RetSpill: Igniting User-Controlled Data to Burn Away Linux Kernel Protections

RetSpill: Igniting User-Controlled Data to Burn Away Linux Kernel Protections
复制标题

DOI:
10.1145/3576915.3623220
复制
发表时间:
2023-11
期刊:
Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Kyle Zeng;Zhenpeng Lin;Kangjie Lu;Xinyu Xing;Ruoyu Wang;Adam Doupé;Yan Shoshitaishvili;Tiffany Bao
Kyle Zeng;Zhenpeng Lin;Kangjie Lu;Xinyu Xing;Ruoyu Wang;Adam Doupé;Yan Shoshitaishvili;Tiffany Bao
中科院分区:
其他
文献类型:
--
作者:
Kyle Zeng;Zhenpeng Lin;Kangjie Lu;Xinyu Xing;Ruoyu Wang;Adam Doupé;Yan Shoshitaishvili;Tiffany Bao

文献摘要

相似文献

利用控制流劫持原语(CFHP)获取根权限对于试图利用Linux内核漏洞的攻击者来说至关重要。这样的攻击已经变得越来越难以捉摸的安全研究人员提出了有能力的内核安全缓解,导致开发复杂的(和,作为一个权衡,脆弱和不可靠的)攻击技术,以恢复it.In本文中,我们提出RetSpill,一个强大而优雅的开发技术,采用用户空间数据已经存在于内核堆栈上的特权升级的复杂性。RetSpill利用了在内核堆栈上临时存储数据的常见做法,例如在从用户空间切换到内核空间期间保留用户空间寄存器值时。我们进行了系统的研究,并确定了四个常见的做法,溢出用户空间数据的内核堆栈。虽然这种做法完全符合内核的安全规范,但它在与控制流劫持(CFH)漏洞配对时引入了一种新的利用途径,使RetSpill能够可靠地将此类漏洞直接转化为权限提升。此外,RetSpill可以绕过目前部署在Linux内核中的许多防御。为了证明这个问题的严重性,我们收集了22个真实世界的内核漏洞,并构建了一个半自动化的工具,该工具以半自动化的方式滥用故意存储的堆栈上的用户空间数据来利用内核。我们的工具为22个CFH漏洞中的20个生成了端到端权限提升漏洞。最后,我们提出了一种新的防御攻击的机制。
Leveraging a control flow hijacking primitive (CFHP) to gain root privileges is critical to attackers striving to exploit Linux kernel vulnerabilities. Such attack has become increasingly elusive as security researchers propose capable kernel security mitigations, leading to the development of complex (and, as a trade-off, brittle and unreliable) attack techniques to regain it. In this paper, we obviate the need for complexity by proposing RetSpill, a powerful yet elegant exploitation technique that employs user space data already present on the kernel stack for privilege escalation. RetSpill exploits the common practice of temporarily storing data on the kernel stack, such as when preserving user space register values during a switch from the user space to the kernel space. We perform a systematic study and identify four common practices that spill user space data to the kernel stack. Although this practice is perfectly within the kernel's security specification, it introduces a new exploitation path when paired with a control flow hijacking (CFH) vulnerability, enabling RetSpill to turn such vulnerabilities directly into privilege escalation reliably. Moreover, RetSpill can bypass many defenses currently deployed in the Linux kernels. To demonstrate the severity of this problem, we collected 22 real-world kernel vulnerabilities and built a semi-automated tool that abuses intentionally-stored, on-stack user space data for kernel exploitation in a semi-automated fashion. Our tool generated end-to-end privilege escalation exploits for 20 out of 22 CFH vulnerabilities. Finally, we propose a new mechanism to defend against the attack.