Linux KernelÐÅϢй¶·ì϶£¨CVE-2020-28588£©

°ä²¼¹¦·ò 2021-04-28

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2020-28588

ʱ    ¼ä

2021-04-28

Àà   ÐÍ

ÐÅϢй¶

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ


Ó°ÏìÁìÓò


PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

2021Äê04ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬Cisco Talos¹«¿ªÅû¶ÁËÔÚLinuxÄÚºËÖз¢ÏÖµÄÒ»¸öÐÅϢй¶·ì϶ £¨CVE-2020-28588£©¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚÔËÐÐLinuxµÄ32λARMÉ豸µÄ/proc/pid/syscallÖ°ÄÜÖУ¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÊýÖ·àÐÍÖ®¼äµÄÃýÎóת»»£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý¶ÁÈ¡/proc/<pid>/syscallÎļþÀ´ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬£¬ÒԲ鿴Äں˲ֿâÄÚ´æÐÅÏ¢»òͨ¹ý´Ë·ì϶À´ÀûÓÃÆäËü佨¸´µÄLinux·ì϶¡£¡£¡£¡£¡£¡£¡£

´Ë±í£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹Äܹ»Í¨¹ý´ËÐÅϢй¶·ìÏ¶ÈÆ¹ýKASLR¡£¡£¡£¡£¡£¡£¡£Äں˵ØÖ·¿Õ¼ä²¼¾ÖËæ»ú»¯£¨KASLR£©ÊÇÒ»ÖÖ·´ÀûÓü¼Êõ£¬£¬£¬£¬£¬£¬£¬Äܹ»½«¸÷Àà¶ÔÏóËæ»ú¸éÖ㬣¬£¬£¬£¬£¬£¬ÒÔÔ¤·À±»¹¥»÷Õ߲²⡣¡£¡£¡£¡£¡£¡£

 

·ì϶ϸ½Ú

/ProcÊÇÀàUnixϵͳÖеÄÒ»¸öÌØÊâµÄÐé¹¹Îļþϵͳ£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ¶¯Ì¬µØ½Ó¼ûÄÚºËÖеĹý³ÌÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ËüÒÔÀàËÆÓÚÎļþµÄµµ´Î½á¹¹ÏÔʾÓйعý³ÌµÄÐÅÏ¢ºÍÆäËüϵͳÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬ËüÔ̺¬/proc/[pid]×ÓĿ¼£¬£¬£¬£¬£¬£¬£¬Ã¿¸ö×ÓĿ¼¶¼Ô̺¬ÎļþºÍ×ÓĿ¼£¬£¬£¬£¬£¬£¬£¬ÕâЩÎļþºÍ×ÓĿ¼Ô̺¬ÁËÓйØÌض¨¹ý³ÌµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¶øÕâЩÐÅÏ¢Äܹ»Í¨¹ýʹÓÃÏàÓ¦µÄ¹ý³ÌIDÀ´¶ÁÈ¡¡£¡£¡£¡£¡£¡£¡£syscall ÎļþÊÇÒ»¸öºÏ·¨µÄLinuxϵͳÎļþ£¬£¬£¬£¬£¬£¬£¬ËüÔ̺¬ÄÚºËʹÓõÄϵͳŲÓÃÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£

/proc/pid/syscallÎļþ»á¶³öϵͳŲÓúÅÂëºÍµ±Ç°¹ý³ÌÔÚÖ´ÐеÄϵͳŲÓõIJÎÊý¼Ä·ÅÆ÷£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°²Ö¿âÖ¸ÕëºÍ·¨Ê½¼ÆÊýÆ÷¼Ä·ÅÆ÷µÄÖµ¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»´óÎÞÊýϵͳŲÓÃʹÓÃµÄ¼Ä·ÅÆ÷½ÏÉÙ£¬£¬£¬£¬£¬£¬£¬µ«ËùÓеÄÁù¸ö²ÎÊý¼Ä·ÅÆ÷µÄÖµ³ÇÊб»Â¶³ö¡£¡£¡£¡£¡£¡£¡£

¹¥»÷ÕßÄܹ»Í¨¹ý¶ÁÈ¡/proc/<pid>/syscallÎļþÀ´²é¿´ÄÚºËÄÚ´æÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÕâÄܹ»ÔÚÄÚºËÅäÖÃÁËCONFIG_HAVE_ARCH_TRACEHOOKµÄÈκÎÌØ¶¨LinuxϵͳÉÏ¿´µ½Êä³ö£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÎÞ·¨ÔÚÔ¶³ÌÍøÂçÉϽøÐмì²â¡£¡£¡£¡£¡£¡£¡£

´¥·¢¸Ã·ì϶µÄshellºÅÁîΪ£º

# echo 0 > /proc/sys/kernel/randomize_va_space (# only needed for a cleaner output)

$ while true; do cat /proc/self/syscall; done | uniq (# waits for changes)

$ while true; do free &>/dev/null; done (# triggers changes)

 

×êÑÐÈËÔ±Ê×ÏÈÔÚAzure SphereÉ豸£¨°æ±¾20.10£¬£¬£¬£¬£¬£¬£¬32λARMÉ豸£©ÉÏ·¢ÏÖÁËÕâ¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬¸ÃÉ豸ÔËÐдòÁËÒ»¸ö²¹¶¡µÄLinuxÄںˡ£¡£¡£¡£¡£¡£¡£Õâ¸ö·ì϶ÔÚv5.1-rc4£¨ÌύΪ631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0£©ÖÐÒѾ­±»ÒýÈ룬£¬£¬£¬£¬£¬£¬µ«ÔÚv5.10-rc4ÖÐÒÀÈ»´æÔÚ£¬£¬£¬£¬£¬£¬£¬ËùÒÔÕâÖÐÑëµÄËùÓа汾ºÜ¿ÉÄܶ¼Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£

 

Ó°ÏìÁìÓò

v5.1-rc4 - v5.10-rc4

ÒѲâÊÔ°æ±¾£º

Linux Kernel v5.10-rc4

Linux Kernel v5.4.66

Linux Kernel v5.9.8

 

0x02 ´ëÖý¨Òé

½¨ÒéÉý¼¶µ½×îа汾¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://cdn.kernel.org/pub/linux/kernel/v5.x/linux-5.12.tar.xz

 

0x03 ²Î¿¼Á´½Ó

https://blog.talosintelligence.com/2021/04/vuln-spotlight-linux-kernel.html

https://talosintelligence.com/vulnerability_reports/TALOS-2020-1211

https://threatpost.com/linux-kernel-bug-wider-cyberattacks/165640/

 

0x04 ¹¦·òÏß

2021-04-27  Cisco Talos¹«¿ª·ì϶

2021-04-28  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png