¡¾Î£º¦Í¨¸æ¡¿Linux Kernelí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-3490£©

Ðû²¼Ê±¼ä 2021-08-02

0x00 Îó²î¸ÅÊö

CVE     ID

CVE-2021-3490

ʱ      ¼ä

2021-05-11

Àà      ÐÍ

´úÂëÖ´ÐÐ

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

·ñ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

µÍ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

Extended Berkeley Packet Filter£¨eBPF£©ÊÇÒ»ÖÖÄÚºËÊÖÒÕ£¨´ÓLinux 4.x×îÏÈ£©£¬£¬£¬£¬ÔÊÐí³ÌÐòÔËÐжøÎÞÐè¸Ä±äÄÚºËÔ´´úÂë»òÌí¼ÓÌØÁíÍâÄ£¿£¿£¿£¿é¡£¡£¡£¡£ËüÊÇLinuxÄÚºËÖеÄÒ»ÖÖÇáÁ¿¼¶µÄɳºÐÐéÄâ»ú£¨VM£©£¬£¬£¬£¬¿ÉÒÔÔÚÆäÖÐÔËÐÐʹÓÃÌØ¶¨ÄÚºË×ÊÔ´µÄBPF×Ö½ÚÂë¡£¡£¡£¡£

2021Äê7ÔÂ29ÈÕ£¬£¬£¬£¬Ñо¿Ö°Ô±¹ûÕæÅû¶ÁËeBPFÖеÄÒ»¸öí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-3490£©µÄÊÖÒÕϸ½ÚºÍPoC£¬£¬£¬£¬²¢ÑÝʾÁËʹÓôËÎó²îÔÚUbuntu 20.10 ºÍ 21.04ÉÏʵÏÖLPE£¨ÍâµØÈ¨ÏÞÌáÉý£©¡£¡£¡£¡£

¸ÃÎó²îÊÇÓÉÓÚLinuxÄÚºËÖа´Î»²Ù×÷£¨AND¡¢OR ºÍ XOR£©µÄ eBPF ALU32 ½çÏ߸ú×ÙûÓÐ׼ȷ¸üР32 λ½çÏߣ¬£¬£¬£¬Ôì³É Linux ÄÚºËÖеÄÔ½½ç¶ÁÈ¡ºÍдÈ룬£¬£¬£¬´Ó¶øµ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îʵÏÖÍâµØÈ¨ÏÞÌáÉý»ò¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

Linux kernel < v5.13-rc4

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ´ËÎó²îÒѾ­ÐÞ¸´¡£¡£¡£¡£½¨Òéʵʱ¸üÐÂÖÁv5.13-rc4£¨ÒÑÓÚ2021Äê5ÔÂ11ÈÕÐû²¼£©»ò¸ü¸ß°æ±¾¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://www.kernel.org/

 

0x03 ²Î¿¼Á´½Ó

https://ubuntu.com/security/CVE-2021-3490

https://securityaffairs.co/wordpress/120688/hacking/cve-2021-3490-linux-kernel-bug.html?

https://github.com/chompie1337/Linux_LPE_eBPF_CVE-2021-3490

https://www.graplsecurity.com/post/kernel-pwning-with-ebpf-a-love-story


0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-08-02

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ¼øºÚµ£±£Íø

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png      image.png