Vulnerability in the netfilter subsystem allows for code execution at the Linux kernel level

A vulnerability (CVE-2022-25636) has been identified in Netfilter, the Linux kernel subsystem used for filtering and modifying network packets, allowing code execution at the kernel level. A proof-of-concept exploit has been reported, enabling a local user to escalate their privileges in Ubuntu 21.10 with the KASLR protection mechanism disabled. The issue manifests starting from kernel version 5.4. A fix is currently available as a patch (corrective kernel releases have not been created). Updates for packages in various distributions can be tracked on the following pages: Debian, SUSE, Ubuntu, RHEL, Fedora, Gentoo, Arch Linux.

The vulnerability is caused by a mistake in calculating the size of the array flow->rule->action.entries in the function nft_fwd_dup_netdev_offload (defined in the file net/netfilter/nf_dup_netdev.c), which can allow attacker-controlled data to be written to memory outside the allocated buffer. The error occurs when configuring 'dup' and 'fwd' rules in chains where hardware packet processing (offload) is applied. Since the overflow happens before the packet filter rule is created and offload support is checked, the vulnerability is also applicable to network devices that do not support hardware offloading, such as the loopback interface.

It is noted that the problem is relatively easy to exploit, as out-of-bounds values can overwrite the pointer to the net_device structure, and the overwritten value is returned to user space, revealing the necessary addresses for the attack in memory. Exploiting the vulnerability requires creating specific rules in nftables, which is only possible with CAP_NET_ADMIN privileges that can be obtained by an unprivileged user in a separate network namespace. The vulnerability can also be used for attacks on container isolation systems.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster