¡¾·çÏÕ¹«¸æ¡¿Linux KernelËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-3490£©

°ä²¼¹¦·ò 2021-08-02

0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-3490

ʱ      ¼ä

2021-05-11

Àà      ÐÍ

´úÂëÖ´ÐÐ

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

·ñ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

µÍ

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

Extended Berkeley Packet Filter£¨eBPF£©ÊÇÒ»ÖÖÄں˼¼Êõ£¨´ÓLinux 4.xÆðÍ·£©£¬£¬£¬£¬£¬£¬ÔÊÐí·¨Ê½ÔËÐжøÎÞÐèŤתÄÚºËÔ´´úÂë»òÔö³¤¶î±íµÄÄ£¿£¿ £¿£¿£¿£¿£¿é¡£¡£¡£ ¡£¡£ËüÊÇLinuxÄÚºËÖеÄÒ»ÖÖÇáÁ¿¼¶µÄɳºÐÐé¹¹»ú£¨VM£©£¬£¬£¬£¬£¬£¬Äܹ»ÔÚÆäÖÐÔËÐÐÀûÓÃÌØ¶¨ÄÚºË×ÊÔ´µÄBPF×Ö½ÚÂë¡£¡£¡£ ¡£¡£

2021Äê7ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±¹«¿ªÅû¶ÁËeBPFÖеÄÒ»¸öËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-3490£©µÄ¼¼Êõϸ½ÚºÍPoC£¬£¬£¬£¬£¬£¬²¢ÑÝʾÁËÀûÓô˷ì϶ÔÚUbuntu 20.10 ºÍ 21.04ÉÏʵÏÖLPE£¨±¾µØÈ¨ÏÞÌáÉý£©¡£¡£¡£ ¡£¡£

¸Ã·ì϶ÊÇÓÉÓÚLinuxÄÚºËÖа´Î»²Ù×÷£¨AND¡¢OR ºÍ XOR£©µÄ eBPF ALU32 Ììǵ¸ú×ÙûÓÐÕýÈ·¸üР32 λÌìǵ£¬£¬£¬£¬£¬£¬Ôì³É Linux ÄÚºËÖеÄÔ½½ç¶ÁÈ¡ºÍдÈ룬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂËÁÒâ´úÂëÖ´ÐÓ×£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ʵÏÖ±¾µØÈ¨ÏÞÌáÉý»ò»Ø¾ø·þÎñ¡£¡£¡£ ¡£¡£

 

Ó°ÏìÁìÓò

Linux kernel < v5.13-rc4

 

0x02 ´ëÖý¨Òé

Ŀǰ´Ë·ì϶ÒѾ­½¨¸´¡£¡£¡£ ¡£¡£½¨Òéʵʱ¸üÐÂÖÁv5.13-rc4£¨ÒÑÓÚ2021Äê5ÔÂ11ÈÕ°ä²¼£©»ò¸ü¸ß°æ±¾¡£¡£¡£ ¡£¡£

ÏÂÔØÁ´½Ó£º

https://www.kernel.org/

 

0x03 ²Î¿¼Á´½Ó

https://ubuntu.com/security/CVE-2021-3490

https://securityaffairs.co/wordpress/120688/hacking/cve-2021-3490-linux-kernel-bug.html?

https://github.com/chompie1337/Linux_LPE_eBPF_CVE-2021-3490

https://www.graplsecurity.com/post/kernel-pwning-with-ebpf-a-love-story


0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-08-02

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png      image.png