ืคื’ื™ืขื•ืช ื‘-systemd-coredump ื”ืžืืคืฉืจืช ืœืงื‘ื•ืข ืืช ืชื•ื›ืŸ ื”ื–ื™ื›ืจื•ืŸ ืฉืœ ืชื•ื›ื ื™ื•ืช suid

ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช (CVE-2022-4415) ื‘ืจื›ื™ื‘ systemd-coredump, ื”ืžืขื‘ื“ ืงื‘ืฆื™ ืœื™ื‘ื” ืฉื ื•ืฆืจื• ืœืื—ืจ ืงืจื™ืกืช ืชื”ืœื™ื›ื™ื, ืžื” ืฉืžืืคืฉืจ ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœืœื ื”ืจืฉืื•ืช ืœืงื‘ื•ืข ืืช ืชื•ื›ืŸ ื”ื–ื™ื›ืจื•ืŸ ืฉืœ ืชื”ืœื™ื›ื™ื ืžื•ืจืฉื™ื ื”ืคื•ืขืœื™ื ืขื ื“ื’ืœ ื”ืฉื•ืจืฉ suid. ื‘ืขื™ื™ืช ืชืฆื•ืจืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืื•ืฉืจื” ื‘ื”ืคืฆื•ืช openSUSE, Arch, Debian, Fedora ื•-SLES.

ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืžื”ื™ืขื“ืจ ืขื™ื‘ื•ื“ ื ื›ื•ืŸ ืฉืœ ื”ืคืจืžื˜ืจ sysctl fs.suid_dumpable ื‘-systemd-coredump, ืฉื›ืืฉืจ ืžื•ื’ื“ืจ ืœืขืจืš ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ 2, ืžืืคืฉืจ ื™ืฆื™ืจืช dump ื”ืœื™ื‘ื” ืขื‘ื•ืจ ืชื”ืœื™ื›ื™ื ืขื ื“ื’ืœ suid. ืžื•ื‘ืŸ ืฉืœืงื•ื‘ืฆื™ ื”ืœื™ื‘ื” ืฉืœ ืชื”ืœื™ื›ื™ suid ืฉื ื›ืชื‘ื• ืขืœ ื™ื“ื™ ื”ืœื™ื‘ื” ื—ื™ื™ื‘ื•ืช ืœื”ื™ื•ืช ื–ื›ื•ื™ื•ืช ื’ื™ืฉื” ืžื•ื’ื“ืจื•ืช ื›ื“ื™ ืœืืคืฉืจ ืงืจื™ืื” ืจืง ืขืœ ื™ื“ื™ ืžืฉืชืžืฉ ื”ืฉื•ืจืฉ. ื›ืœื™ ื”ืฉื™ืจื•ืช systemd-coredump, ื”ื ืงืจื ืขืœ ื™ื“ื™ ื”ืœื™ื‘ื” ื›ื“ื™ ืœืฉืžื•ืจ ืงื‘ืฆื™ ืœื™ื‘ื”, ืžืื—ืกืŸ ืืช ืงื•ื‘ืฅ ื”ืœื™ื‘ื” ืชื—ืช ืžื–ื”ื” ื”ืฉื•ืจืฉ, ืืš ื‘ื ื•ืกืฃ ืžืกืคืง ื’ื™ืฉืช ืงืจื™ืื” ืžื‘ื•ืกืกืช ACL ืœืงื‘ืฆื™ ื”ืœื™ื‘ื” ื‘ื”ืชื‘ืกืก ืขืœ ื”ืžื–ื”ื” ืฉืœ ื”ื‘ืขืœื™ื ืฉื”ืฉื™ืง ืืช ื”ืชื”ืœื™ืš ื‘ืžืงื•ืจ. .

ืชื›ื•ื ื” ื–ื• ืžืืคืฉืจืช ืœืš ืœื”ื•ืจื™ื“ ืงื‘ืฆื™ ืœื™ื‘ื” ืžื‘ืœื™ ืœื”ืชื—ืฉื‘ ื‘ืขื•ื‘ื“ื” ืฉื”ืชื•ื›ื ื™ืช ื™ื›ื•ืœื” ืœืฉื ื•ืช ืืช ืžื–ื”ื” ื”ืžืฉืชืžืฉ ื•ืœื”ืคืขื™ืœ ืขื ื”ืจืฉืื•ืช ื’ื‘ื•ื”ื•ืช. ื”ืžืชืงืคื” ืžืกืชื›ืžืช ื‘ืขื•ื‘ื“ื” ืฉืžืฉืชืžืฉ ื™ื›ื•ืœ ืœื”ืคืขื™ืœ ืืคืœื™ืงืฆื™ื™ืช suid ื•ืœืฉืœื•ื— ืœื” ืื•ืช SIGSEGV, ื•ืœืื—ืจ ืžื›ืŸ ืœื˜ืขื•ืŸ ืืช ื”ืชื•ื›ืŸ ืฉืœ ืงื•ื‘ืฅ ืœื™ื‘ื”, ื”ื›ื•ืœืœ ืคืจื•ืกืช ื–ื™ื›ืจื•ืŸ ืžื”ืชื”ืœื™ืš ื‘ืžื”ืœืš ืกื™ื•ื ื—ืจื™ื’.

