Bypassing SELinux restrictions related to loading kernel modules

The ability to bypass the kernel module loading restriction implemented in the targeted SELinux rules has been demonstrated on one of the studied devices (it is not specified which device this refers to and how much the issue affects SELinux rules in firmware and distributions). The blocking of modules in the engaged SELinux rules was based on restricting access to the system call finit_module, which allows loading a module from a file and is used in utilities like insmod. At the same time, the SELinux rules did not consider the system call init_module, which can also be used to load kernel modules directly from memory buffer.

A prototype exploit has been prepared to demonstrate the method, allowing code execution at the kernel level by loading its own module and completely disabling SELinux protection, given limited root access to the system controlled by SELinux.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster