Ubuntu 20.10 will restrict access to dmesg

Ubuntu Developers agreed restricting access to the /usr/bin/dmesg utility only for users belonging to the "adm" group. Currently, unprivileged Ubuntu users do not have access to /var/log/kern.log, /var/log/syslog and system events in journalctl, but can view the kernel event log via dmesg.

The reason cited is the presence in the dmesg output of information that can be used by attackers to simplify the creation of exploits for privilege escalation. For example, dmesg displays a stack dump in case of failures, and it is possible to determine the addresses of structures in the kernel that can help bypass the KASLR mechanism. An attacker can use dmesg as feedback, gradually bringing the exploit to its proper form, watching the oops messages in the log after unsuccessful attack attempts.

Source: opennet.ru

Add a comment