Linux PolkitȨÏÞÌáÉýÎó²î£¨CVE-2021-3560£©

Ðû²¼Ê±¼ä 2021-06-11

0x00 Îó²î¸ÅÊö

CVE   ID

CVE-2021-3560

ʱ    ¼ä

2021-06-11

Àà    ÐÍ

LPE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

·ñ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

µÍ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

PolkitÊÇÐí¶àLinux ¿¯ÐаæÉÏĬÈÏ×°ÖõÄϵͳЧÀÍ£¬£¬£¬£¬£¬£¬£¬Ëü±»systemdʹÓ㬣¬£¬£¬£¬£¬£¬ÒÔÊÇÈκÎʹÓÃsystemdµÄLinux¿¯Ðа涼»áʹÓÃpolkit ¡£¡£¡£

2021Äê06ÔÂ03ÈÕ£¬£¬£¬£¬£¬£¬£¬RedHatÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËLinux  PolkitÖÐÒ»¸ö±£´æÁË7ÄêµÄȨÏÞÌáÉýÎó²î£¨CVE-2021-3560£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»»ñµÃϵͳÉ쵀 root ȨÏÞ ¡£¡£¡£ÏÖÔÚGitHubµÄÇå¾²Ñо¿Ô±ÒѾ­¹ûÕæÅû¶ÁË´ËÎó²îµÄϸ½ÚºÍPoC ¡£¡£¡£

 

Îó²îϸ½Ú

¸ÃÎó²îÊÇÓÉÓÚµ±ÇëÇóÀú³ÌÔÚŲÓÃpolkit_system_bus_name_get_creds_sync ֮ǰÓë dbus-daemon ¶Ï¿ªÅþÁ¬Ê±£¬£¬£¬£¬£¬£¬£¬¸ÃÀú³ÌÎÞ·¨»ñµÃÀú³ÌµÄΨһuidºÍpid£¬£¬£¬£¬£¬£¬£¬Ò²ÎÞ·¨ÑéÖ¤ÇëÇóÀú³ÌµÄȨÏÞ ¡£¡£¡£

¿ÉÒÔͨ¹ýÆô¶¯dbus-sendÏÂÁÔÚ polkit ÈÔÔÚ´¦Öóͷ£ÇëÇóµÄÀú³ÌÖÐÖÕÖ¹ËüÀ´´¥·¢´ËÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÚÈÏÖ¤ÇëÇóÖÐÖÕÖ¹dbus-send£¨Ò»¸öÀú³Ì¼äͨѶÏÂÁ»áµ¼ÖÂÒ»¸ö¹ýʧ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚpolkit½«ÒªÇóÌṩһ¸ö²»ÔÙ±£´æµÄÅþÁ¬µÄUID£¨ÓÉÓÚ¸ÃÅþÁ¬Òѱ»ÖÕÖ¹£© ¡£¡£¡£¶øpolkit»áÒÔÒ»ÖÖ¹ýʧµÄ·½·¨´¦Öóͷ£´ËÎÊÌ⣺Ëü²»»á¾Ü¾øÕâ¸öÅþÁ¬ÇëÇ󣬣¬£¬£¬£¬£¬£¬¶øÊǰÑÕâ¸öÇëÇóÊÓΪÀ´×ÔUIDΪ0µÄÀú³Ì ¡£¡£¡£

Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îºÜÈÝÒ×±»Ê¹Ó㬣¬£¬£¬£¬£¬£¬Ö»ÐèҪʹÓà bash¡¢kill ºÍ dbus-send µÈ±ê×¼Öն˹¤¾ßÖ´Ðм¸ÌõÏÂÁî¼´¿É ¡£¡£¡£

 

Ó°Ïì¹æÄ£

RHEL 8

Fedora 21¼°¸ü¸ß°æ±¾

Debian testing (¡°bullseye¡±)

Ubuntu 20.04

 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ´ËÎó²îÒѾ­ÐÞ¸´£¬£¬£¬£¬£¬£¬£¬½¨Òé²Î¿¼Linux¸÷¿¯Ðа汾µÄ¹Ù·½Í¨¸æÊµÊ±Éý¼¶¸üÐÂ:

RHEL 8£º

https://access.redhat.com/security/cve/CVE-2021-3560


Fedora 21¼°¸ü¸ß°æ±¾£º

https://bugzilla.redhat.com/show_bug.cgi?id=1967424


Debian testing (¡°bullseye¡±)£º

https://security-tracker.debian.org/tracker/CVE-2021-3560


Ubuntu 20.04£º

https://ubuntu.com/security/CVE-2021-3560

 

0x03 ²Î¿¼Á´½Ó

https://access.redhat.com/security/cve/CVE-2021-3560

https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/

https://www.theregister.com/2021/06/11/linux_polkit_package_patched/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3560

 

0x04 ʱ¼äÏß

2021-06-03  RedHatÐû²¼Ç徲ͨ¸æ

2021-06-11  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png