{"id":83016,"date":"2020-05-27T19:41:58","date_gmt":"2020-05-27T17:41:58","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/25-uyazvimostej-v-rtos-zephyr-v-tom-chisle-ekspluatiruemye-cherez-icmp-paket"},"modified":"2020-05-27T19:41:58","modified_gmt":"2020-05-27T17:41:58","slug":"25-uyazvimostej-v-rtos-zephyr-v-tom-chisle-ekspluatiruemye-cherez-icmp-paket","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/25-uyazvimostej-v-rtos-zephyr-v-tom-chisle-ekspluatiruemye-cherez-icmp-paket","title":{"rendered":"25 vulnerabilities in RTOS Zephyr, including those exploitable via ICMP packets","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Researchers from NCC Group <noindex><a rel=\"nofollow\" href=\"https:\/\/research.nccgroup.com\/2020\/05\/26\/research-report-zephyr-and-mcuboot-security-assessment\/\">have published<\/a><\/noindex> the results of an audit of an open-source project  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.zephyrproject.org\/\">Zephyr<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=46727\">developing<\/a><\/noindex> a real-time operating system (RTOS) aimed at equipping devices in line with the concept of 'Internet of Things' (IoT). The audit revealed <noindex><a rel=\"nofollow\" href=\"https:\/\/research.nccgroup.com\/wp-content\/uploads\/2020\/05\/NCC_Group_Zephyr_MCUboot_Research_Report_2020-05-26_v1.0.pdf\">25 vulnerabilities<\/a><\/noindex> in Zephyr and 1 vulnerability in MCUboot. The development of Zephyr involves contributions from companies like Intel. <\/p>\n<p>A total of 6 vulnerabilities were identified in the network stack, 4 in the kernel, 2 in the command shell, 5 in system call handlers, 5 in the USB subsystem, and 3 in the firmware update mechanism. Two issues were assigned a critical severity level, two \u2014 high, 9 medium, 9 \u2014 low, and 4 \u2014 for consideration. Critical issues affect the IPv4 stack and the MQTT parser, while high-risk issues involve USB mass storage and USB DFU drivers. At the time of disclosure, fixes were prepared only for the 15 most critical vulnerabilities, while issues that lead to denial-of-service or are related to shortcomings in the core's additional protection mechanisms remain unaddressed.<\/p>\n<p>In the IPv4 stack of the platform, a remotely exploitable vulnerability was found that causes memory corruption when processing specially crafted ICMP packets. Another serious issue was identified in the MQTT protocol parser, caused by insufficient length validation of fields in the header and potentially allowing remote code execution. Less critical issues leading to denial of service were found in the IPv6 stack and the implementation of the CoAP protocol.<\/p>\n<p>The remaining issues can be exploited locally to induce a denial of service or execute code at the kernel level. Most of these vulnerabilities are related to the lack of proper argument checks in system calls, potentially enabling arbitrary read and write operations in kernel memory. The problems also include direct issues in the system call handling code \u2014 accessing a negative system call number leads to integer overflow. The kernel also showed problems in the implementation of ASLR (address space layout randomization) protection and the mechanism for setting canary markers in the stack, rendering these mechanisms ineffective. <\/p>\n<p>Many issues affect the USB stack and individual drivers. For example, a problem in USB mass storage allows a buffer overflow and the execution of code at the kernel level when a device is connected to a malicious USB host. A vulnerability in USB DFU, the driver for loading new firmware over USB, permits the upload of a modified firmware image to the internal Flash of a microcontroller without the use of encryption and bypassing secure boot mode with component verification via digital signatures. Additionally, the code of the open bootloader has been studied. <noindex><a rel=\"nofollow\" href=\"https:\/\/juullabs-oss.github.io\/mcuboot\/\">MCUboot<\/a><\/noindex>, in which one non-critical vulnerability was found,<br \/>\nthat may lead to a buffer overflow when using the SMP (Simple Management Protocol) over UART.<\/p>\n<p>It is worth noting that in Zephyr, all processes share a single global shared virtual address space (SASOS, Single Address Space Operating System). Application-specific code is combined with a kernel adapted for the specific application to form a monolithic executable file for loading and running on specific hardware. All system resources are defined at compile time, which reduces code size and increases performance. Only those kernel features required for running the application can be included in the system image.<\/p>\n<p>Notably, one of the key advantages of Zephyr <noindex><a rel=\"nofollow\" href=\"https:\/\/www.osrtos.com\/rtos\/zephyr\/\">it mentions<\/a><\/noindex> is its security-focused development. <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.zephyrproject.org\/1.11.0\/security\/security-overview.html\">It is claimed<\/a><\/noindex>, that all stages of development undergo mandatory security code validation phases: fuzz testing, static analysis, penetration testing, code reviews, backdoor injection analysis, and threat modeling.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53033\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 NCC Group \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u0443\u0434\u0438\u0442\u0430 \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0435\u043a\u0442\u0430 Zephyr, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0433\u043e \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u0443\u044e \u0441\u0438\u0441\u0442\u0435\u043c\u0443 \u0440\u0435\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0432\u0440\u0435\u043c\u0435\u043d\u0438 (RTOS), \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u0443\u044e \u043d\u0430 \u043e\u0441\u043d\u0430\u0449\u0435\u043d\u0438\u0435 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0445 \u043a\u043e\u043d\u0446\u0435\u043f\u0446\u0438\u0438 &#171;\u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u0432\u0435\u0449\u0435\u0439&#187; (IoT, Internet of Things). \u0412 \u0445\u043e\u0434\u0435 \u0430\u0443\u0434\u0438\u0442\u0430 \u0431\u044b\u043b\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 25 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 Zephyr \u0438 1 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 MCUboot. \u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0430 Zephyr \u0432\u0435\u0434\u0451\u0442\u0441\u044f \u043f\u0440\u0438 \u0443\u0447\u0430\u0441\u0442\u0438\u0438 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 Intel. \u0412 \u0441\u0443\u043c\u043c\u0435 \u0431\u044b\u043b\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 6 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-83016","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 NCC Group \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u0443\u0434\u0438\u0442\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/25-uyazvimostej-v-rtos-zephyr-v-tom-chisle-ekspluatiruemye-cherez-icmp-paket\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd4725 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 RTOS Zephyr, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u044b\u0435 \u0447\u0435\u0440\u0435\u0437 ICMP-\u043f\u0430\u043a\u0435\u0442 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 NCC Group \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u0443\u0434\u0438\u0442\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/25-uyazvimostej-v-rtos-zephyr-v-tom-chisle-ekspluatiruemye-cherez-icmp-paket\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-05-27T17:41:58+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-05-27T17:41:58+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd4725 vulnerabilities in the RTOS Zephyr, including those exploitable via ICMP packet | ProHoster","description":"Researchers from NCC Group published the results of an audit.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/25-uyazvimostej-v-rtos-zephyr-v-tom-chisle-ekspluatiruemye-cherez-icmp-paket","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd4725 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 RTOS Zephyr, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u044b\u0435 \u0447\u0435\u0440\u0435\u0437 ICMP-\u043f\u0430\u043a\u0435\u0442 | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 NCC Group \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u0443\u0434\u0438\u0442\u0430.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/25-uyazvimostej-v-rtos-zephyr-v-tom-chisle-ekspluatiruemye-cherez-icmp-paket","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-05-27T17:41:58+00:00","article:modified_time":"2020-05-27T17:41:58+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"83016","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 10:51:14","updated":"2022-10-02 09:38:36","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/83016","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=83016"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/83016\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=83016"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=83016"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=83016"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}