Linux PolkitȨÏÞÌáÉý©¶´£¨CVE-2021-3560£©

Ðû²¼Ê±¼ä 2021-06-11

0x00 ©¶´¸ÅÊö

CVE   ID

CVE-2021-3560

ʱ    ¼ä

2021-06-11

Àà    ÐÍ

LPE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

·ñ

Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

µÍ

PoC/EXP

ÒѹûÈ»

ÔÚÒ°ÀûÓÃ


 

0x01 ©¶´ÏêÇé

image.png

PolkitÊÇÐí¶àLinux ¿¯ÐаæÉÏĬÈϰ²×°µÄϵͳ·þÎñ £¬Ëü±»systemdʹÓà £¬ËùÒÔÈκÎʹÓÃsystemdµÄLinux¿¯Ðа涼ÊÐʹÓÃpolkit ¡£

2021Äê06ÔÂ03ÈÕ £¬RedHatÐû²¼Äþ¾²Í¨¸æ £¬ÐÞ¸´ÁËLinux  PolkitÖÐÒ»¸ö´æÔÚÁË7ÄêµÄȨÏÞÌáÉý©¶´£¨CVE-2021-3560£© £¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8 £¬ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷ÕßÄܹ»»ñµÃϵͳÉ쵀 root ȨÏÞ ¡£Ä¿Ç°GitHubµÄÄþ¾²Ñо¿Ô±ÒѾ­¹ûÈ»Åû¶ÁË´Ë©¶´µÄϸ½ÚºÍPoC ¡£

 

©¶´Ï¸½Ú

¸Ã©¶´ÊÇÓÉÓÚµ±ÇëÇó½ø³ÌÔÚµ÷ÓÃpolkit_system_bus_name_get_creds_sync ֮ǰÓë dbus-daemon ¶Ï¿ªÁ¬½Óʱ £¬¸Ã½ø³ÌÎÞ·¨»ñµÃ½ø³ÌµÄΨһuidºÍpid £¬Ò²ÎÞ·¨ÑéÖ¤ÇëÇó½ø³ÌµÄȨÏÞ ¡£

¿ÉÒÔͨ¹ýÆô¶¯dbus-sendÃüÁÔÚ polkit ÈÔÔÚ´¦ÖÃÇëÇóµÄ¹ý³ÌÖÐÖÕÖ¹ËüÀ´´¥·¢´Ë©¶´ £¬ÔÚÈÏÖ¤ÇëÇóÖÐÖÕÖ¹dbus-send£¨Ò»¸ö½ø³Ì¼äͨÐÅÃüÁ»áµ¼ÖÂÒ»¸ö´íÎó £¬ÒòΪpolkit½«ÒªÇóÌṩһ¸ö²»ÔÙ´æÔÚµÄÁ¬½ÓµÄUID£¨ÒòΪ¸ÃÁ¬½ÓÒѱ»ÖÕÖ¹£© ¡£¶øpolkit»áÒÔÒ»ÖÖ´íÎóµÄ·½Ê½´¦ÖôËÎÊÌ⣺Ëü²»»á¾Ü¾øÕâ¸öÁ¬½ÓÇëÇó £¬¶øÊǰÑÕâ¸öÇëÇóÊÓΪÀ´×ÔUIDΪ0µÄ½ø³Ì ¡£

Ñо¿ÈËÔ±ÌåÏÖ £¬¸Ã©¶´ºÜÈÝÒ×±»ÀûÓà £¬Ö»ÐèҪʹÓà bash¡¢kill ºÍ dbus-send µÈ³ß¶ÈÖն˹¤¾ßÖ´Ðм¸ÌõÃüÁî¼´¿É ¡£

 

Ó°Ï췶Χ

RHEL 8

Fedora 21¼°¸ü¸ß°æ±¾

Debian testing (¡°bullseye¡±)

Ubuntu 20.04

 

 

0x02 ´¦Öý¨Òé

Ŀǰ´Ë©¶´ÒѾ­ÐÞ¸´ £¬½¨Òé²Î¿¼Linux¸÷¿¯Ðа汾µÄ¹Ù·½Í¨¸æ¼°Ê±Éý¼¶¸üÐÂ:

RHEL 8£º

https://access.redhat.com/security/cve/CVE-2021-3560


Fedora 21¼°¸ü¸ß°æ±¾£º

https://bugzilla.redhat.com/show_bug.cgi?id=1967424


Debian testing (¡°bullseye¡±)£º

https://security-tracker.debian.org/tracker/CVE-2021-3560


Ubuntu 20.04£º

https://ubuntu.com/security/CVE-2021-3560

 

0x03 ²Î¿¼Á´½Ó

https://access.redhat.com/security/cve/CVE-2021-3560

https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/

https://www.theregister.com/2021/06/11/linux_polkit_package_patched/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3560

 

0x04 ʱ¼äÏß

2021-06-03  RedHatÐû²¼Äþ¾²Í¨¸æ

2021-06-11  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png