{"id":100806,"date":"2021-07-21T10:22:45","date_gmt":"2021-07-21T08:22:45","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/root-uyazvimost-v-yadre-linux-i-otkaz-v-obsluzhivanii-v-systemd"},"modified":"2021-07-21T10:22:45","modified_gmt":"2021-07-21T08:22:45","slug":"root-uyazvimost-v-yadre-linux-i-otkaz-v-obsluzhivanii-v-systemd","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/root-uyazvimost-v-yadre-linux-i-otkaz-v-obsluzhivanii-v-systemd","title":{"rendered":"Root vulnerability in the Linux kernel and denial of service in systemd","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Security researchers from Qualys have disclosed details of two vulnerabilities affecting the Linux kernel and the system manager systemd. The kernel vulnerability (CVE-2021-33909) allows a local user to execute code with root privileges through manipulation of deeply nested directories.     <\/p>\n<p>The risk of the vulnerability is heightened by the fact that researchers have managed to prepare working exploits that function in Ubuntu 20.04\/20.10\/21.04, Debian 11, and Fedora 34 in default configurations. It is noted that other distributions have not been tested but could theoretically also be affected and attacked. The full exploit code is promised to be published after the issue is widely addressed, meanwhile, only a limited-functionality prototype is available that causes system crashes. The issue has been present since July 2014 and affects kernel releases starting from 3.16. The vulnerability fix was coordinated with the community and incorporated into the kernel on July 19. Major distributions have already formed package updates with the kernel (Debian, Ubuntu, Fedora, RHEL, SUSE, Arch).    <\/p>\n<p>The vulnerability arises from the lack of checking the result of the conversion from size_t to int before performing operations in the seq_file code, which creates files from a sequence of records. The absence of such checks may lead to writing outside the buffer boundaries when creating, mounting, and deleting directory structures with a very high level of nesting (path size exceeding 1 GB). Consequently, an attacker can achieve writing a 10-byte string '\/\/\/deleted' with an offset of '- 2 GB - 10 bytes', pointing to the area immediately preceding the allocated buffer.    <\/p>\n<p>The prepared exploit requires 5 GB of memory and 1 million free inodes to operate. The exploit works by creating a hierarchy of about a million nested directories via the mkdir() call to reach a file path size exceeding 1 GB. This directory is mounted via bind-mount in a separate user namespace, after which the rmdir() function is invoked to delete it. Simultaneously, a thread is created that loads a small eBPF program, which gets blocked after checking the eBPF pseudocode, but before its JIT compilation.     <\/p>\n<p>In an unprivileged user namespace, the file \/proc\/self\/mountinfo is opened, and a long path of the directory mounted via bind-mount is read, resulting in writing the string '\/\/\/deleted' in the area before the buffer starts. The position for writing this string is chosen such that it overwrites an instruction in an already checked but not yet compiled eBPF program.   <\/p>\n<p>Next, at the eBPF program level, the uncontrolled write outside the buffer is transformed into a controlled ability to read and write into other kernel structures by manipulating the btf and map_push_elem structures. As a result, the exploit determines the location of the modprobe_path[] buffer in kernel memory and overwrites it with the path '\/sbin\/modprobe', which allows the initiation of any executable file with root privileges when the request_module() call is made, for example, when creating a netlink socket.    <\/p>\n<p>Researchers suggest several workarounds that are effective only for specific exploits but do not eliminate the issue itself. It is recommended to set the parameter '\/proc\/sys\/kernel\/unprivileged_userns_clone' to 0 to prohibit mounting directories in a separate user namespace, as well as '\/proc\/sys\/kernel\/unprivileged_bpf_disabled' to 1 to prevent loading eBPF programs into the kernel.  <center>  <iframe loading=\"lazy\" title=\"Sequoia: A Local Privilege Escalation Vulnerability in Linux&#039;s Filesystem Layer (CVE-2021-33909)\" src=\"https:\/\/player.vimeo.com\/video\/577035507\" width=\"640\" height=\"360\" frameborder=\"0\" allowfullscreen><\/iframe><\/center>      <\/p>\n<p>Notably, while examining an alternative attack vector involving the use of the FUSE mechanism instead of bind-mounting to mount a large directory, researchers stumbled upon another vulnerability (CVE-2021-33910) affecting the systemd manager. It turned out that when attempting to mount a directory with a path size exceeding 8 MB via FUSE, the initialization management process (PID1) experiences stack memory exhaustion and crashes, which leads the system into a state of \u2018panic\u2019.     <\/p>\n<p>The issue arises because systemd monitors and parses the contents of \/proc\/self\/mountinfo, processing each mount point in the unit_name_path_escape() function, which performs the strdupa() operation, allocating data on the stack rather than on dynamically allocated memory. Since the maximum stack size is limited by RLIMIT_STACK, handling a very large mount point path leads to a crash of the PID1 process, halting system operation. An attack can utilize a simple FUSE module combined with mounting a directory with a deep nesting level, where the path size exceeds 8 MB.    <\/p>\n<p>The problem manifests starting with systemd 220 (April 2015), has already been resolved in the main systemd repository, and fixed in distributions (Debian, Ubuntu, Fedora, RHEL, SUSE, Arch). Notably, in the release of systemd 248, the exploit does not work due to a bug in the systemd code that causes a crash when processing \/proc\/self\/mountinfo. Interestingly, in 2018 a similar situation arose, and when trying to write an exploit for the vulnerability CVE-2018-14634 in the Linux kernel, Qualys researchers stumbled upon three critical vulnerabilities in systemd.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55528\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Qualys \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0434\u0435\u0442\u0430\u043b\u0438 \u0434\u0432\u0443\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0438\u0445 \u044f\u0434\u0440\u043e Linux \u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0439 \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440 systemd. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u044f\u0434\u0440\u0435 (CVE-2021-33909) \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u0447\u0435\u0440\u0435\u0437 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u0438 \u0441 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430\u043c\u0438 \u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u0432\u043b\u043e\u0436\u0435\u043d\u043d\u043e\u0441\u0442\u0438. \u041e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0443\u0441\u0443\u0433\u0443\u0431\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u0435\u043c, \u0447\u0442\u043e \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u043c \u0443\u0434\u0430\u043b\u043e\u0441\u044c \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u0438\u0442\u044c \u0440\u0430\u0431\u043e\u0447\u0438\u0435 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u044b, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0435 \u0432 Ubuntu 20.04\/20.10\/21.04, Debian 11 \u0438 Fedora 34 \u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-100806","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Qualys \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0434\u0435\u0442\u0430\u043b\u0438 \u0434\u0432\u0443\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0438\u0445 \u044f\u0434\u0440\u043e Linux \u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0439 \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440 systemd.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/root-uyazvimost-v-yadre-linux-i-otkaz-v-obsluzhivanii-v-systemd\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Root-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u044f\u0434\u0440\u0435 Linux \u0438 \u043e\u0442\u043a\u0430\u0437 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438 \u0432 systemd | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Qualys \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0434\u0435\u0442\u0430\u043b\u0438 \u0434\u0432\u0443\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0438\u0445 \u044f\u0434\u0440\u043e Linux \u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0439 \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440 systemd.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/root-uyazvimost-v-yadre-linux-i-otkaz-v-obsluzhivanii-v-systemd\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-07-21T08:22:45+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-07-21T08:22:45+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Root vulnerability in the Linux kernel and denial of service in systemd | ProHoster","description":"Security researchers from Qualys have revealed details of two vulnerabilities affecting the Linux kernel and the system manager systemd.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/root-uyazvimost-v-yadre-linux-i-otkaz-v-obsluzhivanii-v-systemd","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Root-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u044f\u0434\u0440\u0435 Linux \u0438 \u043e\u0442\u043a\u0430\u0437 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438 \u0432 systemd | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Qualys \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0434\u0435\u0442\u0430\u043b\u0438 \u0434\u0432\u0443\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0438\u0445 \u044f\u0434\u0440\u043e Linux \u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0439 \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440 systemd.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/root-uyazvimost-v-yadre-linux-i-otkaz-v-obsluzhivanii-v-systemd","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-07-21T08:22:45+00:00","article:modified_time":"2021-07-21T08:22:45+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"100806","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-07-21 08:37:12","updated":"2022-09-29 19:57:23","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/100806","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=100806"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/100806\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=100806"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=100806"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=100806"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}