Root privileges possible via memory exploit
Summary
In January 2012 a hole became known in the Linux kernel from version 2.6.39 through which local users could gain root privileges via /proc/pid/mem. Since 2.6.39 write access had been possible there, and the check via self_exec_id could be bypassed with a child process. Jason A. Donenfeld explained the bug, and shortly afterwards exploits via the setuid program su were circulating; Android was affected too.
Ideas
- Write access to other processes’ memory needs particularly strict checking.
- A newly permitted access path opened a hole.
- setuid programs such as su served as a lever for privilege escalation.
- Android devices were also affected via the shared kernel.
- On Android 4.0 the exploit only worked via run-as and an ADB connection.
Insights
- New freedoms in kernel interfaces need the same review as new features.
- Detailed explanations also speed up the development of exploits.
Facts
- Kernels from version 2.6.39 were affected.
- Linus Torvalds published the patch personally.
References
Critique
- The report names no CVE identifier, which makes matching with distribution updates harder.
Remarks
- The exploit became known as “Mempodipper”; Donenfeld later developed WireGuard.
Recommendations
- Reduce setuid programs to a minimum.
- Where appropriate, restrict access to other processes’ /proc entries with hidepid.
Links to the original source and the Web Archive open in a new tab.