{"id":100168,"date":"2021-05-14T16:23:07","date_gmt":"2021-05-14T14:23:07","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-podsisteme-ebpf-pozvolyayushhie-vypolnit-kod-na-urovne-yadra-linux"},"modified":"2021-05-14T16:23:07","modified_gmt":"2021-05-14T14:23:07","slug":"uyazvimosti-v-podsisteme-ebpf-pozvolyayushhie-vypolnit-kod-na-urovne-yadra-linux","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-podsisteme-ebpf-pozvolyayushhie-vypolnit-kod-na-urovne-yadra-linux","title":{"rendered":"Vulnerabilit\u0103\u021bi \u00een subsistemul eBPF, care permit executarea codului la nivelul nucleului Linux","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Au fost identificate dou\u0103 noi vulnerabilit\u0103\u021bi \u00een subsistemul eBPF, care permite executarea handler-elor \u00een cadrul nucleului Linux \u00eentr-o ma\u0219in\u0103 virtual\u0103 special\u0103 cu JIT. Ambele vulnerabilit\u0103\u021bi ofer\u0103 posibilitatea de a executa cod propriu cu privilegii de nucleu, \u00een afara ma\u0219inii virtuale izolate eBPF. Informa\u021bii despre probleme au fost publicate de echipa Zero Day Initiative, care organizeaz\u0103 competi\u021bii Pwn2Own, \u00een cadrul c\u0103rora anul acesta au fost demonstrate trei atacuri asupra Ubuntu Linux, utiliz\u00e2nd vulnerabilit\u0103\u021bi anterior necunoscute (nu se specific\u0103 dac\u0103 vulnerabilit\u0103\u021bile \u00een eBPF sunt legate de aceste atacuri).   <\/p>\n<ul>\n<li class=\"l\"> CVE-2021-3490 \u2014 vulnerabilitatea este cauzat\u0103 de lipsa verific\u0103rii dep\u0103\u0219irii valorilor de 32 de bi\u021bi \u00een timpul execu\u021biei opera\u021biunilor bitwise AND, OR \u0219i XOR \u00een eBPF ALU32. Un atacator poate profita de aceast\u0103 eroare pentru a citi \u0219i scrie date \u00een afara limitelor buffer-ului alocat. Problema cu opera\u021bia XOR apare \u00eencep\u00e2nd cu versiunea kernel 5.7-rc1, iar AND \u0219i OR \u2014 \u00eencep\u00e2nd cu versiunea 5.10-rc1.\n<li class=\"l\"> CVE-2021-3489 \u2014 vulnerabilitatea este cauzat\u0103 de o eroare \u00een implementarea buffer-ului circular \u0219i se leag\u0103 de faptul c\u0103 func\u021bia bpf_ringbuf_reserve nu verifica dac\u0103 dimensiunea zonei alocate \u00een memorie poate fi mai mic\u0103 dec\u00e2t dimensiunea real\u0103 a buffer-ului circular ringbuf. Problema apare \u00eencep\u00e2nd cu versiunea 5.8-rc1.  <\/ul>\n<p>Starea remedierii vulnerabilit\u0103\u021bilor \u00een distribu\u021bii poate fi urm\u0103rit\u0103 pe urm\u0103toarele pagini: Ubuntu, Debian, RHEL, Fedora, SUSE, Arch). Remediile sunt de asemenea disponibile sub form\u0103 de patch-uri (CVE-2021-3489, CVE-2021-3490). Posibilitatea de exploatare a problemei depinde de disponibilitatea apelului de sistem eBPF pentru utilizator. De exemplu, \u00een configura\u021bia implicit\u0103 \u00een RHEL, pentru exploatarea vulnerabilit\u0103\u021bii este necesar\u0103 privilegii CAP_SYS_ADMIN pentru utilizator.         <\/p>\n<p>Se poate men\u021biona separat o alt\u0103 vulnerabilitate \u00een kernelul Linux \u2014 CVE-2021-32606, care permite unui utilizator local s\u0103 \u00ee\u0219i ridice privilegii p\u00e2n\u0103 la nivelul root. Problema apare \u00eencep\u00e2nd cu kernelul Linux 5.11 \u0219i este cauzat\u0103 de o stare de competi\u021bie \u00een implementarea protocolului CAN ISOTP, care permite modificarea parametrilor de legare la socket din cauza lipsei implement\u0103rii corespunz\u0103toare a bloc\u0103rilor \u00een func\u021bia isotp_setsockopt() la prelucrarea semnului CAN_ISOTP_SF_BROADCAST.    <\/p>\n<p>Dup\u0103 \u00eenchiderea socket-ului, ISOTP continu\u0103 s\u0103 men\u021bin\u0103 leg\u0103tura cu socket-ul receptor, care poate continua s\u0103 utilizeze structurile legate de socket dup\u0103 eliberarea memoriei asociate (use-after-free din cauza apelului la isotp_rcv() pe o structur\u0103 isotp_sock deja eliberat\u0103). Prin manipularea datelor poate fi realizat\u0103 suprascrierea pointer-ului func\u021biei sk_error_report() \u0219i executarea propriului cod la nivel de kernel.