Linux local privilege escalation 0day, 2.6.37 - 3.8.10
fucksheep.org
fucksheep.org
p.s.: same should go for all the "x anounces y" where the posted link neither explains what x is nor what y is.
umm NSFW, if you work at a school.
That's the difference between a power user and a hacker.
A power user RTFM, a hacker RTFS.
assert(!setuid(0));
return execl("/bin/bash", "-sh", NULL);
It spawns a root shell, so it's (probably) a (local) privilege escalation.Anybody could submit some unreadable C code that finishes up with setuid(0) and exec("/bin/sh") - it isn't interesting without an explanation of what it's doing.
Kernel must be compiled with PERF_EVENTS (default on most modern distros). Bug fixed in 3.8.10.
This is the kill log:
http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/04302....
This bug got apparently backported from 2.6.37 into centos6 2.6.32 kernels.
patch here: https://patchwork.kernel.org/patch/2441281/
Bug is in 2.6.37-3.8.8, fixed in 3.8.9.
Linux 2.6.32-358.6.1.el6.x86_64 #1 SMP Tue Apr 23 19:29:00 UTC 2013 x86_64 x86_64 x86_64 GNU/Linux (latest CentOS kernel):
[user@centos ~]$ gcc -O2 exploit.c
[user@centos ~]$ ./a.out
2.6.37-3.x x86_64
sd@fucksheep.org 2010
-sh-4.1#* Linux beqbrgbrg1ux006.tpvision.com 3.2.0-29-generic #46-Ubuntu SMP Fri Jul 27 17:03:23 UTC 2012 x86_64 x86_64 x86_64 GNU/Linux
* Linux DrinkCoffee 3.5.0-25-generic #38-Ubuntu SMP Mon Feb 18 23:27:42 UTC 2013 x86_64 x86_64 x86_64 GNU/Linux
And the process gets killed because of a kernel oops in both.
* Linux bk-ak 3.2.0-40-generic #64-Ubuntu SMP Mon Mar 25 21:22:10 UTC 2013 x86_64 x86_64 x86_64 GNU/Linux
[test@libros-dev tmp]$ ./a.out
Killed
This is in dmesg:
[2112052.363397] Oops: 0000 [#1] PREEMPT SMP
[2112052.363890] CPU 0
[2112052.363969] Pid: 3775, comm: a.out Not tainted 3.8.5-1-ARCH #1 innotek GmbH VirtualBox/VirtualBox
./semtex 2.6.37-3.x x86_64 sd@fucksheep.org 2010 semtex: semtex.c:81: main: Assertion `p = memmem(code, 1024, &needle, 8)' failed. Aborted
[1] - http://elrepo.org/tiki/kmod-tpe
LE: exploit needs to be compiled with -O2 flags to work ...
Compile like this and it works:
gcc -O2 semtex.c && ./a.out[user@host ~]$ uname -a Linux host.company.com 3.8.11-200.fc18.x86_64 #1 SMP Wed May 1 19:44:27 UTC 2013 x86_64 x86_64 x86_64 GNU/Linux [user@host ~]$ gcc -O2 semtex.c && ./a.out a.out: semtex.c:51: sheep: Assertion `!close(fd)' failed. Aborted (core dumped)
me@myServer:~$ uname -a Linux KALIDHCP 2.6.32-5-amd64 #1 SMP Mon Feb 25 00:26:11 UTC 2013 x86_64 GNU/Linux me@myServer:~$ cat /etc/debian_version 6.0.7 me@myServer:~$ gcc -O2 semtex.c me@myServer:~$ ./a.out a.out: semtex.c:51: sheep: Assertion `!close(fd)' failed. Aborted me@myServer:~$
Fixed in 3.8.10 so that one's good.
Otherwise, yes, yes it is.
*Edit: Actually it looks like it's fixed in 3.8.9 (made it in 3.8.9rc8) based on the patch at: https://patchwork.kernel.org/patch/2441281/ -- Someone with more knowledge of kernel dev should double-check.
I would guess anyone with an active php shell they haven't discovered before is going to have a Bad Time.
Also, for any Redhat/CentOS users, here is bugzilla for this issue https://bugzilla.redhat.com/show_bug.cgi?id=962792
Joy unconfined.
