Linux kernel±¾µØÌáȨ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-30

? ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13272 £¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º7.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Linux Kernel < 5.1.17


·ì϶¸ÅÊö


Linux kernelÊÇÃÀ¹úLinux»ù½ð»á°ä²¼µÄ¿ªÔ´²Ù×÷ϵͳLinuxËùʹÓõÄÄںˡ£¡£¡£¡£¡£


Linux kernel 5.1.17֮ǰ°æ±¾ÖдæÔÚ°²È«·ì϶ £¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓÚkernel/ptrace.cÎļþµÄptrace_linkûÓÐÕýÈ·´¦ÖÃ¶ÔÆ¾Ö¤µÄ¼Í¼¡£¡£¡£¡£¡£


µ±Å²ÓÃPTRACE_TRACEMEʱ £¬£¬£¬£¬£¬£¬£¬£¬ptrace_linkº¯Êý½«»ñµÃ¶Ô¸¸¹ý³ÌÍ´´¦µÄRCUÒýÓà £¬£¬£¬£¬£¬£¬£¬£¬¶øºó½«¸ÃÖ¸ÕëÖ¸Ïòget_credº¯Êý¡£¡£¡£¡£¡£µ«ÊÇ £¬£¬£¬£¬£¬£¬£¬£¬¶ÔÏóstruct credµÄÉú¼ÆÖÜÆÚ¹æ¶¨²»ÔÊÐíÎÞǰÌáµØ½«RCUÒýÓÃת»»Îª²»±äÒýÓᣡ£¡£¡£¡£


PTRACE_TRACEME»ñÈ¡¸¸¹ý³ÌµÄƾ֤ £¬£¬£¬£¬£¬£¬£¬£¬Ê¹Æä¿ÉÄÜÏñ¸¸¹ý³ÌÒ»ÑùÖ´Ðи¸¹ý³Ì¿ÉÄÜÖ´Ðеĸ÷Àà²Ù×÷¡£¡£¡£¡£¡£ÈôÊǶñÒâµÍȨÏÞ×Ó¹ý³ÌʹÓÃPTRACE_TRACEME²¢ÇÒ¸Ã×Ó¹ý³ÌµÄ¸¸¹ý³ÌÓµÓиßȨÏÞ £¬£¬£¬£¬£¬£¬£¬£¬¸Ã×Ó¹ý³Ì¿É»ñÈ¡Æä¸¸¹ý³ÌµÄ½ÚÔìȨ²¢ÇÒʹÓÃÆä¸¸¹ý³ÌµÄȨÏÞŲÓÃexecveº¯Êý´´½¨Ò»¸öеĸßȨÏÞ¹ý³Ì¡£¡£¡£¡£¡£


¹¥»÷Õß×îÖÕ½ÚÔìÓµÓиßȨÏÞµÄÁ½¸ö¹ý³Ìptrace¹ØÏµ £¬£¬£¬£¬£¬£¬£¬£¬Äܹ»±»ÓÃÀ´ptrace suid¶þ½øÔìÎļþ²¢»ñµÃrootȨÏÞ¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


EXP£ºhttps://cxsecurity.com/issue/WLB-2019070127


½¨¸´½¨Òé


1.Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶ £¬£¬£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6994eefb0053799d2e07cd140df6c2ea106c41ee


2.Éý¼¶Linux kernelÖÁ5.1.17ÒÔÉϰ汾¡£¡£¡£¡£¡£

²Î¿¼Á´½Ó


https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6994eefb0053799d2e07cd140df6c2ea106c41ee