Exploiting Uses of Uninitialized Stack Variables in Linux Kernels to Leak Kernel Pointers

Exploiting Uses of Uninitialized Stack Variables in Linux Kernels to Leak Kernel Pointers
复制标题

DOI:
--
复制
发表时间:
2020
期刊:
--
影响因子:
--
通讯作者:
Haehyun Cho;Jinbum Park;Joonwon Kang;Tiffany Bao;Ruoyu Wang;Yan Shoshitaishvili;Adam Doupé;Gail-Joon Ahn
Haehyun Cho;Jinbum Park;Joonwon Kang;Tiffany Bao;Ruoyu Wang;Yan Shoshitaishvili;Adam Doupé;Gail-Joon Ahn
中科院分区:
其他
文献类型:
--
作者:
Haehyun Cho;Jinbum Park;Joonwon Kang;Tiffany Bao;Ruoyu Wang;Yan Shoshitaishvili;Adam Doupé;Gail-Joon Ahn

文献摘要

被引文献

相似文献

信息泄漏是Linux内核中最常见的漏洞类型。其中许多是由于使用未初始化的变量或数据结构引起的。一般认为,Linux内核中的大多数信息泄漏都是低风险的,并且由于难以(甚至不可能)利用而不会产生严重影响。因此,开发人员和安全分析师没有足够的注意力来缓解这些漏洞。因此,这些漏洞通常被分配较低的CVSS分数或没有分配任何CVE。此外,许多解决未初始化数据的补丁使用了Linux内核中的漏洞,但这些漏洞不被接受,导致数十亿Linux系统易受攻击。然而,Linux内核中的信息泄漏漏洞并不像人们认为的那样风险低。在本文中,我们提出了一个通用的方法,转换在Linux内核基于堆栈的信息泄漏到内核指针泄漏,这可以用来击败现代的安全防御,如KASLR。以触发Linux内核信息泄漏的漏洞为例,我们的方法自动将其转换为高度影响力的漏洞,泄漏指向内核函数或内核堆栈的指针。我们在Linux内核中的四个已知的CVE和一个安全补丁上评估了我们的方法,并证明了它的有效性。我们的发现为Linux内核开发人员和安全分析人员提供了坚实的证据,以更认真地对待Linux内核中的信息泄漏。
Information leaks are the most prevalent type of vulnerabilities among all known vulnerabilities in Linux kernel. Many of them are caused by the use of uninitialized variables or data structures. It is generally believed that the majority of information leaks in Linux kernel are low-risk and do not have severe impact due to the difficulty (or even the impos-sibility) of exploitation. As a result, developers and security analysts do not pay enough attention to mitigating these vulnerabilities. Consequently, these vulnerabilities are usually assigned low CVSS scores or without any CVEs assigned. Moreover, many patches that address uninitialized data use bugs in Linux kernel are not accepted, leaving billions of Linux systems vulnerable. Nonetheless, information leak vulnerabilities in Linux kernel are not as low-risk as people believe. In this paper, we present a generic approach that converts stack-based information leaks in Linux kernel into kernel-pointer leaks, which can be used to defeat modern security defenses such as KASLR. Taking an exploit that triggers an information leak in Linux kernel, our approach automatically converts it into a highly impactful exploit that leaks pointers to either kernel functions or the kernel stack. We evaluate our approach on four known CVEs and one security patch in Linux kernel and demonstrate its effectiveness. Our findings provide solid evidence for Linux kernel developers and security analysts to treat information leaks in Linux kernel more seriously.