Security leak allows reading Linux kernel memory
Summary
In 2004 Paul Starzetz found several bugs in the Linux kernel’s handling of file offsets through which a logged-in user without special privileges could read kernel memory. The causes were incorrect conversions of 64-bit offsets into 32-bit values and a race condition in the 64-bit file API. In tests, Starzetz found the password of an administrator logged in via SSH in this way.
Ideas
- Incorrect type conversions between 64 and 32 bits opened read access to kernel memory.
- Unprotected concurrent access to a variable created a race condition.
- Kernel memory contains other users’ secrets, such as passwords they have typed.
- A demo exploit made the hole immediately testable in practice.
Insights
- On multi-user systems, local holes are just as serious as remote ones.
- Integer conversion bugs are among the most inconspicuous and dangerous classes of bugs in C.
Facts
- Kernels 2.4 to 2.4.26 and 2.6 to 2.6.7 were affected.
- Red Hat already provided fixed kernel packages at publication.
References
Critique
- The report names no workarounds for systems that cannot be rebooted immediately.
Recommendations
- Apply kernel updates particularly quickly on multi-user systems and shell servers.
- Restrict interactive logins on servers to the users who really need them.
Links to the original source and the Web Archive open in a new tab.