Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CVE-2023-20938 — Analisi tecnica ed exploit proof-of-concept per CVE-2023-20938, una vulnerabilità use-after-free nel driver Binder del kernel Android che consente l'escalation dei privilegi locali. | Kitploit
Strumenti/GitHubGitHub/jaf0rk/cve-2023-20938
Sicurezza AndroidAnalisi delle VulnerabilitàExploitBinary Exploitation
GitHubjaf0rk/cve-2023-20938

CVE-2023-20938

Analisi tecnica ed exploit proof-of-concept per CVE-2023-20938, una vulnerabilità use-after-free nel driver Binder del kernel Android che consente l'escalation dei privilegi locali.

Vedi Repository
1373 mesi faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

CVE-2023-20938

English

Analisi della vulnerabilità

  1. Il client A e il client B stabiliscono una connessione Binder tramite il context manager servicemanager
  2. A crea il node 0xbeef (node = binder_new_node(proc, fp);), B fa riferimento al node 0xbeef tramite ref->target_node
  3. B prima gestisce correttamente target_node 0xbeef e inserisce la transazione binder_transaction che fa riferimento a target_node 0xbeef nella coda delle transazioni di A (binder_enqueue_work_ilocked(&t->work, &proc->todo);), consentendo ad A di fare nuovamente riferimento al puntatore pendente liberato
  4. B utilizza un offsets_size non allineato per entrare nel codice di gestione degli errori (IS_ALIGNED(tr->offsets_size, sizeof(binder_size_t))), facendo sì che un buffer_offset ancora pari a 0 venga passato alla funzione binder_transaction_buffer_release, innescando così la vulnerabilità
  5. La funzione binder_transaction_buffer_release chiama la funzione binder_dec_node_nilocked tramite binder_dec_node, decrementando il contatore di riferimenti local_strong_refs del node 0xbeef; tuttavia, l'istanza del node dispone di più contatori di riferimenti ed elenchi di riferimenti e il rilascio viene innescato solo quando tutti questi contatori vengono azzerati
  6. La chiusura del binder di B attiva la funzione binder_cleanup_ref_olocked; in questo momento viene chiamata anche binder_dec_node_nilocked e, quando binder_dec_node_nilocked restituisce true, il puntatore ref->node che punta al node (0xbeef) non verrà azzerato
  7. Successivamente verrà chiamata binder_free_ref; nella funzione binder_free_ref il node 0xbeef viene liberato
  8. A farà nuovamente riferimento al node 0xbeef già liberato nella funzione binder_thread_read

Note aggiuntive: In un ambiente Android reale, un'applicazione con permessi ordinari non può registrare servizi tramite servicemanager, ma può realizzare il collegamento dei due processi tramite ITokenManager; questo caso di test utilizza appunto ITokenManager

