Linux PolkitȨÏÞÌáÉý·ì϶£¨CVE-2021-3560£©

°ä²¼¹¦·ò 2021-06-11

0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2021-3560

ʱ    ¼ä

2021-06-11

Àà    ÐÍ

LPE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

·ñ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

µÍ

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

PolkitÊǺܶàLinux ¿¯ÐаæÉÏĬÈÏ×°ÖõÄϵͳ·þÎñ£¬Ëü±»systemdʹÓã¬ËùÒÔÈκÎʹÓÃsystemdµÄLinux¿¯Ðаæ³ÇÊÐʹÓÃpolkit¡£

2021Äê06ÔÂ03ÈÕ£¬RedHat°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËLinux  PolkitÖÐÒ»¸ö´æÔÚÁË7ÄêµÄȨÏÞÌáÉý·ì϶£¨CVE-2021-3560£©£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜ»ñµÃϵͳÉ쵀 root ȨÏÞ¡£Ä¿Ç°GitHubµÄ°²È«×êÑÐÔ±ÒѾ­¹«¿ªÅû¶ÁË´Ë·ì϶µÄϸ½ÚºÍPoC¡£

 

·ì϶ϸ½Ú

¸Ã·ì϶ÊÇÓÉÓÚµ±ÒªÇó¹ý³ÌÔÚŲÓÃpolkit_system_bus_name_get_creds_sync ֮ǰÓë dbus-daemon ¶Ï¿ªÏνÓʱ£¬¸Ã¹ý³ÌÎÞ·¨»ñµÃ¹ý³ÌµÄΨһuidºÍpid£¬Ò²ÎÞ·¨ÑéÖ¤ÒªÇó¹ý³ÌµÄȨÏÞ¡£

Äܹ»Í¨¹ýÆô¶¯dbus-sendºÅÁÔÚ polkit ÈÔÔÚ´¦ÖÃÒªÇóµÄ¹ý³ÌÖÐÖÕÖ¹ËüÀ´´¥·¢´Ë·ì϶£¬ÔÚÈÏÖ¤ÒªÇóÖÐÖÕÖ¹dbus-send£¨Ò»¸ö¹ý³Ì¼äͨѶºÅÁ»áµ¼ÖÂÒ»¸öÃýÎó£¬ÓÉÓÚpolkit½«ÒªÇóÌṩһ¸ö²»ÔÙ´æÔÚµÄÏνӵÄUID£¨ÓÉÓÚ¸ÃÏνÓÒѱ»ÖÕÖ¹£©¡£¶øpolkit»áÒÔÒ»ÖÖÃýÎóµÄ·½Ê½´¦ÖôËÎÊÌ⣺Ëü²»»á»Ø¾øÕâ¸öÏνÓÒªÇ󣬶øÊǰÑÕâ¸öÒªÇóÊÓΪÀ´×ÔUIDΪ0µÄ¹ý³Ì¡£

×êÑÐÈËÔ±°µÊ¾£¬¸Ã·ì϶ºÜÈÝÒ×±»ÀûÓã¬Ö»±ØÒªÊ¹Óà bash¡¢kill ºÍ dbus-send µÈ³ß¶ÈÖն˹¤¾ßÖ´Ðм¸ÌõºÅÁî¼´¿É¡£

 

Ó°ÏìÁìÓò

RHEL 8

Fedora 21¼°¸ü¸ß°æ±¾

Debian testing (¡°bullseye¡±)

Ubuntu 20.04

 

 

0x02 ´ëÖý¨Òé

Ŀǰ´Ë·ì϶ÒѾ­½¨¸´£¬½¨Òé²Î¿¼Linux¸÷¿¯Ðа汾µÄ¹Ù·½¹«¸æÊµÊ±Éý¼¶¸üÐÂ:

RHEL 8£º

https://access.redhat.com/security/cve/CVE-2021-3560


Fedora 21¼°¸ü¸ß°æ±¾£º

https://bugzilla.redhat.com/show_bug.cgi?id=1967424


Debian testing (¡°bullseye¡±)£º

https://security-tracker.debian.org/tracker/CVE-2021-3560


Ubuntu 20.04£º

https://ubuntu.com/security/CVE-2021-3560

 

0x03 ²Î¿¼Á´½Ó

https://access.redhat.com/security/cve/CVE-2021-3560

https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/

https://www.theregister.com/2021/06/11/linux_polkit_package_patched/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3560

 

0x04 ¹¦·òÏß

2021-06-03  RedHat°ä²¼°²È«²¼¸æ

2021-06-11  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png