25 vulnerabilities in RTOS Zephyr, including those exploitable via ICMP packets

Researchers from NCC Group have published the results of an audit of an open-source project Zephyr, developing a real-time operating system (RTOS) aimed at equipping devices aligned with the concept of the Internet of Things (IoT). The audit identified 25 vulnerabilities in Zephyr and 1 vulnerability in MCUboot. The development of Zephyr involves contributions from companies like Intel.

A total of 6 vulnerabilities were found in the network stack, 4 in the kernel, 2 in the shell, 5 in system call handlers, 5 in the USB subsystem, and 3 in the firmware update mechanism. Two issues were assigned a critical severity level, two were high, 9 moderate, 9 low, and 4 were for consideration. The critical issues affect the IPv4 stack and the MQTT parser, while the high-risk ones involve USB mass storage and USB DFU drivers. At the time of disclosure, fixes were provided only for the 15 most dangerous vulnerabilities, leaving unresolved issues related to denial of service or shortcomings in kernel protection mechanisms.

In the IPv4 stack of the platform, a remotely exploitable vulnerability was found that causes memory corruption when processing specially crafted ICMP packets. Another serious issue was identified in the MQTT protocol parser, caused by insufficient length validation of fields in the header and potentially allowing remote code execution. Less critical issues leading to denial of service were found in the IPv6 stack and the implementation of the CoAP protocol.

The remaining issues can be exploited locally to trigger denial of service or execute code at the kernel level. Most of these vulnerabilities are related to insufficient argument checks in system calls, which may lead to reading and writing arbitrary memory areas of the kernel. The problems also encompass the system call handling code itself — accessing a negative system call number leads to integer overflow. Additionally, issues were found in the implementation of ASLR (address space layout randomization) protection and the mechanism for setting canary values on the stack, rendering these mechanisms ineffective.

Many issues affect the USB stack and individual drivers. For example, a problem in USB mass storage allows a buffer overflow and the execution of code at the kernel level when a device is connected to a malicious USB host. A vulnerability in USB DFU, the driver for loading new firmware over USB, permits the upload of a modified firmware image to the internal Flash of a microcontroller without the use of encryption and bypassing secure boot mode with component verification via digital signatures. Additionally, the code of the open bootloader has been studied. MCUboot, in which one non-critical vulnerability was found,
that may lead to a buffer overflow when using the SMP (Simple Management Protocol) over UART.

It is worth noting that in Zephyr, all processes share a single global shared virtual address space (SASOS, Single Address Space Operating System). Application-specific code is combined with a kernel adapted for the specific application to form a monolithic executable file for loading and running on specific hardware. All system resources are defined at compile time, which reduces code size and increases performance. Only those kernel features required for running the application can be included in the system image.

Notably, one of the key advantages of Zephyr it mentions is its security-focused development. It is claimed, that all stages of development undergo mandatory security code validation phases: fuzz testing, static analysis, penetration testing, code reviews, backdoor injection analysis, and threat modeling.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster