Critical hole in the Linux kernel affects all versions since 2001
Summary
In 2009 Tavis Ormandy and Julien Tinnes from Google found a hole that affected all Linux kernels 2.4 and 2.6 since May 2001 and allowed local root privileges. With rarely used protocols such as Bluetooth, PPPoX or ISDN, pointers in the socket operations remained uninitialised, which could be exploited via sock_sendpage. Brad Spengler published the exploit “wunderbar_emporium”, which worked on a current Ubuntu 8.10.
Ideas
- Unimplemented socket operations should have pointed to safe default functions.
- A null pointer dereference in the kernel could be used for privilege escalation.
- The kernel developers fixed the shared function instead of each protocol individually.
- Setting mmap_min_addr to a value greater than zero prevented the exploit.
Insights
- Rarely used code ages unnoticed and remains vulnerable for years.
- Protection mechanisms that catch entire classes of bugs also work against unknown holes.
Facts
- Versions 2.4.4 to 2.4.37.4 and 2.6.0 to 2.6.30.4 were affected.
- The hole is known as CVE-2009-2692.
References
Critique
- The report explains the cause well but does not say which distributions already set mmap_min_addr by default.
Remarks
- Modern kernels prohibit mappings at address zero by default, so null pointer bugs usually only cause crashes now.
Recommendations
- Check with sysctl vm.mmap_min_addr that the value is greater than zero.
- Block kernel modules for protocols such as Bluetooth, PPPoX or ISDN on servers that do not need them.
Links to the original source and the Web Archive open in a new tab.