{"id":82556,"date":"2020-05-22T19:41:55","date_gmt":"2020-05-22T17:41:55","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/kriticheskaya-uyazvimost-v-realizaczii-funkczii-memcpy-dlya-armv7-iz-sostava-glibc"},"modified":"2020-05-22T19:41:55","modified_gmt":"2020-05-22T17:41:55","slug":"kriticheskaya-uyazvimost-v-realizaczii-funkczii-memcpy-dlya-armv7-iz-sostava-glibc","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/kriticheskaya-uyazvimost-v-realizaczii-funkczii-memcpy-dlya-armv7-iz-sostava-glibc","title":{"rendered":"Critical vulnerability in the implementation of the memcpy function for ARMv7 in the Glibc package","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Security researchers from Cisco <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.talosintelligence.com\/2020\/05\/cve-2020-6096.html\">revealed<\/a><\/noindex> details <noindex><a rel=\"nofollow\" href=\"https:\/\/talosintelligence.com\/vulnerability_reports\/TALOS-2020-1019\">a vulnerability<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-6096\">CVE-2020-6096<\/a><\/noindex>) in the implementation provided in the Glibc function memcpy() for the 32-bit ARMv7 platform. The issue is caused by incorrect handling of negative values for the parameter defining the size of the memory area to be copied, due to the use of assembler optimizations that manipulate signed 32-bit integers. Calling memcpy() on ARMv7 systems with a negative size leads to incorrect comparisons of values and writes outside the boundaries of the specified buffer.<\/p>\n<p>The vulnerability can be exploited to execute code in situations where an attacker can manipulate the formation of a negative value for the variable through which the size of the data to be copied is passed (for example, going negative will occur when more than 2 GB of data is sent, but during the attack, to overflow the buffer, at least 4 GB must be transmitted). The memcpy() function is widely used in applications, and ARMv7 processors are prevalent in automotive systems, mobile, industrial, consumer, communication, and embedded devices, which could potentially become targets for attacks using Bluetooth, HD Radio\/DAB, USB, CAN bus, Wi-Fi, and other external data sources (for example, network-accessible services and applications that accept input without size limitations could be attacked).<\/p>\n<p>As an example, a working exploit is created for attacking the HTTP server embedded in automotive information systems, accessible via the car's Wi-Fi network. An external attacker can exploit the memcpy vulnerability on this server by sending a very large GET request and gain root access to the system.<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/1.bp.blogspot.com\/-jn5Ehvf41zM\/XsaUrrbL_OI\/AAAAAAAABtE\/naydd40WyaApbJtZWKMokafBH7--HTNNQCLcBGAsYHQ\/s1600\/image20.png\"><img decoding=\"async\" alt=\"Critical vulnerability in the implementation of the memcpy function for ARMv7 in the Glibc package\" src=\"\/wp-content\/uploads\/2020\/05\/b6f2cf147a6d69fe1084f6ab3eb30bc9.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>On 32-bit x86 systems, the problem does not manifest, as the memcpy implementation for this architecture correctly interprets the size variable as an unsigned integer of type size_t (in assembler code, <noindex><a rel=\"nofollow\" href=\"https:\/\/code.woboq.org\/userspace\/glibc\/sysdeps\/arm\/memcpy.S.html\">implementations<\/a><\/noindex> for ARMv7 instead of size_t it is processed as a signed integer). A fix is currently available in the form of <noindex><a rel=\"nofollow\" href=\"https:\/\/patchwork.sourceware.org\/project\/glibc\/patch\/ac494a6febda4430857df1fc31f64e19@huawei.com\/\">a patch<\/a><\/noindex>, which will be included in the August update of Glibc 2.32.<br \/>\nThe fix involves replacing the use of assembler instructions that operate on signed operands (bge and blt) with their unsigned counterparts (blo and bhs). <\/p>\n<p>The issue has not yet been resolved in <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-6096\">Debian 9 and 10<\/a><\/noindex> (it does not manifest in Debian 8), <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1820332\">Alpine<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2020\/CVE-2020-6096.html\">Ubuntu<\/a><\/noindex>, OpenEmbedded, Tizen (uses glibc).  <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2020-6096\">SUSE\/openSUSE<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.suse.com\/show_bug.cgi?id=CVE-2020-6096\">openSUSE<\/a><\/noindex> the issue does not affect them, as they do not support 32-bit ARMv7 systems. Android is not susceptible to the vulnerability, as it uses its own implementation of libc (Bionic). In <noindex><a rel=\"nofollow\" href=\"https:\/\/openwrt.org\/advisory\/start\">OpenWRT<\/a><\/noindex> most builds Musl is used by default, but glibc is also available in the repository.