{"id":100548,"date":"2021-06-20T10:22:54","date_gmt":"2021-06-20T08:22:55","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-yadre-linux-zatragivayushhaya-setevoj-protokol-can-bcm"},"modified":"2021-06-20T10:22:54","modified_gmt":"2021-06-20T08:22:55","slug":"uyazvimost-v-yadre-linux-zatragivayushhaya-setevoj-protokol-can-bcm","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-yadre-linux-zatragivayushhaya-setevoj-protokol-can-bcm","title":{"rendered":"Vulnerabilidad en el n\u00facleo de Linux que afecta al protocolo de red CAN BCM.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Se ha detectado una vulnerabilidad en el n\u00facleo de Linux (CVE-2021-3609) que permite a un usuario local elevar sus privilegios en el sistema. El problema es causado por una condici\u00f3n de carrera en la implementaci\u00f3n del protocolo CAN BCM y se manifiesta en las versiones del n\u00facleo de Linux desde 2.6.25 hasta 5.13-rc6. En las distribuciones, el problema a\u00fan no se ha corregido (RHEL, Fedora, Debian, Ubuntu, SUSE, Arch).     <\/p>\n<p>El investigador que identific\u00f3 la vulnerabilidad logr\u00f3 preparar un exploit para obtener derechos de root en sistemas con n\u00facleos Linux 5.4 y versiones m\u00e1s recientes, demostrando la posibilidad de llevar a cabo un ataque exitoso en Ubuntu 20.04.02 LTS. No se descarta la posibilidad de modificar el exploit para que funcione con n\u00facleos m\u00e1s antiguos (en el n\u00facleo 5.4, el c\u00f3digo CAN BCM (net\/can\/bcm.c) fue trasladado de hrtimer_tasklet a HRTIMER_MODE_SOFT).      <\/p>\n<p>El protocolo CAN BCM permite registrar un manejador de mensajes propio que recibe mensajes a trav\u00e9s del bus CAN (controller area network) y asociarlo a un socket de red espec\u00edfico. Cuando se recibe un mensaje entrante, se invoca la funci\u00f3n bcm_rx_handler(). El atacante puede aprovechar la condici\u00f3n de carrera y lograr el cierre del socket de red al mismo tiempo que se ejecuta bcm_rx_handler(). Al cerrarse el socket, se llama a la funci\u00f3n bcm_release(), en la cual se libera la memoria asignada para las estructuras bcm_op y bcm_sock, que contin\u00faan utiliz\u00e1ndose en el manejador bcm_rx_handler() a\u00fan en ejecuci\u00f3n. Se genera una situaci\u00f3n que conduce a un acceso a un bloque de memoria ya liberado (use-after-free).    <\/p>\n<p>El ataque consiste en abrir dos sockets CAN BCM y asociarlos a la interfaz vcan. En el primer socket se llama a sendmsg() con la bandera RX_SETUP para configurar el manejador de mensajes entrantes de CAN, y en el segundo socket se realiza una llamada a sendmsg() para enviar un mensaje al primer socket. Tras la llegada del mensaje, se activa la llamada a bcm_rx_handler(), y el atacante elige el momento adecuado para cerrar el primer socket, lo que provoca la ejecuci\u00f3n de bcm_release() y la liberaci\u00f3n de las estructuras bcm_op y bcm_sock, aunque el trabajo de bcm_rx_handler() a\u00fan no ha finalizado.   <\/p>\n<p>A trav\u00e9s de manipulaciones con el contenido de bcm_sock, un atacante puede redefinir el puntero de la funci\u00f3n sk-&gt;sk_data_ready(sk), redirigir la ejecuci\u00f3n y, utilizando t\u00e9cnicas de programaci\u00f3n orientada a retorno (ROP \u2014 Return-Oriented Programming), lograr la sobrescritura del par\u00e1metro modprobe_path y conseguir que su c\u00f3digo se ejecute con privilegios de root. Al utilizar la t\u00e9cnica ROP, el atacante no intenta colocar su c\u00f3digo en la memoria, sino que opera con fragmentos de instrucciones de m\u00e1quina que ya existen en las bibliotecas cargadas, los cuales terminan con una instrucci\u00f3n de retorno de control (generalmente, estas son las terminaciones de funciones de biblioteca). La funci\u00f3n del exploit se reduce a construir una cadena de llamadas a bloques semejantes (\"gadgets\") para obtener la funcionalidad deseada.      <center><img decoding=\"async\" alt=\"Vulnerabilidad en el n\u00facleo de Linux que afecta al protocolo de red CAN BCM.\" src=\"\/wp-content\/uploads\/2021\/06\/60534f0194a819c8401abf2ec53b3a9a.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>          <\/p>\n<p>Para realizar el ataque se requiere acceso para crear sockets CAN y una interfaz de red vcan configurada. Los permisos necesarios para llevar a cabo el ataque pueden ser obtenidos por un usuario no privilegiado en contenedores creados en sistemas con el soporte activado para espacios de nombres de identificadores de usuario (user namespaces). Por ejemplo, los espacios de nombres de usuario est\u00e1n habilitados por defecto en Ubuntu y Fedora, pero no est\u00e1n activados en Debian y RHEL.<br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55359\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-3609), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435\u043c \u0433\u043e\u043d\u043a\u0438 \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 CAN BCM \u0438 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u0445 \u044f\u0434\u0440\u0430 Linux \u0441 2.6.25 \u043f\u043e 5.13-rc6. \u0412 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u043e\u043a\u0430 \u043e\u0441\u0442\u0430\u0451\u0442\u0441\u044f \u043d\u0435\u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 (RHEL, Fedora, Debian, Ubuntu, SUSE, Arch). \u0412\u044b\u044f\u0432\u0438\u0432\u0448\u0438\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0441\u043c\u043e\u0433 \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u0438\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442 \u0434\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u043f\u0440\u0430\u0432 root [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":100549,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-100548","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-3609), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-yadre-linux-zatragivayushhaya-setevoj-protokol-can-bcm\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u044f\u0434\u0440\u0435 Linux, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0430\u044f \u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b CAN BCM | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-3609), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-yadre-linux-zatragivayushhaya-setevoj-protokol-can-bcm\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-06-20T08:22:55+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-06-20T08:22:55+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilidad en el n\u00facleo de Linux que afecta al protocolo de red CAN BCM | ProHoster","description":"Se ha encontrado una vulnerabilidad en el n\u00facleo de Linux (CVE-2021-3609) que permite a un usuario local elevar sus privilegios en el sistema.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-yadre-linux-zatragivayushhaya-setevoj-protokol-can-bcm","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u044f\u0434\u0440\u0435 Linux, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0430\u044f \u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b CAN BCM | ProHoster","og:description":"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-3609), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-yadre-linux-zatragivayushhaya-setevoj-protokol-can-bcm","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-06-20T08:22:55+00:00","article:modified_time":"2021-06-20T08:22:55+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"100548","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-06-20 08:24:40","updated":"2022-10-01 08:48:35","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/100548","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=100548"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/100548\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media\/100549"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=100548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=100548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=100548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}