Note

  1. Makefile: file make; è possibile modificare la directory di output al suo interno
  2. Configurazione dell'emulatore Cuttlefish
  3. Ambiente di compilazione del kernel: la versione dell'ambiente kernel in cui ho innescato la vulnerabilità è android12-5.10.136_r00, con architettura hardware x86_64
root@kitploit:~
commit ee965fe12def46132d0087a9f353750d717e717c (HEAD -> android12-5.10.136_r00, tag: android12-5.10.136_r00)
Merge: b7247246f637 fb39cdb9eac1
Author: Greg Kroah-Hartman <[email protected]>
Date:   Tue Aug 16 12:45:36 2022 +0200
  1. Eseguendo aapk nell'emulatore Android, si vedrà il seguente log di crash KASAN:
root@kitploit:~
[   43.177167] ==================================================================
[   43.178189] BUG: KASAN: use-after-free in binder_ioctl+0x48de/0x50b0
[   43.178438] Read of size 8 at addr ffff888116e99d58 by task poc/89
[   43.178646] 
[   43.179102] CPU: 0 PID: 89 Comm: poc Not tainted 5.4.219 #1
[   43.179309] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
[   43.179766] Call Trace:
[   43.180332]  dump_stack+0x76/0x9c
[   43.180514]  ? binder_ioctl+0x48de/0x50b0
[   43.180738]  print_address_description.constprop.0+0x16/0x200
[   43.180962]  ? binder_ioctl+0x48de/0x50b0
[   43.181131]  ? binder_ioctl+0x48de/0x50b0
[   43.181303]  __kasan_report.cold+0x1d/0x35
[   43.181464]  ? binder_ioctl+0x48de/0x50b0
[   43.181626]  kasan_report+0x10/0x20
[   43.181761]  binder_ioctl+0x48de/0x50b0
[   43.181966]  ? switch_mm_irqs_off+0x388/0xd80
[   43.182127]  ? __switch_to_asm+0x42/0x80
[   43.182250]  ? binder_thread_write+0x2070/0x2070
[   43.182392]  ? __schedule+0x71b/0x18b0
[   43.182513]  ? io_schedule_timeout+0x150/0x150
[   43.182660]  ? hrtimer_start_range_ns+0x635/0xc10
[   43.182803]  ? wait_woken+0x1c0/0x1c0
[   43.182944]  ? hrtimer_try_to_cancel+0x19/0x3f0
[   43.183092]  ? do_nanosleep+0x246/0x4c0
[   43.183218]  ? schedule_timeout_idle+0x50/0x50
[   43.183363]  ? _raw_spin_unlock_irqrestore+0x36/0x70
[   43.183519]  ? memset+0x20/0x40
[   43.183632]  do_vfs_ioctl+0x91e/0xef0
[   43.183759]  ? selinux_file_ioctl+0x36f/0x510
[   43.183896]  ? ioctl_preallocate+0x1a0/0x1a0
[   43.184034]  ? selinux_bprm_set_creds+0xcb0/0xcb0
[   43.184182]  ? memset+0x20/0x40
[   43.184289]  ? __rseq_handle_notify_resume+0x61d/0xb10
[   43.184458]  ? __x64_sys_rseq+0x4f0/0x4f0
[   43.184600]  ? security_file_ioctl+0x4b/0x90
[   43.184742]  ksys_ioctl+0x59/0x90
[   43.184853]  ? switch_fpu_return+0xc2/0x210
[   43.184987]  __x64_sys_ioctl+0x69/0xa0
[   43.185112]  ? prepare_exit_to_usermode+0x231/0x2c0
[   43.185260]  do_syscall_64+0x87/0x140
[   43.185384]  entry_SYSCALL_64_after_hwframe+0x5c/0xc1
[   43.185665] 
[   43.185836] Allocated by task 89:
[   43.186060]  save_stack+0x1b/0x80
[   43.186211]  __kasan_kmalloc.constprop.0+0xc2/0xd0
[   43.186380]  binder_new_node+0x49/0x870
[   43.186519]  binder_transaction+0x4002/0x5d20
[   43.186669]  binder_thread_write+0x454/0x2070
[   43.186816]  binder_ioctl+0xff9/0x50b0
[   43.186950]  do_vfs_ioctl+0x91e/0xef0
[   43.187070]  ksys_ioctl+0x59/0x90
[   43.187177]  __x64_sys_ioctl+0x69/0xa0
[   43.187296]  do_syscall_64+0x87/0x140
[   43.187419]  entry_SYSCALL_64_after_hwframe+0x5c/0xc1
[   43.187628] 
[   43.187760] Freed by task 67:
[   43.187921]  save_stack+0x1b/0x80
[   43.188082]  __kasan_slab_free+0x12e/0x170
[   43.188286]  kfree+0x90/0x250
[   43.188485]  binder_deferred_func+0xba6/0x1040
[   43.188777]  process_one_work+0x6fe/0x1250
[   43.188989]  worker_thread+0x534/0x1200
[   43.189156]  kthread+0x314/0x3e0
[   43.189278]  ret_from_fork+0x35/0x40
[   43.189412] 
[   43.189509] The buggy address belongs to the object at ffff888116e99d00
[   43.189509]  which belongs to the cache kmalloc-128 of size 128
[   43.190587] The buggy address is located 88 bytes inside of
[   43.190587]  128-byte region [ffff888116e99d00, ffff888116e99d80)
[   43.191116] The buggy address belongs to the page:
[   43.191529] page:ffffea00045ba640 refcount:1 mapcount:0 mapping:ffff88811a801480 index:0x0
[   43.192177] flags: 0x200000000000200(slab)
[   43.192678] raw: 0200000000000200 dead000000000100 dead000000000122 ffff88811a801480
[   43.192969] raw: 0000000000000000 0000000000100010 00000001ffffffff 0000000000000000
[   43.193251] page dumped because: kasan: bad access detected
[   43.193438] 
[   43.193518] Memory state around the buggy address:
[   43.193928]  ffff888116e99c00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[   43.194205]  ffff888116e99c80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   43.194434] >ffff888116e99d00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[   43.194728]                                                     ^
[   43.194976]  ffff888116e99d80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   43.195291]  ffff888116e99e00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
[   43.195653] ==================================================================
[   43.196033] Disabling lock debugging due to kernel taint
[   43.197301] binder: release 89:89 transaction 12 in, still active
[   43.197576] binder: release 89:89 transaction 9 out, still active
[   43.198094] binder: send failed reply for transaction 12, target dead
[   43.198392] binder: send failed reply for transaction 9, target dead

TODO: exploit in fase di scrittura...

Scarica lo strumento