{"id":106088,"date":"2022-12-15T13:06:35","date_gmt":"2022-12-15T11:06:35","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-yadre-linux-udalyonno-ekspluatiruemye-cherez-bluetooth"},"modified":"2022-12-15T13:06:35","modified_gmt":"2022-12-15T11:06:35","slug":"uyazvimosti-v-yadre-linux-udalyonno-ekspluatiruemye-cherez-bluetooth","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-yadre-linux-udalyonno-ekspluatiruemye-cherez-bluetooth","title":{"rendered":"Vulnerabilit\u0103\u021bi \u00een nucleul Linux, exploatate de la distan\u021b\u0103 prin Bluetooth","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>O vulnerabilitate a fost identificat\u0103 \u00een kernelul Linux (CVE-2022-42896), care poate fi utilizat\u0103 poten\u021bial pentru a organiza execu\u021bia de cod de la distan\u021b\u0103 la nivel de kernel prin trimiterea unui pachet L2CAP special format prin Bluetooth. \u00cen plus, a fost descoperit\u0103 o alt\u0103 problem\u0103 similar\u0103 (CVE-2022-42895) \u00een gestionatorul L2CAP, care poate duce la scurgeri de con\u021binut din memoria kernelului \u00een pachetele de informa\u021bii de configurare. Prima vulnerabilitate s-a manifestat din august 2014 (kernel 3.16), iar a doua din octombrie 2011 (kernel 3.0). Vulnerabilit\u0103\u021bile au fost remediate \u00een versiunile kernelului Linux 6.1.0, 6.0.8, 4.9.333, 4.14.299, 4.19.265, 5.4.224, 5.10.154 \u0219i 5.15.78. Se poate urm\u0103ri implementarea remedierilor \u00een distribu\u021bii pe urm\u0103toarele pagini: Debian, Ubuntu, Gentoo, RHEL, SUSE, Fedora, Arch.      <\/p>\n<p>Pentru a demonstra capacitatea de a efectua un atac de la distan\u021b\u0103, au fost publicate prototipuri de exploit-uri care func\u021bioneaz\u0103 pe Ubuntu 22.04. Pentru a efectua atacul, atacatorul trebuie s\u0103 se afle \u00een apropierea Bluetooth \u2014 nu este necesar\u0103 asocierea prealabil\u0103, dar Bluetooth-ul trebuie s\u0103 fie activ pe computer. Este suficient s\u0103 se cunoasc\u0103 adresa MAC a dispozitivului victimei, care poate fi determinat\u0103 prin sniffing sau, pe unele dispozitive, calculat\u0103 pe baza adresei MAC Wi-Fi.       <\/p>\n<p>Prima vulnerabilitate (CVE-2022-42896) este cauzat\u0103 de accesarea unei zone de memorie deja eliberate (use-after-free) \u00een implementarea func\u021biilor l2cap_connect \u0219i l2cap_le_connect_req \u2014 dup\u0103 crearea canalului prin apelul de callback new_connection, pentru acesta nu era activat\u0103 o blocare, dar era setat un temporizator (__set_chan_timer), care, la expirarea timeout-ului, invoca func\u021bia l2cap_chan_timeout \u0219i cur\u0103\u021ba canalul f\u0103r\u0103 a verifica finalizarea lucrului cu canalul \u00een func\u021biile l2cap_le_connect*.     <\/p>\n<p>\u00cen mod implicit, timeout-ul este de 40 de secunde \u0219i s-a presupus c\u0103 o stare de competi\u021bie nu poate ap\u0103rea \u00eentr-un asemenea interval, dar s-a dovedit c\u0103 din cauza unei alte erori \u00een gestionatorul SMP se poate ob\u021bine un apel instantaneu al temporizatorului \u0219i, astfel, atingerea unei st\u0103ri de competi\u021bie. Problema din l2cap_le_connect_req poate duce la scurgeri de memorie a kernelului, iar \u00een l2cap_connect la suprascrierea con\u021binutului memoriei \u0219i executarea propriului cod. Prima variant\u0103 de atac poate fi efectuat\u0103 folosind Bluetooth LE 4.0 (din 2009), iar a doua folosind Bluetooth BR\/EDR 5.2 (din 2020).      <\/p>\n<p>A doua vulnerabilitate (CVE-2022-42895) este cauzat\u0103 de scurgerea datelor reziduale din memorie \u00een func\u021bia l2cap_parse_conf_req, ceea ce poate fi folosit pentru ob\u021binerea de informa\u021bii despre indicii structurilor nucleului prin trimiterea de cereri de configurare special concepute. \u00cen func\u021bia l2cap_parse_conf_req s-a folosit structura l2cap_conf_efs, care nu a fost ini\u021bializat\u0103 corespunz\u0103tor \u0219i, prin manipularea flag-ului FLAG_EFS_ENABLE, s-a putut ob\u021bine includerea \u00een pachet a datelor vechi din stiv\u0103. Problema se manifest\u0103 doar pe sistemele \u00een care nucleul este compilat cu op\u021biunea CONFIG_BT_HS (dezactivat\u0103 \u00een mod implicit, dar activat\u0103 \u00een anumite distribu\u021bii, de exemplu, \u00een Ubuntu). Pentru un atac de succes este necesar\u0103, de asemenea, setarea parametrului HCI_HS_ENABLED prin interfa\u021ba de gestionare la valoarea true (care \u00een mod implicit nu este folosit\u0103).