В ядре Linux устранена следующая уязвимость:
net: mctp: сохранить ссылку на устройство маршрута в mctp_route_lookup()
mctp_route_lookup() использует rt->dev без ссылки на него.
mctp_route_lookup_single() возвращает маршрут только под RCU, поэтому
устройство маршрута может быть отключено одновременно: mctp_dev_put() удаляет
последняя ссылка и синхронно kfree() mdev->addrs. mctp_dev_saddr()
затем читает rt->dev->addrs[0], давая доступное использование после освобождения
непривилегированный локальный пользователь AF_MCTP на пути приема/пересылки (нет
Требуется CAP_NET_RAW):
ОШИБКА: KASAN: использование плиты после освобождения в mctp_route_lookup
Чтение размера 1 по адресу addr... с помощью задачи mctp_uaf/...
mctp_route_lookup
mctp_pkttype_receive
Освобожден заданием...:
свободный
mctp_dev_put
mctp_dev_notify
В том же окне mctp_dst_from_route() -> mctp_dev_hold() также
увеличивает счетчик ссылок, который уже достиг нуля
(«refcount_t: добавление 0... mctp_dev_hold»).
Это вновь вводит класс использования после освобождения CVE-2023-3439: источник
поиск адреса перенесен перед точкой назначения.
ссылку на его устройство.
Возьмите ссылку с помощью refcount_inc_not_zero(), прежде чем касаться rt->dev,
пропустить устройство, которое уже мертво, и удалить ссылку, как только
пункт назначения взял свое.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: net: mctp: hold a reference to the route device in mctp_route_lookup() mctp_route_lookup() uses rt->dev without holding a reference on it. mctp_route_lookup_single() returns the route under RCU only, so the route's device can be torn down concurrently: mctp_dev_put() drops the last reference and synchronously kfree()s mdev->addrs. mctp_dev_saddr() then reads rt->dev->addrs[0], giving a use-after-free reachable by an unprivileged local AF_MCTP user on the receive/forwarding path (no CAP_NET_RAW required): BUG: KASAN: slab-use-after-free in mctp_route_lookup Read of size 1 at addr ... by task mctp_uaf/... mctp_route_lookup mctp_pkttype_receive Freed by task ...: kfree mctp_dev_put mctp_dev_notify In the same window mctp_dst_from_route() -> mctp_dev_hold() also increments a refcount that has already reached zero ("refcount_t: addition on 0 ... mctp_dev_hold"). This reintroduces the use-after-free class of CVE-2023-3439: the source address lookup was moved ahead of the point where the destination takes its device reference. Take a reference with refcount_inc_not_zero() before touching rt->dev, skip a device that is already dead, and drop the reference once the destination has taken its own.
Характеристики атаки
Последствия
Строка CVSS v3.1