bk99.de entertain the web since 1997

Root privileges through Linux kernel bug [Update]

Summary

In 2010 Rafal Wojtczuk described a problem in Linux memory management in which the stack and shared memory segments could grow into each other. Using the X server as an example, Wojtczuk showed how an attacker could overwrite return addresses on the stack by writing to the shared memory and gain root privileges. The fix, a guard page between the stack and other areas, came in 2.6.32.19, 2.6.34.4 and 2.6.35.2, although SUSE had offered a fix as early as 2004.

Ideas

  • A growing stack can run into another memory area.
  • A guard page as a minimum gap prevents overlapping.
  • The attack requires local code execution, for example via a second hole.
  • Processes whose stack hits other areas are now terminated with SIGBUS.

Insights

  • Conceptual flaws in memory management often survive for many years.
  • A patch that is available but not adopted protects nobody.

Facts

  • Andrea Arcangeli offered a fix as early as September 2004, but it did not make it into the official kernel.
  • SUSE had incorporated the fix into SLE 9 and 11 as well as openSUSE 11.1 to 11.3.

References

Critique

  • The report initially mixed up two vulnerabilities and had to clarify in an update that Spengler’s exploit concerned a different hole.

Remarks

  • In 2017 Qualys showed with “Stack Clash” that a single guard page is not enough; the gap was then increased considerably.

Recommendations

  • Keep kernels up to date, even if a hole only seems to be exploitable locally.
  • Do not run graphical interfaces and X servers on servers that do not need them.

Read the original article

Search the Web Archive