Linux PolkitȨÏÞÌáÉý·ì϶£¨CVE-2021-3560£©
°ä²¼¹¦·ò 2021-06-110x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-3560 | ʱ ¼ä | 2021-06-11 |
Àà ÐÍ | LPE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ·ñ | Ó°ÏìÁìÓò | |
¹¥»÷¸´ÔÓ¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | µÍ |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà |
0x01 ·ì϶ÏêÇé

PolkitÊǺܶàLinux ¿¯ÐаæÉÏĬÈÏ×°ÖõÄϵͳ·þÎñ£¬Ëü±»systemdʹÓã¬ËùÒÔÈκÎʹÓÃsystemdµÄLinux¿¯Ðаæ³ÇÊÐʹÓÃpolkit¡£
2021Äê06ÔÂ03ÈÕ£¬RedHat°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËLinux PolkitÖÐÒ»¸ö´æÔÚÁË7ÄêµÄȨÏÞÌáÉý·ì϶£¨CVE-2021-3560£©£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜ»ñµÃϵͳÉ쵀 root ȨÏÞ¡£Ä¿Ç°GitHubµÄ°²È«×êÑÐÔ±ÒѾ¹«¿ªÅû¶ÁË´Ë·ì϶µÄϸ½ÚºÍPoC¡£
·ì϶ϸ½Ú
¸Ã·ì϶ÊÇÓÉÓÚµ±ÒªÇó¹ý³ÌÔÚŲÓÃpolkit_system_bus_name_get_creds_sync ֮ǰÓë dbus-daemon ¶Ï¿ªÏνÓʱ£¬¸Ã¹ý³ÌÎÞ·¨»ñµÃ¹ý³ÌµÄΨһuidºÍpid£¬Ò²ÎÞ·¨ÑéÖ¤ÒªÇó¹ý³ÌµÄȨÏÞ¡£
Äܹ»Í¨¹ýÆô¶¯dbus-sendºÅÁÔÚ polkit ÈÔÔÚ´¦ÖÃÒªÇóµÄ¹ý³ÌÖÐÖÕÖ¹ËüÀ´´¥·¢´Ë·ì϶£¬ÔÚÈÏÖ¤ÒªÇóÖÐÖÕÖ¹dbus-send£¨Ò»¸ö¹ý³Ì¼äͨѶºÅÁ»áµ¼ÖÂÒ»¸öÃýÎó£¬ÓÉÓÚpolkit½«ÒªÇóÌṩһ¸ö²»ÔÙ´æÔÚµÄÏνӵÄUID£¨ÓÉÓÚ¸ÃÏνÓÒѱ»ÖÕÖ¹£©¡£¶øpolkit»áÒÔÒ»ÖÖÃýÎóµÄ·½Ê½´¦ÖôËÎÊÌ⣺Ëü²»»á»Ø¾øÕâ¸öÏνÓÒªÇ󣬶øÊǰÑÕâ¸öÒªÇóÊÓΪÀ´×ÔUIDΪ0µÄ¹ý³Ì¡£
×êÑÐÈËÔ±°µÊ¾£¬¸Ã·ì϶ºÜÈÝÒ×±»ÀûÓã¬Ö»±ØÒªÊ¹Óà bash¡¢kill ºÍ dbus-send µÈ³ß¶ÈÖն˹¤¾ßÖ´Ðм¸ÌõºÅÁî¼´¿É¡£
Ó°ÏìÁìÓò
RHEL 8
Fedora 21¼°¸ü¸ß°æ±¾
Debian testing (¡°bullseye¡±)
Ubuntu 20.04
0x02 ´ëÖý¨Òé
Ŀǰ´Ë·ì϶ÒѾ½¨¸´£¬½¨Òé²Î¿¼Linux¸÷¿¯Ðа汾µÄ¹Ù·½¹«¸æÊµÊ±Éý¼¶¸üÐÂ:
RHEL 8£º
https://access.redhat.com/security/cve/CVE-2021-3560
Fedora 21¼°¸ü¸ß°æ±¾£º
https://bugzilla.redhat.com/show_bug.cgi?id=1967424
Debian testing (¡°bullseye¡±)£º
https://security-tracker.debian.org/tracker/CVE-2021-3560
Ubuntu 20.04£º
https://ubuntu.com/security/CVE-2021-3560
0x03 ²Î¿¼Á´½Ó
https://access.redhat.com/security/cve/CVE-2021-3560
https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/
https://www.theregister.com/2021/06/11/linux_polkit_package_patched/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3560
0x04 ¹¦·òÏß
2021-06-03 RedHat°ä²¼°²È«²¼¸æ
2021-06-11 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