º³åÇø·ÖÅÉ£¬£¬£¬£¬´Ó¶øµ¼ÖÂÕûÊýÒç³ö¡¢Ô½½çдÈëÒÔ¼°È¨ÏÞÌáÉý¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÔÚĬÈÏÉèÖÃÖÐʹÓôËÎó²î£¬£¬£¬£¬×îÖÕ¿ÉÒÔÔÚÊÜÓ°ÏìÖ÷»úÉÏ»ñµÃroot ȨÏÞ¡£¡£¡£¡£Îó²îÓ°ÏìÁË×Ô 2014 ÄêÒÔÀ´Ðû²¼µÄËùÓÐ Linux Äں˰汾¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Linux kernel 3.16 - 5.13.x£¨5.13.4֮ǰ£©
Systemd(PID 1)¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2021-33910£©
systemdÊǰüÀ¨ÔÚ´ó´ó¶¼»ùÓÚ Linux ϵͳÖеÄÈí¼þÌ×¼þ£¬£¬£¬£¬ËüÌṩÁËÒ»¸öϵͳºÍЧÀÍÖÎÀíÆ÷£¬£¬£¬£¬×÷Ϊ PID 1 ÔËÐв¢Æô¶¯ÏµÍ³µÄÆäÓಿ·Ö¡£¡£¡£¡£
¸ÃÎó²îÓÉsystemd v220£¨2015Äê4Ô£©Ìá½»µÄ7410616c£¨¡°½¹µã£º·µ¹¤µ¥Î»Ãû³ÆÑéÖ¤ºÍ²Ù×÷Âß¼¡±£©ÒýÈ룬£¬£¬£¬¸ÃÎó²î½«¶ÑÖеÄstrdup()Ìæ»»Îª¶ÑÖеÄstrdupa()¡£¡£¡£¡£ºÎ·ÇÌØÈ¨Óû§¶¼¿ÉÒÔʹÓôËÎó²îʹ systemd Í߽⣬£¬£¬£¬´Ó¶øÊ¹Õû¸öϵͳÍ߽⣨ÄÚºËÍ߽⣩£¬£¬£¬£¬µ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁË2015 Äê 4 ÔÂÖ®ºóÐû²¼µÄËùÓÐ systemd °æ±¾¡£¡£¡£¡£
Ó°Ïì¹æÄ£
systemd 220 ¨C 248
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´¡£¡£¡£¡£¼øÓÚÎó²îµÄÓ°Ïì¹æÄ£½Ï¹ã£¬£¬£¬£¬ÇÒPoCÒѾ¹ûÕæ£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶ÖÁLinux Kernel 5.13.4£¨ÓÚ2021Äê7ÔÂ20ÈÕÐû²¼£©»ò¸ü¸ß°æ±¾¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://www.kernel.org/
0x03 ²Î¿¼Á´½Ó
https://blog.qualys.com/vulnerabilities-threat-research/2021/07/20/sequoia-a-local-privilege-escalation-vulnerability-in-linuxs-filesystem-layer-cve-2021-33909
https://blog.qualys.com/vulnerabilities-threat-research/2021/07/20/cve-2021-33910-denial-of-service-stack-exhaustion-in-systemd-pid-1
https://www.bleepingcomputer.com/news/security/new-linux-kernel-bug-lets-you-get-root-on-most-modern-distros/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-07-21 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ¼øºÚµ£±£Íø
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º