{"id":101712,"date":"2021-10-21T10:22:53","date_gmt":"2021-10-21T08:22:53","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/raskryta-tehnika-ekspluataczii-uyazvimosti-v-tty-podsisteme-yadra-linux"},"modified":"2021-10-21T10:22:53","modified_gmt":"2021-10-21T08:22:53","slug":"raskryta-tehnika-ekspluataczii-uyazvimosti-v-tty-podsisteme-yadra-linux","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/raskryta-tehnika-ekspluataczii-uyazvimosti-v-tty-podsisteme-yadra-linux","title":{"rendered":"Technik zur Ausnutzung einer Schwachstelle im tty-Subsystem des Linux-Kernels aufgedeckt","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Forscher des Google Project Zero-Teams ver\u00f6ffentlichten eine Methode zur Ausnutzung einer Schwachstelle (CVE-2020-29661) in der Implementierung des ioctl-Handlers TIOCSPGRP aus dem tty-Subsystem des Linux-Kernels und beleuchteten ausf\u00fchrlich die Schutzmechanismen, die solche Schwachstellen blockieren k\u00f6nnten.       <\/p>\n<p>Der problematische Fehler wurde im Linux-Kernel bereits am 3. Dezember letzten Jahres behoben. Das Problem tritt in Kerneln bis zur Version 5.9.13 auf, aber die meisten Distributionen haben das Problem in Paketupdates mit Kerneln, die bereits im letzten Jahr angeboten wurden, behoben (Debian, RHEL, SUSE, Ubuntu, Fedora, Arch). Eine \u00e4hnliche Schwachstelle (CVE-2020-29660) wurde gleichzeitig in der Implementierung des ioctl-Aufrufs TIOCGSID gefunden, aber auch diese wurde bereits weitgehend behoben.      <\/p>\n<p>Das Problem wird durch einen Fehler bei der Einrichtung von Sperren verursacht, der zu einem Race Condition im Code drivers\/tty\/tty_jobctrl.c f\u00fchrt, der ausgenutzt werden konnte, um Bedingungen f\u00fcr den Zugriff auf Speicher nach dessen Freigabe (use-after-free) zu schaffen, die aus dem Benutzerspeicher durch Manipulation mit dem ioctl-Aufruf TIOCSPGRP ausgenutzt werden konnten. Ein funktionierender Exploit wurde zur Erh\u00f6hung der Berechtigungen in Debian 10 mit dem Kernel 4.19.0-13-amd64 demonstriert.      <\/p>\n<p>In dem ver\u00f6ffentlichten Artikel wird jedoch der Fokus nicht so sehr auf der Technik zur Erstellung eines funktionierenden Exploits gelegt, sondern darauf, welche Werkzeuge im Kernel existieren, um solche Schwachstellen zu sch\u00fctzen. Die Schlussfolgerung ist wenig beruhigend: Methoden wie die Segmentierung von Speicher im Heap und die Kontrolle des Zugriffs auf den Speicher nach dessen Freigabe kommen in der Praxis nicht zur Anwendung, da sie die Leistung beeintr\u00e4chtigen, und der auf CFI (Control Flow Integrity) basierende Schutz, der Exploits in sp\u00e4teren Phasen eines Angriffs blockiert, einer \u00dcberarbeitung bedarf.   <\/p>\n<p>In Bezug auf die \u00dcberlegung, was die Situation langfristig verbessern k\u00f6nnte, wird die Anwendung fortschrittlicher statischer Analysatoren oder die Verwendung von Programmiersprachen, die sicheren Umgang mit Speicher erm\u00f6glichen, wie Rust und Dialekte der Programmiersprache C mit erweiterten Annotationen (z. B. Checked C), in Betracht gezogen, um w\u00e4hrend des Build-Prozesses den Zustand von Sperren, Objekten und Zeigern zu \u00fcberpr\u00fcfen. Unter den Schutzma\u00dfnahmen wird auch die Aktivierung des Modus panic_on_oops, der \u00dcbergang von Kernelstrukturen in einen Nur-Lese-Modus und die Beschr\u00e4nkung des Zugriffs auf Systemaufrufe durch Mechanismen wie seccomp erw\u00e4hnt.<br \/>\n<br \/>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56004\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u0430\u043d\u0434\u044b Google Project Zero \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u043c\u0435\u0442\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2020-29661) \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 ioctl-\u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 TIOCSPGRP \u0438\u0437 tty-\u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u044b \u044f\u0434\u0440\u0430 Linux, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0435\u043b\u0438 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u044b \u0437\u0430\u0449\u0438\u0442\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u043b\u0438 \u0431\u044b \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043f\u043e\u0434\u043e\u0431\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438. \u0412\u044b\u0437\u044b\u0432\u0430\u044e\u0449\u0430\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u043e\u0448\u0438\u0431\u043a\u0430 \u0431\u044b\u043b\u0430 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u044f\u0434\u0440\u0435 Linux \u0435\u0449\u0451 3 \u0434\u0435\u043a\u0430\u0431\u0440\u044f \u043f\u0440\u043e\u0448\u043b\u043e\u0433\u043e \u0433\u043e\u0434\u0430. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0432 \u044f\u0434\u0440\u0430\u0445 \u0434\u043e \u0432\u0435\u0440\u0441\u0438\u0438 5.9.13, \u043d\u043e \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u043e\u0432 \u0443\u0441\u0442\u0440\u0430\u043d\u0438\u043b\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-101712","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u0430\u043d\u0434\u044b Google Project Zero \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u043c\u0435\u0442\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2020-29661) \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 ioctl-\u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 TIOCSPGRP \u0438\u0437 tty-\u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u044b \u044f\u0434\u0440\u0430 Linux, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0435\u043b\u0438 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u044b.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/raskryta-tehnika-ekspluataczii-uyazvimosti-v-tty-podsisteme-yadra-linux\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 tty-\u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Linux | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u0430\u043d\u0434\u044b Google Project Zero \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u043c\u0435\u0442\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2020-29661) \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 ioctl-\u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 TIOCSPGRP \u0438\u0437 tty-\u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u044b \u044f\u0434\u0440\u0430 Linux, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0435\u043b\u0438 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u044b.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/raskryta-tehnika-ekspluataczii-uyazvimosti-v-tty-podsisteme-yadra-linux\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-10-21T08:22:53+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-10-21T08:22:53+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Technik zur Ausnutzung einer Schwachstelle im tty-Subsystem des Linux-Kernels aufgedeckt | ProHoster","description":"Forscher des Google Project Zero-Teams haben eine Methode zur Ausnutzung der Schwachstelle (CVE-2020-29661) in der Implementierung des ioctl-Handlers TIOCSPGRP aus der tty-Subsystem des Linux-Kernels ver\u00f6ffentlicht und die Mechanismen im Detail untersucht.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/raskryta-tehnika-ekspluataczii-uyazvimosti-v-tty-podsisteme-yadra-linux","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 tty-\u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Linux | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u0430\u043d\u0434\u044b Google Project Zero \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u043c\u0435\u0442\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2020-29661) \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 ioctl-\u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 TIOCSPGRP \u0438\u0437 tty-\u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u044b \u044f\u0434\u0440\u0430 Linux, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0435\u043b\u0438 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u044b.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/raskryta-tehnika-ekspluataczii-uyazvimosti-v-tty-podsisteme-yadra-linux","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-10-21T08:22:53+00:00","article:modified_time":"2021-10-21T08:22:53+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"101712","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-10-21 08:23:00","updated":"2022-09-28 02:15:28","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/101712","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=101712"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/101712\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=101712"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=101712"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=101712"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}