Root privileges through Linux kernel bug [Update]
Summary
In 2010 Rafal Wojtczuk described a problem in Linux memory management in which the stack and shared memory segments could grow into each other. Using the X server as an example, Wojtczuk showed how an attacker could overwrite return addresses on the stack by writing to the shared memory and gain root privileges. The fix, a guard page between the stack and other areas, came in 2.6.32.19, 2.6.34.4 and 2.6.35.2, although SUSE had offered a fix as early as 2004.
Ideas
- A growing stack can run into another memory area.
- A guard page as a minimum gap prevents overlapping.
- The attack requires local code execution, for example via a second hole.
- Processes whose stack hits other areas are now terminated with SIGBUS.
Insights
- Conceptual flaws in memory management often survive for many years.
- A patch that is available but not adopted protects nobody.
Facts
- Andrea Arcangeli offered a fix as early as September 2004, but it did not make it into the official kernel.
- SUSE had incorporated the fix into SLE 9 and 11 as well as openSUSE 11.1 to 11.3.
References
Critique
- The report initially mixed up two vulnerabilities and had to clarify in an update that Spengler’s exploit concerned a different hole.
Remarks
- In 2017 Qualys showed with “Stack Clash” that a single guard page is not enough; the gap was then increased considerably.
Recommendations
- Keep kernels up to date, even if a hole only seems to be exploitable locally.
- Do not run graphical interfaces and X servers on servers that do not need them.
Links to the original source and the Web Archive open in a new tab.