{"id":108680,"date":"2023-05-24T12:48:28","date_gmt":"2023-05-24T10:48:28","guid":{"rendered":"https:\/\/prohoster.info\/?p=108680"},"modified":"2023-05-24T16:23:52","modified_gmt":"2023-05-24T14:23:52","slug":"uyazvimosti-v-module-ksmbd-yadra-linux-pozvolyayushhie-udalyonno-vypolnit-svoj-kod","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimosti-v-module-ksmbd-yadra-linux-pozvolyayushhie-udalyonno-vypolnit-svoj-kod","title":{"rendered":"Schwachstellen im ksmbd-Modul des Linux-Kernels, die es erm\u00f6glichen, Code aus der Ferne auszuf\u00fchren","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Im Modul ksmbd, das eine in den Linux-Kernel integrierte Implementierung eines Datei-Servers auf Basis des SMB-Protokolls anbietet, wurden 14 Sicherheitsanf\u00e4lligkeiten entdeckt, von denen vier es Angreifern erm\u00f6glichen, aus der Ferne Code mit Kernel-Rechten auszuf\u00fchren. Ein Angriff kann ohne Authentifizierung durchgef\u00fchrt werden, solange das Modul ksmbd auf dem System aktiviert ist. Die Probleme traten ab Kernel 5.15 auf, in dessen Kern das Modul ksmbd aufgenommen wurde. Die Sicherheitsanf\u00e4lligkeiten wurden in den Kernel-Updates 6.3.2, 6.2.15, 6.1.28 und 5.15.112 behoben. Die Korrekturen in den Distributionen k\u00f6nnen auf den folgenden Seiten verfolgt werden: Debian, Ubuntu, Gentoo, RHEL, SUSE, Fedora, Gentoo, Arch.     <\/p>\n<p>Festgestellte Probleme:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2023-32254, CVE-2023-32250, CVE-2023-32257, CVE-2023-32258 \u2014 Remote code execution with kernel privileges due to lack of proper object locks when processing external requests containing SMB2_TREE_DISCONNECT, SMB2_SESSION_SETUP, SMB2_LOGOFF, and SMB2_CLOSE commands, resulting in an exploitable race condition. An attack can be carried out without authentication.\n<li class=\"l\"> CVE-2023-32256 \u2014 Memory content leak from kernel memory areas due to a race condition when processing SMB2_QUERY_INFO and SMB2_LOGOFF commands. An attack can be carried out without authentication.\n<li class=\"l\"> CVE-2023-32252, CVE-2023-32248 \u2014 Remote denial of service due to null pointer dereference when processing SMB2_LOGOFF, SMB2_TREE_CONNECT, and SMB2_QUERY_INFO commands. An attack can be carried out without authentication.\n<li class=\"l\"> CVE-2023-32249 \u2014 Session hijacking possibility due to insufficient isolation when processing the session identifier in multichannel mode.\n<li class=\"l\"> CVE-2023-32247, CVE-2023-32255 \u2014 Denial of service due to memory leak when processing the SMB2_SESSION_SETUP command. An attack can be carried out without authentication.\n<li class=\"l\"> CVE-2023-2593 \u2014 Denial of service due to exhaustion of available memory caused by a bug that leads to memory not being returned when processing new TCP connections. An attack can be carried out without authentication.\n<li class=\"l\"> CVE-2023-32253 \u2014 Denial of service due to a deadlock occurring when processing the SMB2_SESSION_SETUP command. An attack can be carried out without authentication.\n<li class=\"l\"> CVE-2023-32251 \u2014 Lack of protection against authentication parameter guessing attacks (brute force).\n<li class=\"l\"> CVE-2023-32246 \u2014 A local user of the system with the ability to unload the ksmbd module can execute their code at the Linux kernel level.    <\/ul>\n<p>Dar\u00fcber hinaus wurden weitere 5 Schwachstellen im Paket ksmbd-tools festgestellt, das die f\u00fcr die Verwaltung und den Betrieb von ksmbd ben\u00f6tigten Utilities enth\u00e4lt, die im Benutzerspeicherraum ausgef\u00fchrt werden. Die gef\u00e4hrlichsten Schwachstellen (ZDI-CAN-17822, ZDI-CAN-17770, ZDI-CAN-17820, CVE bisher nicht zugewiesen) erm\u00f6glichen es einem nicht authentifizierten entfernten Angreifer, seinen Code mit Root-Rechten auszuf\u00fchren. Diese Schwachstellen resultieren aus dem Fehlen einer \u00dcberpr\u00fcfung der Gr\u00f6\u00dfe der empfangenen externen Daten, bevor diese in den Puffer im Code des Dienstes WKSSVC sowie in den Handlern LSARPC_OPNUM_LOOKUP_SID2 und SAMR_OPNUM_QUERY_USER_INFO kopiert werden. Zwei weitere Schwachstellen (ZDI-CAN-17823, ZDI-CAN-17821) k\u00f6nnen zu einem entfernten Denial-of-Service f\u00fchren, ohne dass eine Authentifizierung erforderlich ist.            <\/p>\n<p>Ksmbd wird als hochleistungsf\u00e4hige und f\u00fcr den Einsatz auf eingebetteten Ger\u00e4ten bereitgestellte Erweiterung zu Samba dargestellt, die bei Bedarf mit den Werkzeugen und Bibliotheken von Samba integriert werden kann. Die Unterst\u00fctzung f\u00fcr die Ausf\u00fchrung eines SMB-Servers mithilfe des ksmbd-Moduls ist im Samba-Paket seit Version 4.16.0 vorhanden. Im Gegensatz zum im Benutzerspeicherbereich laufenden SMB-Server ist ksmbd hinsichtlich der Leistung, des Speicherverbrauchs und der Integration mit erweiterten Kernel-Funktionalit\u00e4ten effizienter. Die Autoren des ksmbd-Codes sind Namjae Jeon von Samsung und Hyunchul Lee von LG, w\u00e4hrend die Wartung im Kernel von Steve French von Microsoft, dem Hauptverantwortlichen f\u00fcr die CIFS\/SMB2\/SMB3-Subsysteme im Linux-Kernel und einem langj\u00e4hrigen Mitglied des Samba-Entwicklungsteams, durchgef\u00fchrt wird, das erheblich zur Implementierung der Unterst\u00fctzung f\u00fcr die SMB\/CIFS-Protokolle in Samba und Linux beigetragen hat.      <\/p>\n<p>Zus\u00e4tzlich sind zwei Schwachstellen im Grafiktreiber vmwgfx zu erw\u00e4hnen, der f\u00fcr die Implementierung von 3D-Beschleunigung in VMware-Umgebungen verwendet wird. Die erste Schwachstelle (ZDI-CAN-20292) erm\u00f6glicht es einem lokalen Benutzer, seine Berechtigungen im System zu erh\u00f6hen. Diese Schwachstelle ergibt sich aus dem Fehlen einer \u00dcberpr\u00fcfung des Status des Buffers vor der Freigabe bei der Verarbeitung des Objekts vmw_buffer_object, was zu einem doppelten Aufruf der Funktion free f\u00fchren kann. Die zweite Schwachstelle (ZDI-CAN-20110) f\u00fchrt zu einem Leck des Speicherinhalts des Kernels aufgrund von Fehlern bei der Handhabung von Sperren von GEM-Objekten.<br \/>\n<br \/>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59189\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 ksmbd, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u044e\u0449\u0435\u043c \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u0443\u044e \u0432 \u044f\u0434\u0440\u043e Linux \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 SMB, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 14 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0447\u0435\u0442\u044b\u0440\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u044f\u0434\u0440\u0430. \u0410\u0442\u0430\u043a\u0430 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0430 \u0431\u0435\u0437 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438, \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u0447\u0442\u043e\u0431\u044b \u043d\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0431\u044b\u043b \u0430\u043a\u0442\u0438\u0432\u0438\u0440\u043e\u0432\u0430\u043d \u043c\u043e\u0434\u0443\u043b\u044c ksmbd. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 \u044f\u0434\u0440\u0430 5.15, \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u0431\u044b\u043b \u043f\u0440\u0438\u043d\u044f\u0442 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-108680","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 ksmbd, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u044e\u0449\u0435\u043c \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u0443\u044e \u0432 \u044f\u0434\u0440\u043e Linux \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 SMB, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 14 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0447\u0435\u0442\u044b\u0440\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u044f\u0434\u0440\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimosti-v-module-ksmbd-yadra-linux-pozvolyayushhie-udalyonno-vypolnit-svoj-kod\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043c\u043e\u0434\u0443\u043b\u0435 ksmbd \u044f\u0434\u0440\u0430 Linux, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 ksmbd, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u044e\u0449\u0435\u043c \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u0443\u044e \u0432 \u044f\u0434\u0440\u043e Linux \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 SMB, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 14 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0447\u0435\u0442\u044b\u0440\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u044f\u0434\u0440\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimosti-v-module-ksmbd-yadra-linux-pozvolyayushhie-udalyonno-vypolnit-svoj-kod\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-05-24T10:48:28+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-05-24T14:23:52+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Sicherheitsanf\u00e4lligkeiten im Modul ksmbd des Linux-Kernels, die es erm\u00f6glichen, eigenen Code remote auszuf\u00fchren | ProHoster","description":"Im Modul ksmbd, das eine in den Linux-Kernel integrierte Implementierung eines Dateiservers auf Basis des SMB-Protokolls anbietet, wurden 14 Sicherheitsanf\u00e4lligkeiten entdeckt, von denen vier es erm\u00f6glichen, remote eigenen Code mit Kernelrechten auszuf\u00fchren.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimosti-v-module-ksmbd-yadra-linux-pozvolyayushhie-udalyonno-vypolnit-svoj-kod","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043c\u043e\u0434\u0443\u043b\u0435 ksmbd \u044f\u0434\u0440\u0430 Linux, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 | ProHoster","og:description":"\u0412 \u043c\u043e\u0434\u0443\u043b\u0435 ksmbd, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u044e\u0449\u0435\u043c \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u0443\u044e \u0432 \u044f\u0434\u0440\u043e Linux \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 SMB, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 14 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0447\u0435\u0442\u044b\u0440\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u044f\u0434\u0440\u0430.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimosti-v-module-ksmbd-yadra-linux-pozvolyayushhie-udalyonno-vypolnit-svoj-kod","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-05-24T10:48:28+00:00","article:modified_time":"2023-05-24T14:23:52+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/108680","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=108680"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/108680\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=108680"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=108680"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=108680"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}