<br \/>\n<br \/>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=58329\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-42896), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e L2CAP-\u043f\u0430\u043a\u0435\u0442\u0430 \u0447\u0435\u0440\u0435\u0437 Bluetooth. \u041a\u0440\u043e\u043c\u0435 \u0442\u043e\u0433\u043e, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0435\u0449\u0451 \u043e\u0434\u043d\u0430 \u043f\u043e\u0445\u043e\u0436\u0430\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 (CVE-2022-42895) \u0432 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0435 L2CAP, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0442\u0435\u0447\u043a\u0435 \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0433\u043e \u043f\u0430\u043c\u044f\u0442\u0438 \u044f\u0434\u0440\u0430 \u0432 \u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0441\u043e \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f\u043c\u0438 \u043e \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438. \u041f\u0435\u0440\u0432\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0441 \u0430\u0432\u0433\u0443\u0441\u0442\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-106088","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-42896), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e L2CAP-\u043f\u0430\u043a\u0435\u0442\u0430 \u0447\u0435\u0440\u0435\u0437.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-yadre-linux-udalyonno-ekspluatiruemye-cherez-bluetooth\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u044f\u0434\u0440\u0435 Linux, \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u044b\u0435 \u0447\u0435\u0440\u0435\u0437 Bluetooth | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-42896), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e L2CAP-\u043f\u0430\u043a\u0435\u0442\u0430 \u0447\u0435\u0440\u0435\u0437.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-yadre-linux-udalyonno-ekspluatiruemye-cherez-bluetooth\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-12-15T11:06:35+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-15T11:06:35+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u0103\u021bi \u00een nucleul Linux, exploatate de la distan\u021b\u0103 prin Bluetooth | ProHoster","description":"A fost identificat\u0103 o vulnerabilitate \u00een nucleul Linux (CVE-2022-42896), care poate fi poten\u021bial utilizat\u0103 pentru a organiza executarea de cod la nivel de nucleu prin trimiterea unui pachet L2CAP special conceput.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-yadre-linux-udalyonno-ekspluatiruemye-cherez-bluetooth","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u044f\u0434\u0440\u0435 Linux, \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u044b\u0435 \u0447\u0435\u0440\u0435\u0437 Bluetooth | ProHoster","og:description":"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-42896), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e L2CAP-\u043f\u0430\u043a\u0435\u0442\u0430 \u0447\u0435\u0440\u0435\u0437.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-yadre-linux-udalyonno-ekspluatiruemye-cherez-bluetooth","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-12-15T11:06:35+00:00","article:modified_time":"2022-12-15T11:06:35+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/106088","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=106088"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/106088\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=106088"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=106088"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=106088"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}