¡¾Ç徲ͨ¸æ¡¿LinuxÄÚºËȨÏÞÌáÉýÎó²î£¨CVE-2021-33909£©Í¨¸æ
2021-07-22
Ò». Îó²î¸ÅÊö
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²â·¢Ã÷QualysÑо¿ÍŶÓÅû¶ÁËLinux ÄÚºËÎļþϵͳ²ãÖеÄÒ»¸öÍâµØÌáȨÎó²î£¨CVE-2021-33909£¬Ò²³ÆÎªSequoia£©£¬¸ÃÎó²îΪLinux Äں˵Äseq_file ½Ó¿Ú±£´æsize_t-to-int ÀàÐÍת»»Îó²î£¬ÓÉÓÚfs/seq_file.c ûÓÐ׼ȷÏÞÖÆ seq »º³åÇø·ÖÅÉ£¬´Ó¶øµ¼ÖÂÕûÊýÒç³ö¡¢Ô½½çдÈëÒÔ¼°È¨ÏÞÌáÉý¡£í§ÒâÓû§È¨Ï޵Ĺ¥»÷Õß¶¼¿ÉÒÔÔÚĬÈÏÉèÖÃÖÐʹÓôËÎó²î£¬´Ó¶ø»ñµÃÊÜÓ°ÏìÖ÷»úµÄroot ȨÏÞ¡£¸ÃÎó²îÓ°ÏìÁË×Ô 2014 ÄêÒÔÀ´Ðû²¼µÄËùÓÐ Linux Äں˰汾£¬ÏÖÔÚPoCÒѹûÕæ£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
²Î¿¼Á´½Ó£º
https://www.qualys.com/2021/07/20/cve-2021-33909/sequoia-local-privilege-escalation-linux.txt
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
3.16 <= Linux kernel < 5.13.4
²»ÊÜÓ°Ïì°æ±¾
Linux kernel => 5.13.4
Èý. Îó²î¼ì²â
3.1 °æ±¾¼ì²â
LinuxϵͳÓû§¿ÉÒÔͨ¹ýÉó²é°æÔÀ´ÅжÏÄ¿½ñϵͳÊÇ·ñÔÚÊÜÓ°Ïì¹æÄ£ÄÚ£¬Éó²é²Ù×÷ϵͳ°æ±¾ÐÅÏ¢ÏÂÁîÈçÏ£º
|
cat /proc/version |
ËÄ. Îó²î·À»¤
4.1 ¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÔÚ×îа汾ÖÐÐÞ¸´Á˸ÃÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º https://www.kernel.org/
4.2 ÔÝʱ»º½â²½·¥
ÈôÏà¹ØÓû§ÔÝʱÎÞ·¨¾ÙÐÐÉý¼¶²Ù×÷£¬¿ÉÕë¶ÔQualysÒÑÖªµÄÌØ¶¨Îó²îʹÓþÙÐÐÔÝʱ·À»¤£º
1¡¢½« /proc/sys/kernel/unprivileged_userns_cloneÉèÖÃΪ 0£¬ÒÔ±ÜÃâ¹¥»÷ÕßÔÚÓû§ÃüÃû¿Õ¼äÖйÒÔØ³¤Ä¿Â¼¡£
2¡¢½« /proc/sys/kernel/unprivileged_bpf_disabled ÉèÖÃΪ 1£¬ÒÔ±ÜÃâ¹¥»÷Õß½«eBPF³ÌÐò¼ÓÔØµ½ÄÚºËÖС£
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







