CIFSwitch — een kwetsbaarheid in de CIFS-subsys van de Linux-kernel die root-rechten kan verkrijgen

Details have been revealed and an exploit has been published for the CIFSwitch vulnerability (CVE not yet assigned) in the CIFS kernel module and the cifs-utils toolkit, allowing an unprivileged user to gain root rights in the system. The fix is only available as a patch, which was published on May 16 and accepted into the main branch of the Linux kernel on May 19 (corrective kernel releases are not yet available).

The vulnerability affects the code that provides support for the cifs.spnego mechanism for authentication via the SPNEGO (Simple and Protected GSSAPI Negotiation) protocol when connecting to SMB servers. When using cifs.spnego to determine keys from Kerberos/SPNEGO, the kernel invokes the cifs.upcall handler, provided by the cifs-utils package and executed in user space with root rights.

An unprivileged user can initiate a call to the handler by sending a request requiring the retrieval of the 'cifs.spnego' key, with a forged description 'CIFS SPNEGO'. The cifs.upcall handler does not perform additional checks of the validity of the parameters passed through the kernel, among other things, it takes the values of the fields pid, uid, creduid and
upcall_target as trustworthy. Once activated, the cifs.upcall handler switches into the namespaces of the user process that sent the request, and before privilege drop, it searches the NSS (Name Service Switch) system database.

An attacker can launch their process in a separate mount namespace, leading to the NSS request being executed in their context. To exploit the vulnerability, it is sufficient for the attacker to place their own configuration file /etc/nsswitch.conf and a set of spoofed libraries libnss_*.so.2 in the environment they created. Executing an NSS request by the cifs.upcall handler will lead to loading the spoofed libraries with root rights.

To exploit the vulnerability, the system must allow the creation of user namespaces or mount namespaces, and the cifs-utils package must be installed on the system. The distributions where the vulnerability can be exploited with the default configuration include:

  • Linux Mint Cinnamon 21.3/22.3
  • CentOS Stream 9 GNOME
  • Rocky Linux 9 Workstation
  • Kali Linux
  • AlmaLinux 9.7 Workstation
  • SUSE 15 SP7/SAP 15 SP7/SAP 16

Distributies waarvoor de installatie van het cifs-utils-pakket nodig is om de exploit te laten werken:

  • Ubuntu 18.04/20.04/22.04 Desktop/Server
  • Pop!_OS 22.04 Intel/24.04 Generic
  • Ubuntu 24.04 Desktop minimal/volledig en Server
  • Debian 11/12/13 netinst standaard en GNOME/KDE/standaard/XFCE
  • CentOS Stream 9 Cinnamon/KDE/MATE/XFCE
  • Rocky Linux 9 KDE/Workstation-Lite
  • openSUSE Leap 15.6 GNOME/KDE
  • openSUSE Tumbleweed GNOME/KDE
  • Rocky Linux 8 GenericCloud
  • Oracle Linux 8/9 KVM
  • Amazon Linux 2023 KVM

Distributies waarbij in de standaardconfiguratie instellingen worden toegepast die de exploitatie van de kwetsbaarheid via SELinux of Apparmor blokkeren, zelfs met het cifs-utils-pakket aanwezig:

  • Ubuntu 26.04 Desktop/Server
  • Fedora 40/41/42/43/44 Workstation/Server
  • CentOS Stream 10 GNOME/KDE
  • Rocky Linux 10 Workstation
  • AlmaLinux 10.1 Workstation
  • Oracle Linux 10 KVM
  • openSUSE Tumbleweed GNOME/KDE
  • openSUSE Leap 16.0 OEM GNOME/KDE/Minimal-VM
  • SUSE Linux 16

Als een omweg om bescherming te bieden, kan de automatische laadtijd van de cifs-kernelmodule worden geblokkeerd:

sh -c «printf 'install cifs /bin/false\n' > /etc/modprobe.d/cifs.conf; rmmod cifs 2>/dev/null; true»

Het is ook mogelijk om het gebruik van user namespace te verbieden («sysctl -w kernel.unprivileged_userns_clone=0») en de regel cifs.spnego in de instellingen van cifs-utils te verwijderen of te overschrijven:

cat >/etc/request-key.d/cifs.spnego.conf <‘EOF’
create cifs.spnego * * /usr/sbin/keyctl negate %k 30 %S
EOF

Ondertussen zijn er op 28 mei 137 kwetsbaarheidsrapporten over de Linux-kernel gepubliceerd, en op 27 mei waren dat er 277.

Bron: opennet.ru

Koop betrouwbare webhosting met bescherming tegen DDoS, VPS VDS servers 🔥 Koop betrouwbare webhosting met bescherming tegen DDoS, VPS VDS servers | ProHoster