¡¾·ì϶¹«¸æ¡¿Linux Kernel ±¾µØÈ¨ÏÞÌáÉý·ì϶£¨CVE-2021-33909£©

°ä²¼¹¦·ò 2021-07-21

0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-33909

ʱ      ¼ä

2021-07-21

Àà     ÐÍ

LPE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ


Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

 

2021Äê7ÔÂ20ÈÕ£¬Qualys×êÑÐÍŶӹ«¿ªÅû¶ÁËÔÚLinux ÄÚºËÎļþϵͳ²ãÖз¢ÏÖµÄÒ»¸ö±¾µØÌáȨ·ì϶£¨CVE-2021-33909£¬Ò²³ÆÎªSequoia£©ºÍsystemd (PID 1) ÖеÄÒ»¸ö»Ø¾ø·þÎñ·ì϶£¨CVE-2021-33910£© ¡£

Linux Kernel ±¾µØÌáȨ·ì϶£¨CVE-2021-33909£©

Linux ÄÚºËÎļþϵͳ²ãÖдæÔÚsize_t-to-int ÀàÐÍת»»·ì϶¡£ÓÉÓÚfs/seq_file.c ûÓÐÕýÈ·ÏÞ¶È seq »º³å·Ö±æÅ䣬´Ó¶øµ¼ÖÂÕûÊýÒç³ö¡¢Ô½½çдÈëÒÔ¼°È¨ÏÞÌáÉý¡£¹¥»÷ÕßÄܹ»ÔÚĬÈÏÅäÖÃÖÐÀûÓô˷ì϶£¬×îÖÕÄܹ»ÔÚÊÜÓ°ÏìÖ÷»úÉÏ»ñµÃroot ȨÏÞ¡£·ì϶ӰÏìÁË×Ô 2014 ÄêÒÔÀ´°ä²¼µÄËùÓÐ Linux Äں˰汾¡£

Ó°ÏìÁìÓò

Linux kernel 3.16 - 5.13.x£¨5.13.4֮ǰ£©

 

Systemd(PID 1)»Ø¾ø·þÎñ·ì϶£¨CVE-2021-33910£©

systemdÊÇÔ̺¬ÔÚ´óÎÞÊý»ùÓÚ Linux ϵͳÖеÄÈí¼þÌ×¼þ£¬ËüÌṩÁËÒ»¸öϵͳºÍ·þÎñÖÎÀíÆ÷£¬×÷Ϊ PID 1 ÔËÐв¢Æô¶¯ÏµÍ³µÄÆäÓಿÃÅ¡£

¸Ã·ì϶ÓÉsystemd v220£¨2015Äê4Ô£©Ìá½»µÄ7410616c£¨¡°Ö÷Ì⣺·µ¹¤µ¥ÔªÃû³ÆÑéÖ¤ºÍ²Ù×÷Âß¼­¡±£©ÒýÈ룬¸Ã·ì϶½«¶ÑÖеÄstrdup()´úÌæÎª¶ÑÖеÄstrdupa()¡£ºÎ·ÇÌØÈ¨Óû§¶¼Äܹ»ÀûÓô˷ì϶ʹ systemd ±ÀÀ££¬´Ó¶øÊ¹Õû¸öϵͳ±ÀÀ££¨Äں˱ÀÀ££©£¬µ¼Ö»ؾø·þÎñ¡£¸Ã·ì϶ӰÏìÁË2015 Äê 4 ÔÂÖ®ºó°ä²¼µÄËùÓÐ systemd °æ±¾¡£

Ó°ÏìÁìÓò

systemd 220 ¨C 248

 

0x02 ´ëÖý¨Òé

ĿǰÕâЩ·ì϶ÒѾ­½¨¸´¡£¼øÓÚ·ì϶µÄÓ°ÏìÁìÓò½Ï¹ã£¬ÇÒPoCÒѾ­¹«¿ª£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶ÖÁLinux Kernel 5.13.4£¨ÓÚ2021Äê7ÔÂ20ÈÕ°ä²¼£©»ò¸ü¸ß°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://www.kernel.org/

 

0x03 ²Î¿¼Á´½Ó

https://blog.qualys.com/vulnerabilities-threat-research/2021/07/20/sequoia-a-local-privilege-escalation-vulnerability-in-linuxs-filesystem-layer-cve-2021-33909

https://blog.qualys.com/vulnerabilities-threat-research/2021/07/20/cve-2021-33910-denial-of-service-stack-exhaustion-in-systemd-pid-1

https://www.bleepingcomputer.com/news/security/new-linux-kernel-bug-lets-you-get-root-on-most-modern-distros/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-07-21

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚGA»Æ½ð¼×

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png         image.png