Whether the vulnerability is patched or the exploit just doesn't work, I can't say, but I get this:
yebyen@oneiric64:~$ gcc -O2 semtex.c
yebyen@oneiric64:~$ ./a.out
Killed
(Don't worry the hostname is oneiric64. It's not running oneiric.)Want me to pastebin it? edit:
It starts out
[318258.327110] BUG: unable to handle kernel paging request at 0000001781ef7788
[318258.328251] IP: [<ffffffff8108f1a5>] atomic_dec_and_mutex_lock+0x15/0x90
[318258.328251] PGD 2b18b067 PUD 0
[318258.328251] Oops: 0000 [#4] SMP Linux (redacted) 3.2.0-41-virtual #66-Ubuntu SMP Thu Apr 25 03:47:17 UTC 2013 x86_64 x86_64 x86_64 GNU/Linux
[ 413.309308] BUG: unable to handle kernel paging request at 0000001781eef4e8
[ 413.310359] IP: [<ffffffff8108d605>] atomic_dec_and_mutex_lock+0x15/0xa0
[ 413.311025] PGD 1c4ec067 PUD 0
[ 413.311680] Oops: 0000 [#6] SMP
[ 413.312007] CPU 0
Edit: disregard the timestamp above, VM has not synced with NTP for some time. gunther> gcc -O2 semtex.c
gunther> ./a.out
a.out: semtex.c:63: main: Assertion `(map = mmap((void*)0x380000000, 0x010000000, 3, 0x32, 0,0)) == (void*)0x380000000' failed.
Aborted
gunther> uname -r
3.4.2-x86_64-linode25$ uname -a Linux li252-14 3.5.2-linode45 #1 SMP Wed Aug 15 14:10:55 EDT 2012 i686 i686 i386 GNU/Linux
$ gcc -O2 semtex.c && ./a.out semtex.c: In function âfuckâ: semtex.c:30:37: warning: cast from pointer to integer of different size semtex.c:30:23: warning: cast to pointer from integer of different size semtex.c:31:21: warning: cast from pointer to integer of different size semtex.c:37:19: warning: cast to pointer from integer of different size semtex.c: In function âmainâ: semtex.c:74:3: warning: cast to pointer from integer of different size semtex.c:74:3: warning: cast to pointer from integer of different size a.out: semtex.c:51: sheep: Assertion `!close(fd)' failed. Aborted
(from below)
PS1/ $ w
12:17:27 up 38 days, 17:18, 1 user, load average: 0.44, 0.11, 0.04
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
user pts/0 Narnia 07:11 0.00s 0.25s 0.11s w
PS1/ $ uname -a
Linux Rivendell 2.6.32-358.2.1.el6.x86_64 #1 SMP Wed Mar 13 00:26:49 UTC 2013 x86_64 x86_64 x86_64 GNU/Linux
PS1/ $ cat /etc/redhat\-release
CentOS release 6.4 (Final)
PS1/ $ ./a.out
2.6.37-3.x x86_64
sd@fucksheep.org 2010
a.out: sheep.c:81: main: Assertion `p = memmem(code, 1024, &needle, 8)' failed.
Abort(coredump)
PS1/
Seems it is nicely dumped instead of doing weird things in userland.
Under root is doesn't coredump, but returns to the prompt without any hassle.
$ grep -A 10 'int perf_swevent_init' linux-2.6.32-358.el6/kernel/events/core.c static int perf_swevent_init(struct perf_event *event) { int event_id = event->attr.config;
if (event->attr.type != PERF_TYPE_SOFTWARE) return -ENOENT;
switch (event_id) { case PERF_COUNT_SW_CPU_CLOCK: case PERF_COUNT_SW_TASK_CLOCK: return -ENOENT;
gcc -O2 sheep.c && ./a.out [5126545.172128] BUG: unable to handle kernel paging request at ffffffff1de68048This is a brilliant example of how stupid many distros are with their kernel configurations. They need to start understanding that enabling features that nobody uses only increases the probability of problematic bugs.
Also, they need to stop enabling CONFIG_CC_STACKPROTECTOR. It slows stuff down, and as can be seen here, often doesn't do any good.
[a@err ~]$ uname -a Linux err 2.6.32-358.6.1.el6.i686 #1 SMP Tue Apr 23 18:13:20 UTC 2013 i686 i686 i386 GNU/Linux [a@err ~]$ ./a.out a.out: 1.c:51: sheep: Assertion `!close(fd)' failed. Aborted (core dumped) [a@err ~]$
Linux XX 2.6.32-358.2.1.el6.x86_64 #1 SMP Wed Mar 13 00:26:49 UTC 2013 x86_64 x86_64 x86_64 GNU/Linux
Lack of exploit code doesn't imply a lack of vulnerability :)
I may be wrong though, as I didn't scan through all the affected code.
IGjDf1e4eQxWyBFArYM8HgvCuns6p+GbfHoE3SPxYV59kXnA12BWdMr6D5eAAFgtBSX+/Yi+vLxMmEiszkwHLCA=