Linux KernelÐÅϢй¶·ì϶£¨CVE-2020-28588£©
°ä²¼¹¦·ò 2021-04-280x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-28588 | ʱ ¼ä | 2021-04-28 |
Àà ÐÍ | ÐÅϢй¶ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | Ó°ÏìÁìÓò | ||
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà |
0x01 ·ì϶ÏêÇé

2021Äê04ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬Cisco Talos¹«¿ªÅû¶ÁËÔÚLinuxÄÚºËÖз¢ÏÖµÄÒ»¸öÐÅϢй¶·ì϶ £¨CVE-2020-28588£©¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚÔËÐÐLinuxµÄ32λARMÉ豸µÄ/proc/pid/syscallÖ°ÄÜÖУ¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÊýÖ·àÐÍÖ®¼äµÄÃýÎóת»»£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý¶ÁÈ¡/proc/<pid>/syscallÎļþÀ´ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬£¬ÒԲ鿴Äں˲ֿâÄÚ´æÐÅÏ¢»òͨ¹ý´Ë·ì϶À´ÀûÓÃÆäËü佨¸´µÄLinux·ì϶¡£¡£¡£¡£¡£¡£¡£
´Ë±í£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹Äܹ»Í¨¹ý´ËÐÅϢй¶·ìÏ¶ÈÆ¹ýKASLR¡£¡£¡£¡£¡£¡£¡£Äں˵ØÖ·¿Õ¼ä²¼¾ÖËæ»ú»¯£¨KASLR£©ÊÇÒ»ÖÖ·´ÀûÓü¼Êõ£¬£¬£¬£¬£¬£¬£¬Äܹ»½«¸÷Àà¶ÔÏóËæ»ú¸éÖ㬣¬£¬£¬£¬£¬£¬ÒÔÔ¤·À±»¹¥»÷Õ߲²⡣¡£¡£¡£¡£¡£¡£
·ì϶ϸ½Ú
/ProcÊÇÀàUnixϵͳÖеÄÒ»¸öÌØÊâµÄÐé¹¹Îļþϵͳ£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ¶¯Ì¬µØ½Ó¼ûÄÚºËÖеĹý³ÌÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ËüÒÔÀàËÆÓÚÎļþµÄµµ´Î½á¹¹ÏÔʾÓйعý³ÌµÄÐÅÏ¢ºÍÆäËüϵͳÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬ËüÔ̺¬/proc/[pid]×ÓĿ¼£¬£¬£¬£¬£¬£¬£¬Ã¿¸ö×ÓĿ¼¶¼Ô̺¬ÎļþºÍ×ÓĿ¼£¬£¬£¬£¬£¬£¬£¬ÕâЩÎļþºÍ×ÓĿ¼Ô̺¬ÁËÓйØÌض¨¹ý³ÌµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¶øÕâЩÐÅÏ¢Äܹ»Í¨¹ýʹÓÃÏàÓ¦µÄ¹ý³ÌIDÀ´¶ÁÈ¡¡£¡£¡£¡£¡£¡£¡£syscall ÎļþÊÇÒ»¸öºÏ·¨µÄLinuxϵͳÎļþ£¬£¬£¬£¬£¬£¬£¬ËüÔ̺¬ÄÚºËʹÓõÄϵͳŲÓÃÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£
/proc/pid/syscallÎļþ»á¶³öϵͳŲÓúÅÂëºÍµ±Ç°¹ý³ÌÔÚÖ´ÐеÄϵͳŲÓõIJÎÊý¼Ä·ÅÆ÷£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°²Ö¿âÖ¸ÕëºÍ·¨Ê½¼ÆÊýÆ÷¼Ä·ÅÆ÷µÄÖµ¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»´óÎÞÊýϵͳŲÓÃʹÓÃµÄ¼Ä·ÅÆ÷½ÏÉÙ£¬£¬£¬£¬£¬£¬£¬µ«ËùÓеÄÁù¸ö²ÎÊý¼Ä·ÅÆ÷µÄÖµ³ÇÊб»Â¶³ö¡£¡£¡£¡£¡£¡£¡£
¹¥»÷ÕßÄܹ»Í¨¹ý¶ÁÈ¡/proc/<pid>/syscallÎļþÀ´²é¿´ÄÚºËÄÚ´æÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÕâÄܹ»ÔÚÄÚºËÅäÖÃÁËCONFIG_HAVE_ARCH_TRACEHOOKµÄÈκÎÌØ¶¨LinuxϵͳÉÏ¿´µ½Êä³ö£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÎÞ·¨ÔÚÔ¶³ÌÍøÂçÉϽøÐмì²â¡£¡£¡£¡£¡£¡£¡£
´¥·¢¸Ã·ì϶µÄshellºÅÁîΪ£º
# echo 0 > /proc/sys/kernel/randomize_va_space (# only needed for a cleaner output)
$ while true; do cat /proc/self/syscall; done | uniq (# waits for changes)
$ while true; do free &>/dev/null; done (# triggers changes)
×êÑÐÈËÔ±Ê×ÏÈÔÚAzure SphereÉ豸£¨°æ±¾20.10£¬£¬£¬£¬£¬£¬£¬32λARMÉ豸£©ÉÏ·¢ÏÖÁËÕâ¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬¸ÃÉ豸ÔËÐдòÁËÒ»¸ö²¹¶¡µÄLinuxÄںˡ£¡£¡£¡£¡£¡£¡£Õâ¸ö·ì϶ÔÚv5.1-rc4£¨ÌύΪ631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0£©ÖÐÒѾ±»ÒýÈ룬£¬£¬£¬£¬£¬£¬µ«ÔÚv5.10-rc4ÖÐÒÀÈ»´æÔÚ£¬£¬£¬£¬£¬£¬£¬ËùÒÔÕâÖÐÑëµÄËùÓа汾ºÜ¿ÉÄܶ¼Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£
Ó°ÏìÁìÓò
v5.1-rc4 - v5.10-rc4
ÒѲâÊÔ°æ±¾£º
Linux Kernel v5.10-rc4
Linux Kernel v5.4.66
Linux Kernel v5.9.8
0x02 ´ëÖý¨Òé
½¨ÒéÉý¼¶µ½×îа汾¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://cdn.kernel.org/pub/linux/kernel/v5.x/linux-5.12.tar.xz
0x03 ²Î¿¼Á´½Ó
https://blog.talosintelligence.com/2021/04/vuln-spotlight-linux-kernel.html
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1211
https://threatpost.com/linux-kernel-bug-wider-cyberattacks/165640/
0x04 ¹¦·òÏß
2021-04-27 Cisco Talos¹«¿ª·ì϶
2021-04-28 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