{"id":109268,"date":"2023-07-06T03:10:18","date_gmt":"2023-07-06T01:10:18","guid":{"rendered":"https:\/\/prohoster.info\/?p=109268"},"modified":"2023-07-06T09:41:48","modified_gmt":"2023-07-06T07:41:48","slug":"uyazvimost-stackrot-v-yadre-linux-pozvolyayushhaya-povysit-svoi-privilegii","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-stackrot-v-yadre-linux-pozvolyayushhaya-povysit-svoi-privilegii","title":{"rendered":"La vuln\u00e9rabilit\u00e9 StackRot dans le noyau Linux, permettant d'\u00e9lever ses privil\u00e8ges","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>La conversion du VMA (Virtual Memory Area) dans le noyau Linux 6.1 de la structure de donn\u00e9es \u00ab arbre rouge-noir \u00bb \u00e0 \u00ab arbre d'\u00e9rable \u00bb a conduit \u00e0 l'apparition d'une vuln\u00e9rabilit\u00e9 (CVE-2023-3269), permettant \u00e0 un utilisateur non privil\u00e9gi\u00e9 d'ex\u00e9cuter son code avec les droits du noyau. La vuln\u00e9rabilit\u00e9, nomm\u00e9e StackRot, se manifeste \u00e0 partir de la version 6.1 du noyau et a \u00e9t\u00e9 corrig\u00e9e dans les mises \u00e0 jour 6.4.1, 6.3.11 et 6.1.37.     <\/p>\n<p>La structure \u00ab arbre d'\u00e9rable \u00bb est une variante des B-trees, prenant en charge l'indexation par intervalles de valeurs et con\u00e7ue pour un usage efficace du cache des processeurs modernes. Par rapport \u00e0 l'\u00ab arbre rouge-noir \u00bb, l'utilisation de l'\u00ab arbre d'\u00e9rable \u00bb permet d'obtenir de meilleures performances. La vuln\u00e9rabilit\u00e9 est caus\u00e9e par une erreur dans le gestionnaire d'extension de pile : dans la structure \u00ab arbre d'\u00e9rable \u00bb, utilis\u00e9e pour la gestion des zones de m\u00e9moire virtuelle dans le noyau, le remplacement d'un n\u0153ud dans l'arbre pouvait se produire sans verrouillage en \u00e9criture, ce qui cr\u00e9ait des conditions pour acc\u00e9der \u00e0 une zone de m\u00e9moire apr\u00e8s sa lib\u00e9ration (use-after-free).       <\/p>\n<p>L'exploitation de la vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 compliqu\u00e9e par le fait que les n\u0153uds dans la structure \u00ab arbre d'\u00e9rable \u00bb sont lib\u00e9r\u00e9s de mani\u00e8re diff\u00e9r\u00e9e en utilisant des appels de rappel avec des verrous RCU (Read-copy-update). Cependant, les chercheurs ont r\u00e9ussi \u00e0 surmonter les difficult\u00e9s rencontr\u00e9es et \u00e0 pr\u00e9parer un exploit fonctionnel, qu'ils pr\u00e9voient de publier \u00e0 la fin juillet, afin de donner aux utilisateurs le temps de mettre \u00e0 jour leurs syst\u00e8mes. L'exploitation est possible dans presque toutes les configurations du noyau et n\u00e9cessite seulement des privil\u00e8ges minimaux.<br \/>\n<br \/>Source : <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59385\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u043d\u044b\u0439 \u0432 \u044f\u0434\u0440\u0435 Linux 6.1 \u043f\u0435\u0440\u0435\u0432\u043e\u0434 VMA (Virtual Memory Area) \u0441\u043e \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u0434\u0430\u043d\u043d\u044b\u0445 &#171;red-black tree&#187; \u043d\u0430 &#171;maple tree&#187; \u043f\u0440\u0438\u0432\u0451\u043b \u043a \u043f\u043e\u044f\u0432\u043b\u0435\u043d\u0438\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-3269), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u044f\u0434\u0440\u0430. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f StackRot, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 \u0432\u044b\u043f\u0443\u0441\u043a\u0430 \u044f\u0434\u0440\u0430 6.1 \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f\u0445 6.4.1, 6.3.11 \u0438 6.1.37. \u0421\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0430 &#171;maple [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-109268","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u043d\u044b\u0439 \u0432 \u044f\u0434\u0440\u0435 Linux 6.1 \u043f\u0435\u0440\u0435\u0432\u043e\u0434 VMA (Virtual Memory Area) \u0441\u043e \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u0434\u0430\u043d\u043d\u044b\u0445 &quot;red-black tree&quot; \u043d\u0430 &quot;maple tree&quot; \u043f\u0440\u0438\u0432\u0451\u043b \u043a \u043f\u043e\u044f\u0432\u043b\u0435\u043d\u0438\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-3269), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-stackrot-v-yadre-linux-pozvolyayushhaya-povysit-svoi-privilegii\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c StackRot \u0432 \u044f\u0434\u0440\u0435 Linux, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u043d\u044b\u0439 \u0432 \u044f\u0434\u0440\u0435 Linux 6.1 \u043f\u0435\u0440\u0435\u0432\u043e\u0434 VMA (Virtual Memory Area) \u0441\u043e \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u0434\u0430\u043d\u043d\u044b\u0445 &quot;red-black tree&quot; \u043d\u0430 &quot;maple tree&quot; \u043f\u0440\u0438\u0432\u0451\u043b \u043a \u043f\u043e\u044f\u0432\u043b\u0435\u043d\u0438\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-3269), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-stackrot-v-yadre-linux-pozvolyayushhaya-povysit-svoi-privilegii\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-07-06T01:10:18+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-07-06T07:41:48+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vuln\u00e9rabilit\u00e9 StackRot dans le noyau Linux, permettant d'augmenter ses privil\u00e8ges | ProHoster","description":"La conversion dans le c\u0153ur Linux 6.1 de VMA (Virtual Memory Area) de la structure de donn\u00e9es \"red-black tree\" \u00e0 \"maple tree\" a conduit \u00e0 l'apparition d'une vuln\u00e9rabilit\u00e9 (CVE-2023-3269) permettant \u00e0 un utilisateur non privil\u00e9gi\u00e9.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-stackrot-v-yadre-linux-pozvolyayushhaya-povysit-svoi-privilegii","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c StackRot \u0432 \u044f\u0434\u0440\u0435 Linux, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 | ProHoster","og:description":"\u0412\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u043d\u044b\u0439 \u0432 \u044f\u0434\u0440\u0435 Linux 6.1 \u043f\u0435\u0440\u0435\u0432\u043e\u0434 VMA (Virtual Memory Area) \u0441\u043e \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u0434\u0430\u043d\u043d\u044b\u0445 &quot;red-black tree&quot; \u043d\u0430 &quot;maple tree&quot; \u043f\u0440\u0438\u0432\u0451\u043b \u043a \u043f\u043e\u044f\u0432\u043b\u0435\u043d\u0438\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-3269), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-stackrot-v-yadre-linux-pozvolyayushhaya-povysit-svoi-privilegii","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-07-06T01:10:18+00:00","article:modified_time":"2023-07-06T07:41:48+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/109268","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=109268"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/109268\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=109268"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=109268"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=109268"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}