Linux PolkitȨÏÞÌáÉý©¶´£¨CVE-2021-3560£©
Ðû²¼Ê±¼ä 2021-06-110x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-3560 | ʱ ¼ä | 2021-06-11 |
Àà ÐÍ | LPE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ·ñ | Ó°Ï췶Χ | |
¹¥»÷ÅÓ´ó¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | µÍ |
PoC/EXP | ÒѹûÈ» | ÔÚÒ°ÀûÓà |
0x01 ©¶´ÏêÇé
PolkitÊÇÐí¶àLinux ¿¯ÐаæÉÏĬÈϰ²×°µÄϵͳ·þÎñ£¬Ëü±»systemdʹÓã¬ËùÒÔÈκÎʹÓÃsystemdµÄLinux¿¯Ðа涼ÊÐʹÓÃpolkit¡£
2021Äê06ÔÂ03ÈÕ£¬RedHatÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËLinux PolkitÖÐÒ»¸ö´æÔÚÁË7ÄêµÄȨÏÞÌáÉý©¶´£¨CVE-2021-3560£©£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷ÕßÄܹ»»ñµÃϵͳÉ쵀 root ȨÏÞ¡£Ä¿Ç°GitHubµÄÄþ¾²Ñо¿Ô±ÒѾ¹ûÈ»Åû¶ÁË´Ë©¶´µÄϸ½ÚºÍPoC¡£
©¶´Ï¸½Ú
¸Ã©¶´ÊÇÓÉÓÚµ±ÇëÇó½ø³ÌÔÚµ÷ÓÃpolkit_system_bus_name_get_creds_sync ֮ǰÓë dbus-daemon ¶Ï¿ªÁ¬½Óʱ£¬¸Ã½ø³ÌÎÞ·¨»ñµÃ½ø³ÌµÄΨһuidºÍpid£¬Ò²ÎÞ·¨ÑéÖ¤ÇëÇó½ø³ÌµÄȨÏÞ¡£
¿ÉÒÔͨ¹ýÆô¶¯dbus-sendÃüÁÔÚ polkit ÈÔÔÚ´¦ÖÃÇëÇóµÄ¹ý³ÌÖÐÖÕÖ¹ËüÀ´´¥·¢´Ë©¶´£¬ÔÚÈÏÖ¤ÇëÇóÖÐÖÕÖ¹dbus-send£¨Ò»¸ö½ø³Ì¼äͨÐÅÃüÁ»áµ¼ÖÂÒ»¸ö´íÎó£¬ÒòΪpolkit½«ÒªÇóÌṩһ¸ö²»ÔÙ´æÔÚµÄÁ¬½ÓµÄUID£¨ÒòΪ¸ÃÁ¬½ÓÒѱ»ÖÕÖ¹£©¡£¶øpolkit»áÒÔÒ»ÖÖ´íÎóµÄ·½Ê½´¦ÖôËÎÊÌ⣺Ëü²»»á¾Ü¾øÕâ¸öÁ¬½ÓÇëÇ󣬶øÊǰÑÕâ¸öÇëÇóÊÓΪÀ´×ÔUIDΪ0µÄ½ø³Ì¡£
Ñо¿ÈËÔ±ÌåÏÖ£¬¸Ã©¶´ºÜÈÝÒ×±»ÀûÓã¬Ö»ÐèҪʹÓà bash¡¢kill ºÍ dbus-send µÈ³ß¶ÈÖն˹¤¾ßÖ´Ðм¸ÌõÃüÁî¼´¿É¡£
Ó°Ï췶Χ
RHEL 8
Fedora 21¼°¸ü¸ß°æ±¾
Debian testing (¡°bullseye¡±)
Ubuntu 20.04
0x02 ´¦Öý¨Òé
Ŀǰ´Ë©¶´ÒѾÐÞ¸´£¬½¨Òé²Î¿¼Linux¸÷¿¯Ðа汾µÄ¹Ù·½Í¨¸æ¼°Ê±Éý¼¶¸üÐÂ:
RHEL 8£º
https://access.redhat.com/security/cve/CVE-2021-3560
Fedora 21¼°¸ü¸ß°æ±¾£º
https://bugzilla.redhat.com/show_bug.cgi?id=1967424
Debian testing (¡°bullseye¡±)£º
https://security-tracker.debian.org/tracker/CVE-2021-3560
Ubuntu 20.04£º
https://ubuntu.com/security/CVE-2021-3560
0x03 ²Î¿¼Á´½Ó
https://access.redhat.com/security/cve/CVE-2021-3560
https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/
https://www.theregister.com/2021/06/11/linux_polkit_package_patched/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3560
0x04 ʱ¼äÏß
2021-06-03 RedHatÐû²¼Äþ¾²Í¨¸æ
2021-06-11 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/