bk99.de entertain the web since 1997

Security leak allows reading Linux kernel memory

Summary

In 2004 Paul Starzetz found several bugs in the Linux kernel’s handling of file offsets through which a logged-in user without special privileges could read kernel memory. The causes were incorrect conversions of 64-bit offsets into 32-bit values and a race condition in the 64-bit file API. In tests, Starzetz found the password of an administrator logged in via SSH in this way.

Ideas

  • Incorrect type conversions between 64 and 32 bits opened read access to kernel memory.
  • Unprotected concurrent access to a variable created a race condition.
  • Kernel memory contains other users’ secrets, such as passwords they have typed.
  • A demo exploit made the hole immediately testable in practice.

Insights

  • On multi-user systems, local holes are just as serious as remote ones.
  • Integer conversion bugs are among the most inconspicuous and dangerous classes of bugs in C.

Facts

  • Kernels 2.4 to 2.4.26 and 2.6 to 2.6.7 were affected.
  • Red Hat already provided fixed kernel packages at publication.

References

Critique

  • The report names no workarounds for systems that cannot be rebooted immediately.

Recommendations

  • Apply kernel updates particularly quickly on multi-user systems and shell servers.
  • Restrict interactive logins on servers to the users who really need them.

Read the original article

Search the Web Archive