Në kernelin Linux 5.4 janë pranuar patch-e për kufizimin e aksesit të root te mekanizmat e brendshëm të kernelit

Linus Torvalds pranoi as part of the upcoming release of the Linux kernel 5.4 set of patches “lockdown«, proposed by David Howells (works at Red Hat) and Matthew Garrett (Matthew Garrett, works at Google) to restrict root user access to the kernel. The functionality related to “lockdown” has been moved to an optionally loadable LSM module (Linux Security Module), which establishes a barrier between UID 0 and the kernel, limiting certain low-level functionality.

If an attacker gains code execution with root privileges as a result of an attack, they can execute their code at the kernel level, for example, by replacing the kernel using kexec or reading/writing memory via /dev/kmem. The most obvious consequence of such activity may be bypassing UEFI Secure Boot or extracting sensitive data stored at the kernel level.

Initially, the functions for limiting root were developed in the context of enhancing the security of verified boot, and distributions have long employed third-party patches to block UEFI Secure Boot bypass. However, such restrictions were not incorporated into the main kernel due to disagreements on their implementation and concerns about disruption of existing systems. The “lockdown” module has incorporated already used in distributions patches, which were reworked into a separate subsystem not tied to UEFI Secure Boot.

In lockdown mode, access to /dev/mem, /dev/kmem, /dev/port, /proc/kcore, debugfs, kprobes debug mode, mmiotrace, tracefs, BPF, PCMCIA CIS (Card Information Structure), certain ACPI interfaces, and CPU MSR registers is restricted, calls to kexec_file and kexec_load are blocked, sleep mode is prohibited, the use of DMA for PCI devices is limited, importing ACPI code from EFI variables is forbidden,
I/O port manipulations are not allowed, including changing the interrupt number and I/O port for the serial port.

By default, the lockdown module is not active, it is built when specifying the SECURITY_LOCKDOWN_LSM option in kconfig and activated via the kernel parameter “lockdown=”, the control file “/sys/kernel/security/lockdown”, or build options LOCK_DOWN_KERNEL_FORCE_*, tĂ« cilat mund tĂ« kenĂ« vlera «integritet» dhe «konfidencialitet». NĂ« rastin e parĂ« bllokohen mundĂ«sitĂ« qĂ« lejojnĂ« ndryshimin e bĂ«rthamĂ«s nĂ« punĂ« nga hapĂ«sira e pĂ«rdoruesit, ndĂ«rsa nĂ« rastin e dytĂ«, pĂ«rveç kĂ«saj, çaktivizohet funksionaliteti qĂ« mund tĂ« pĂ«rdoret pĂ«r nxjerrjen e informacionit konfidencial nga bĂ«rthama.

Në të njëjtën kohë, është e rëndësishme të theksohet se lockdown-i vetëm kufizon mundësitë standarde të aksesit në bërthamë, por nuk mbron nga modifikimet si rezultat i shfrytëzimit të dobësive. Për të bllokuar ndryshimet në bërthamën në punë kur përdoren eksploit, projekti Openwall po zhvillohet modulin e veçantë LKRG (Linux Kernel Runtime Guard).

Burimi: opennet.ru

Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS đŸ”„ Blini hosting tĂ« besueshĂ«m pĂ«r faqe interneti me mbrojtje nga DDoS, serverĂ« VPS VDS | ProHoster