ืœื“ื•ื’ืžื”, ืžืฉืชืžืฉ ื™ื›ื•ืœ ืœื”ืจื™ืฅ "/usr/bin/su" ื•ื‘ื˜ืจืžื™ื ืœ ืื—ืจ ืœืกื™ื™ื ืืช ื”ื‘ื™ืฆื•ืข ืฉืœื• ืขื ื”ืคืงื•ื“ื” "kill -s SIGSEGV `pidof su`", ื•ืœืื—ืจ ืžื›ืŸ systemd-coredump ื™ืฉืžื•ืจ ืืช ืงื•ื‘ืฅ ื”ืœื™ื‘ื” ื‘-/var /lib/systemd/ coredump, ื”ื’ื“ืจืช ACL ืขื‘ื•ืจื” ื”ืžืืคืฉืจ ืงืจื™ืื” ืขืœ ื™ื“ื™ ื”ืžืฉืชืžืฉ ื”ื ื•ื›ื—ื™. ืžื›ื™ื•ื•ืŸ ืฉืชื•ื›ื ื™ืช ื”ืฉื™ืจื•ืช suid 'su' ืงื•ืจื ืืช ื”ืชื•ื›ืŸ ืฉืœ /etc/shadow ืœืชื•ืš ื”ื–ื™ื›ืจื•ืŸ, ืชื•ืงืฃ ื™ื›ื•ืœ ืœืงื‘ืœ ื’ื™ืฉื” ืœืžื™ื“ืข ืขืœ ื”-hash ืฉืœ ื”ืกื™ืกืžื” ืฉืœ ื›ืœ ื”ืžืฉืชืžืฉื™ื ื‘ืžืขืจื›ืช. ื›ืœื™ ื”ืฉื™ืจื•ืช sudo ืื™ื ื• ืจื’ื™ืฉ ืœื”ืชืงืคื”, ืžื›ื™ื•ื•ืŸ ืฉื”ื•ื ืื•ืกืจ ืขืœ ื™ืฆื™ืจืช ืงื‘ืฆื™ ืœื™ื‘ื” ื‘ืืžืฆืขื•ืช ulimit.

ืœื˜ืขื ืช ืžืคืชื—ื™ systemd, ื”ืคื’ื™ืขื•ืช ืžื•ืคื™ืขื” ื”ื—ืœ ืžื’ืจืกื” 247 ืฉืœ systemd (ื ื•ื‘ืžื‘ืจ 2020), ืืš ืœื“ื‘ืจื™ ื”ื—ื•ืงืจ ืฉื–ื™ื”ื” ืืช ื”ื‘ืขื™ื”, ืžื•ืฉืคืขืช ื’ื ืžื”ื“ื•ืจื” 246. ื”ืคื’ื™ืขื•ืช ืžื•ืคื™ืขื” ืื systemd ืžื•ืจื›ื‘ ืขื ืกืคืจื™ื™ืช libacl (ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘- ื›ืœ ื”ื”ืคืฆื•ืช ื”ืคื•ืคื•ืœืจื™ื•ืช). ื”ืชื™ืงื•ืŸ ื–ืžื™ืŸ ื›ืจื’ืข ื›ืชื™ืงื•ืŸ. ืืชื” ื™ื›ื•ืœ ืœืขืงื•ื‘ ืื—ืจ ื”ืชื™ืงื•ื ื™ื ื‘ื”ืคืฆื•ืช ื‘ืขืžื•ื“ื™ื ื”ื‘ืื™ื: Debian, Ubuntu, Gentoo, RHEL, SUSE, Fedora, Gentoo, Arch. ื›ืคืชืจื•ืŸ ืื‘ื˜ื—ื”, ืืชื” ื™ื›ื•ืœ ืœื”ื’ื“ื™ืจ ืืช sysctl fs.suid_dumpable ืœ-0, ืืฉืจ ืžืฉื‘ื™ืช ืืช ืฉืœื™ื—ืช ื”-dumps ืœืžื˜ืคืœ systemd-coredump.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”