<br \/>\n<br \/>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55150\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 eBPF, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0442\u044c \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0432\u043d\u0443\u0442\u0440\u0438 \u044f\u0434\u0440\u0430 Linux \u0432 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0439 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u0435 \u0441 JIT. \u041e\u0431\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0434\u0430\u044e\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u044f\u0434\u0440\u0430, \u0432\u043d\u0435 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u044b eBPF. \u0418\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u0445 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u043a\u043e\u043c\u0430\u043d\u0434\u0430 Zero Day Initiative, \u043f\u0440\u043e\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u0441\u043e\u0440\u0435\u0432\u043d\u043e\u0432\u0430\u043d\u0438\u044f Pwn2Own, \u0432 \u0445\u043e\u0434\u0435 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0432 \u044d\u0442\u043e\u043c \u0433\u043e\u0434\u0443 \u0431\u044b\u043b\u0438 \u043f\u0440\u043e\u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u0442\u0440\u0438 \u0430\u0442\u0430\u043a\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-100168","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 eBPF, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0442\u044c \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0432\u043d\u0443\u0442\u0440\u0438 \u044f\u0434\u0440\u0430 Linux \u0432 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0439 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u0435 \u0441 JIT.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-podsisteme-ebpf-pozvolyayushhie-vypolnit-kod-na-urovne-yadra-linux\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 eBPF, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 Linux | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 eBPF, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0442\u044c \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0432\u043d\u0443\u0442\u0440\u0438 \u044f\u0434\u0440\u0430 Linux \u0432 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0439 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u0435 \u0441 JIT.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-podsisteme-ebpf-pozvolyayushhie-vypolnit-kod-na-urovne-yadra-linux\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-05-14T14:23:07+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-05-14T14:23:07+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u0103\u021bi \u00een subsistemul eBPF, care permit executarea codului la nivel de kernel Linux | ProHoster","description":"Au fost descoperite dou\u0103 noi vulnerabilit\u0103\u021bi \u00een subsistemul eBPF, care permite rularea handler-elor \u00een interiorul kernel-ului Linux \u00eentr-o ma\u0219in\u0103 virtual\u0103 special\u0103 cu JIT.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-podsisteme-ebpf-pozvolyayushhie-vypolnit-kod-na-urovne-yadra-linux","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 eBPF, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 Linux | ProHoster","og:description":"\u0412\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0434\u0432\u0435 \u043d\u043e\u0432\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 eBPF, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0442\u044c \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0432\u043d\u0443\u0442\u0440\u0438 \u044f\u0434\u0440\u0430 Linux \u0432 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0439 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u0435 \u0441 JIT.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-podsisteme-ebpf-pozvolyayushhie-vypolnit-kod-na-urovne-yadra-linux","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-05-14T14:23:07+00:00","article:modified_time":"2021-05-14T14:23:07+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"100168","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-05-14 21:05:35","updated":"2022-10-09 15:55:52","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/100168","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=100168"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/100168\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=100168"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=100168"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=100168"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}