CVE-2020-8835| Linux Kernel ÐÅϢй¶/ȨÏÞÌáÉý·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-01

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-8835

ʱ    ¼ä

2020-03-30

Àà    ÐÍ

ԽȨ½Ó¼û

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

·ñ

Ó°ÏìÁìÓò

Linux Kernel 5.4£¬5.5


0x01 ·ì϶ÏêÇé


Linux kernelÊÇÃÀ¹úLinux»ù½ð»á°ä²¼µÄ¿ªÔ´²Ù×÷ϵͳLinuxËùʹÓõÄÄںˡ£¸Ã·ì϶×îÔçÓÚPwn2Own ½ÇÖðÉÏÓÃÓÚÑÝʾ Linux ÄÚºËȨÏÞÌáÉý·ì϶¡£


ÔÚLinuxÄں˵ÄeBPF´úÂëÑéÖ¤·¨Ê½µÄʵÏÖÖз¢ÏÖÁËÒ»¸öԽȨ½Ó¼û·ì϶£¬ÆäÖÐeBPF·¨Ê½ÖеÄ32λָÁîʱ²úÉúÁËÃýÎóµÄ¼Ä·ÅÆ÷ÌìÇµÍÆËã¡£¸ÃȱµãÔÊÐíûÓÐÌØÈ¨µÄÓû§»ò¹ý³ÌÖ´ÐÐeBPF·¨Ê½Ê¹Äں˱ÀÀ££¬´Ó¶øµ¼Ö»ؾø·þÎñ»ò»ñµÃϵͳrootȨÏÞ¡£


0x02 ´ëÖý¨Òé


һʱ¹æ»®¿Éͨ¹ýÅú¸ÄÄں˲ÎÊýÀ´¶Ôͨ³£Óû§½øÐÐÏÞ¶È£º


Ubuntu£º

$ sudo sysctl kernel.unprivileged_bpf_disabled=1

$ echo kernel.unprivileged_bpf_disabled=1 | \

sudo tee /etc/sysctl.d/90-CVE-2020-8835.conf


Redhat£º

# sysctl -w kernel.unprivileged_bpf_disabled=1


Fedora£º

# sysctl -w kernel.unprivileged_bpf_disabled=1



Óйؿ¯ÐаæµÄ½¨¸´½¨Òé


Debian£º

https://security-tracker.debian.org/tracker/CVE-2020-8835


Red Hat Enterprise Linux/CentOS£º

https://access.redhat.com/security/cve/CVE-2020-8835


Ubuntu£º

https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-8835.html


0x03 ÓйØÐÂÎÅ


https://www.thezdi.com/blog/2020/3/19/pwn2own-2020-day-one-results


0x04 ²Î¿¼Á´½Ó


https://access.redhat.com/security/cve/cve-2020-8835

https://security-tracker.debian.org/tracker/CVE-2020-8835

https://security.sios.com/vulnerability/kernel-security-vulnerability-20200331.html

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8835


0x05 ¹¦·òÏß


2020-03-19 ZDI չʾ¸Ã·ì϶¹¥»÷³É¾Í

2020-03-30 CVE ÊÕ¼¸Ã·ì϶