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53003\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cisco \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0434\u0435\u0442\u0430\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2020-6096) \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0439 \u0432 Glibc \u0444\u0443\u043d\u043a\u0446\u0438\u0438 memcpy() \u0434\u043b\u044f 32-\u0440\u0430\u0437\u0440\u044f\u0434\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b ARMv7. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u043e\u0439 \u043e\u0442\u0440\u0438\u0446\u0430\u0442\u0435\u043b\u044c\u043d\u044b\u0445 \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0439 \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430, \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u044f\u044e\u0449\u0435\u0433\u043e \u0440\u0430\u0437\u043c\u0435\u0440 \u043a\u043e\u043f\u0438\u0440\u0443\u0435\u043c\u043e\u0439 \u043e\u0431\u043b\u0430\u0441\u0442\u0438, \u0438\u0437-\u0437\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0430\u0441\u0441\u0435\u043c\u0431\u043b\u0435\u0440\u043d\u044b\u0445 \u043e\u043f\u0442\u0438\u043c\u0438\u0437\u0430\u0446\u0438\u0439, \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u0443\u044e\u0449\u0438\u0445 \u0437\u043d\u0430\u043a\u043e\u0432\u044b\u043c\u0438 32-\u0440\u0430\u0437\u0440\u044f\u0434\u043d\u044b\u043c\u0438 \u0446\u0435\u043b\u044b\u043c\u0438 \u0447\u0438\u0441\u043b\u0430\u043c\u0438. \u0412\u044b\u0437\u043e\u0432 memcpy() \u043d\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 ARMv7 \u0441 \u043e\u0442\u0440\u0438\u0446\u0430\u0442\u0435\u043b\u044c\u043d\u044b\u043c \u0440\u0430\u0437\u043c\u0435\u0440\u043e\u043c \u043f\u0440\u0438\u0432\u043e\u0434\u0438\u0442 \u043a \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u043c\u0443 \u0441\u0440\u0430\u0432\u043d\u0435\u043d\u0438\u044e \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0439 \u0438 \u0437\u0430\u043f\u0438\u0441\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":82557,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-82556","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cisco \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0434\u0435\u0442\u0430\u043b\u0438\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/kriticheskaya-uyazvimost-v-realizaczii-funkczii-memcpy-dlya-armv7-iz-sostava-glibc\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 memcpy \u0434\u043b\u044f ARMv7 \u0438\u0437 \u0441\u043e\u0441\u0442\u0430\u0432\u0430 Glibc | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cisco \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0434\u0435\u0442\u0430\u043b\u0438\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/kriticheskaya-uyazvimost-v-realizaczii-funkczii-memcpy-dlya-armv7-iz-sostava-glibc\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-05-22T17:41:55+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-05-22T17:41:55+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Critical vulnerability in the memcpy function implementation for ARMv7 within Glibc | ProHoster","description":"Security researchers from Cisco disclosed details","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/kriticheskaya-uyazvimost-v-realizaczii-funkczii-memcpy-dlya-armv7-iz-sostava-glibc","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 memcpy \u0434\u043b\u044f ARMv7 \u0438\u0437 \u0441\u043e\u0441\u0442\u0430\u0432\u0430 Glibc | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cisco \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0434\u0435\u0442\u0430\u043b\u0438","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/kriticheskaya-uyazvimost-v-realizaczii-funkczii-memcpy-dlya-armv7-iz-sostava-glibc","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-05-22T17:41:55+00:00","article:modified_time":"2020-05-22T17:41:55+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"82556","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 15:35:23","updated":"2022-09-28 08:25:32","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/82556","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=82556"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/82556\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/82557"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=82556"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=82556"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=82556"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}