GRO Frag — siódma luka klasy Copy Fail, przyznająca prawa root w systemie Linux

W publicznym dostępie opublikowano exploit dla siódmej podatności (1, 2-3, 4, 5, 6) w jądrze Linux, umożliwiającej nieuprzywilejowanemu lokalnemu użytkownikowi uzyskanie praw roota poprzez nadpisywanie danych w pamięci podręcznej stron. Identyfikator CVE jeszcze nie został przypisany, poza kodem exploita brak jest informacji na temat problemu. Poprawka jest dostępna tylko w formie łatki, która została opublikowana 20 maja, a 21 maja została przyjęta do głównej gałęzi jądra Linux (poprawkowe wersje jądra są jeszcze niedostępne).

Vulnerability exists in the implementation of the GRO (Generic Receive Offload) technology used to accelerate the processing of segmented packets. The vulnerability is due to an error in the implementation of the zerocopy mechanism in the skb_gro_receive() function, which directly modifies data in the page cache to avoid unnecessary buffering. When the SKBFL_MANAGED_FRAG_REFS flag is set, the reference to the freed memory pages in the shinfo->frags field was skipped, after which this field was attached to another skb without changing the reference counter, leading to access to memory after it was freed (use-after-free). The issue could be exploited to overwrite data in the page cache by manipulating the pointer to the io_uring buffer.

The attack is possible on systems with the io_uring subsystem enabled (io_uring_disabled=0). To run the exploit, an executable file with the SUID-root flag must be available for reading in the system. The exploitation mechanism works as follows: the attacker forces the user database to settle in the page cache, after which they substitute the string "hax::0:0::/root:/bin/sh" into the cache. Then, the command "su hax" is executed, which obtains not the original user database from the storage, but a modified copy with the substituted login "hax" that has been granted root privileges and a blank password. The exploit has been tested on Ubuntu 24.04.

Źródło: opennet.ru

Kup solidny hosting stron z ochroną przed DDoS, serwery VPS VDS 🔥 Kup solidny hosting stron z ochroną przed DDoS, serwery VPS VDS | ProHoster