
Analyse technique et exploit de preuve de concept pour CVE-2023-20938, une vulnérabilité use-after-free dans le pilote Binder du noyau Android, permettant une escalade de privilèges locaux.
Remarque supplémentaire : Dans un environnement Android réel, une application ordinaire ne peut pas enregistrer de services via servicemanager, mais elle peut utiliser ITokenManager pour établir un lien entre deux processus. Ce cas de test utilise ITokenManager.
commit ee965fe12def46132d0087a9f353750d717e717c (HEAD -> android12-5.10.136_r00, tag: android12-5.10.136_r00)
Merge: b7247246f637 fb39cdb9eac1
Author: Greg Kroah-Hartman <[email protected]>
Date: Tue Aug 16 12:45:36 2022 +0200
[ 43.177167] ==================================================================
[ 43.178189] BUG: KASAN: use-after-free in binder_ioctl+0x48de/0x50b0
[ 43.178438] Read of size 8 at addr ffff888116e99d58 by task poc/89
[ 43.178646]
[ 43.179102] CPU: 0 PID: 89 Comm: poc Not tainted 5.4.219 #1
[ 43.179309] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
[ 43.179766] Call Trace:
[ 43.180332] dump_stack+0x76/0x9c
[ 43.180514] ? binder_ioctl+0x48de/0x50b0
[ 43.180738] print_address_description.constprop.0+0x16/0x200
[ 43.180962] ? binder_ioctl+0x48de/0x50b0
[ 43.181131] ? binder_ioctl+0x48de/0x50b0
[ 43.181303] __kasan_report.cold+0x1d/0x35
[ 43.181464] ? binder_ioctl+0x48de/0x50b0
[ 43.181626] kasan_report+0x10/0x20
[ 43.181761] binder_ioctl+0x48de/0x50b0
[ 43.181966] ? switch_mm_irqs_off+0x388/0xd80
[ 43.182127] ? __switch_to_asm+0x42/0x80
[ 43.182250] ? binder_thread_write+0x2070/0x2070
[ 43.182392] ? __schedule+0x71b/0x18b0
[ 43.182513] ? io_schedule_timeout+0x150/0x150
[ 43.182660] ? hrtimer_start_range_ns+0x635/0xc10
[ 43.182803] ? wait_woken+0x1c0/0x1c0
[ 43.182944] ? hrtimer_try_to_cancel+0x19/0x3f0
[ 43.183092] ? do_nanosleep+0x246/0x4c0
[ 43.183218] ? schedule_timeout_idle+0x50/0x50
[ 43.183363] ? _raw_spin_unlock_irqrestore+0x36/0x70
[ 43.183519] ? memset+0x20/0x40
[ 43.183632] do_vfs_ioctl+0x91e/0xef0
[ 43.183759] ? selinux_file_ioctl+0x36f/0x510
[ 43.183896] ? ioctl_preallocate+0x1a0/0x1a0
[ 43.184034] ? selinux_bprm_set_creds+0xcb0/0xcb0
[ 43.184182] ? memset+0x20/0x40
[ 43.184289] ? __rseq_handle_notify_resume+0x61d/0xb10
[ 43.184458] ? __x64_sys_rseq+0x4f0/0x4f0
[ 43.184600] ? security_file_ioctl+0x4b/0x90
[ 43.184742] ksys_ioctl+0x59/0x90
[ 43.184853] ? switch_fpu_return+0xc2/0x210
[ 43.184987] __x64_sys_ioctl+0x69/0xa0
[ 43.185112] ? prepare_exit_to_usermode+0x231/0x2c0
[ 43.185260] do_syscall_64+0x87/0x140
[ 43.185384] entry_SYSCALL_64_after_hwframe+0x5c/0xc1
[ 43.185665]
[ 43.185836] Allocated by task 89:
[ 43.186060] save_stack+0x1b/0x80
[ 43.186211] __kasan_kmalloc.constprop.0+0xc2/0xd0
[ 43.186380] binder_new_node+0x49/0x870
[ 43.186519] binder_transaction+0x4002/0x5d20
[ 43.186669] binder_thread_write+0x454/0x2070
[ 43.186816] binder_ioctl+0xff9/0x50b0
[ 43.186950] do_vfs_ioctl+0x91e/0xef0
[ 43.187070] ksys_ioctl+0x59/0x90
[ 43.187177] __x64_sys_ioctl+0x69/0xa0
[ 43.187296] do_syscall_64+0x87/0x140
[ 43.187419] entry_SYSCALL_64_after_hwframe+0x5c/0xc1
[ 43.187628]
[ 43.187760] Freed by task 67:
[ 43.187921] save_stack+0x1b/0x80
[ 43.188082] __kasan_slab_free+0x12e/0x170
[ 43.188286] kfree+0x90/0x250
[ 43.188485] binder_deferred_func+0xba6/0x1040
[ 43.188777] process_one_work+0x6fe/0x1250
[ 43.188989] worker_thread+0x534/0x1200
[ 43.189156] kthread+0x314/0x3e0
[ 43.189278] ret_from_fork+0x35/0x40
[ 43.189412]
[ 43.189509] The buggy address belongs to the object at ffff888116e99d00
[ 43.189509] which belongs to the cache kmalloc-128 of size 128
[ 43.190587] The buggy address is located 88 bytes inside of
[ 43.190587] 128-byte region [ffff888116e99d00, ffff888116e99d80)
[ 43.191116] The buggy address belongs to the page:
[ 43.191529] page:ffffea00045ba640 refcount:1 mapcount:0 mapping:ffff88811a801480 index:0x0
[ 43.192177] flags: 0x200000000000200(slab)
[ 43.192678] raw: 0200000000000200 dead000000000100 dead000000000122 ffff88811a801480
[ 43.192969] raw: 0000000000000000 0000000000100010 00000001ffffffff 0000000000000000
[ 43.193251] page dumped because: kasan: bad access detected
[ 43.193438]
[ 43.193518] Memory state around the buggy address:
[ 43.193928] ffff888116e99c00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 43.194205] ffff888116e99c80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 43.194434] >ffff888116e99d00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 43.194728] ^
[ 43.194976] ffff888116e99d80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[ 43.195291] ffff888116e99e00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[ 43.195653] ==================================================================
[ 43.196033] Disabling lock debugging due to kernel taint
[ 43.197301] binder: release 89:89 transaction 12 in, still active
[ 43.197576] binder: release 89:89 transaction 9 out, still active
[ 43.198094] binder: send failed reply for transaction 12, target dead
[ 43.198392] binder: send failed reply for transaction 9, target dead
TODO : écriture de l'exploit en cours...