Vulnerability in the ksmbd module of the Linux kernel, allowing remote code execution

A critical vulnerability has been discovered in the ksmbd module, which includes a kernel-integrated implementation of a file server based on the SMB protocol, allowing remote execution of arbitrary code with kernel privileges. An attack can be conducted without authentication, as long as the ksmbd module is activated on the system. The issue emerged starting from kernel 5.15, released in November 2021, and has been patched in updates 5.15.61, 5.18.18, and 5.19.2, released in August 2022, without further publicity. Since a CVE identifier has not yet been assigned to this issue, detailed information about the fix in distributions is currently unavailable.

Details about the exploitation of the vulnerability have not yet been disclosed; it is only known that the vulnerability is caused by access to a previously freed memory area (Use-After-Free) due to the lack of an object existence check before performing operations on it. The problem is related to the smb2_tree_disconnect() function, which freed the memory allocated for the ksmbd_tree_connect structure, but a pointer was left that was used when processing certain external requests containing SMB2_TREE_DISCONNECT commands.

In addition to the mentioned vulnerability in ksmbd, four less severe issues have also been fixed:

  • ZDI-22-1688 — remote code execution with kernel privileges due to the lack of a check for the actual size of external data before copying it into an allocated buffer in the code handling file attributes. The risk associated with this vulnerability is mitigated by the fact that the attack can only be carried out by an authenticated user.
  • ZDI-22-1691 — remote information leakage from kernel memory due to improper input parameter verification in the SMB2_WRITE command handler (the attack can only be executed by an authenticated user).
  • ZDI-22-1687 — remote denial of service call through exhaustion of available system memory due to improper resource deallocation in the SMB2_NEGOTIATE command handler (the attack can be conducted without authentication).
  • ZDI-22-1689 — remote kernel crash call due to insufficient checking of parameters in the SMB2_TREE_CONNECT command, leading to reading from out-of-bounds memory (the attack can only be performed by an authenticated user).

Support for the operation of the SMB server using the ksmbd module is included in the Samba package starting from version 4.16.0. Unlike the user-space SMB server, ksmbd is more efficient in terms of performance, memory consumption, and integration with advanced kernel features. Ksmbd is presented as a high-performance extension to Samba, ready for use in embedded devices, and can be integrated with Samba tools and libraries if necessary. The authors of the ksmbd code are Namjae Jeon from Samsung and Hyunchul Lee from LG, with maintenance in the kernel by Steve French from Microsoft, the maintainer of the CIFS/SMB2/SMB3 subsystem in the Linux kernel and a long-time member of the Samba development team, who has made significant contributions to the implementation of SMB/CIFS protocol support in Samba and Linux.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster