Vulnerabilities in Buildroot allowing code execution on the build server via a MITM attack

The Buildroot build system, aimed at creating bootable Linux environments for embedded systems, has identified six vulnerabilities that allow for changes to be made to the generated system images or to execute code at the build system level during a man-in-the-middle (MITM) interception of transit traffic. The vulnerabilities have been fixed in Buildroot releases 2023.02.8, 2023.08.4, and 2023.11.

The first five vulnerabilities (CVE-2023-45841, CVE-2023-45842, CVE-2023-45838, CVE-2023-45839, CVE-2023-45840) affect the integrity checking code for package hashes. The issues stem from the ability to use HTTP for downloading files and the absence of checksum hash files for certain packages, allowing the contents of those packages to be compromised while intercepting the build traffic. server (for example, when a user connects through a wireless network controlled by an attacker).

In particular, the aufs and aufs-util packages were loaded via HTTP and were not hash-checked. Hashes were also missing for the riscv64-elf-toolchain, versal-firmware, and mxsldr packages, which by default were loaded over HTTPS, but in case of issues would fall back to unencrypted loading from the host http://sources.buildroot.net. With the absence of ‘.hash’ files, the Buildroot toolchain considered the checks successful and processed the downloaded packages, including applying patches contained in the packages and running build scripts. Having the ability to replace the downloaded packages, an attacker could add their own patches or Makefile build files, allowing changes to be made to the resulting image or build system scripts and executing their code.

The sixth vulnerability (CVE-2023-43608) is caused by an error in the implementation of the BR_NO_CHECK_HASH_FOR functionality, which allows the disabling of hash integrity checks for selective packages. Some packages, such as the Linux kernel, U-Boot, and versal-firmware, permitted downloading the latest versions for which integrity hash checks were not yet formed. For these versions, the BR_NO_CHECK_HASH_FOR option was used to disable hash checking. The data was downloaded via HTTPS, but by default, in case of download failure, it would fall back to unencrypted access to source.buildroot.net over http://. During a MITM attack, an attacker could block the connection to the HTTPS server, causing the download to revert to http://sources.buildroot.net.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster