bk99.de entertain the web since 1997

Root privileges possible via memory exploit

Summary

In January 2012 a hole became known in the Linux kernel from version 2.6.39 through which local users could gain root privileges via /proc/pid/mem. Since 2.6.39 write access had been possible there, and the check via self_exec_id could be bypassed with a child process. Jason A. Donenfeld explained the bug, and shortly afterwards exploits via the setuid program su were circulating; Android was affected too.

Ideas

  • Write access to other processes’ memory needs particularly strict checking.
  • A newly permitted access path opened a hole.
  • setuid programs such as su served as a lever for privilege escalation.
  • Android devices were also affected via the shared kernel.
  • On Android 4.0 the exploit only worked via run-as and an ADB connection.

Insights

  • New freedoms in kernel interfaces need the same review as new features.
  • Detailed explanations also speed up the development of exploits.

Facts

  • Kernels from version 2.6.39 were affected.
  • Linus Torvalds published the patch personally.

References

Critique

  • The report names no CVE identifier, which makes matching with distribution updates harder.

Remarks

  • The exploit became known as “Mempodipper”; Donenfeld later developed WireGuard.

Recommendations

  • Reduce setuid programs to a minimum.
  • Where appropriate, restrict access to other processes’ /proc entries with hidepid.

Read the original article

Search the Web Archive