
Un testbed per CVE-2016-0728, un bug di leak/overflow del refcount in Linux
Questa repository contiene un programma di test per CVE-2016-0728, un bug di refcount leak e overflow in Linux, che porta a un use-after-free.
Il bug è stato trovato e spiegato da Perception Point. Non sono affiliato a loro.
Welcome to the CVE-2016-0728 testbed
sizeof(struct msg_msg) == 0x30, sizeof(struct key) == 0xb8
PID: 27673, UID: (1000/1000)
Keyring: 1b66e5d6, "test-1a328d6e"
Usage: 1
Press a key: (f)ork (i)ncref (a)uto-incref (r)evoke (h)eap-spray (s)hell (q)uit
Sul mio sistema di test, una shell di root poteva essere ottenuta nel seguente modo:
revokeexecl("/bin/sh", "sh", NULL)Ho trovato utile eseguire watch -n0.1 cat /proc/keys per vedere cosa
sta succedendo.
Questo codice è stato testato solo su x86-64, ma dovrebbe funzionare anche su altre
architetture, perché non ho usato offset magici, ma ho copiato le
definizioni delle strutture dagli header di Linux e ho usato sizeof
(eccetto per il fatto che ho hard-codato gli indirizzi di prepare_kernel_cred e
commit_creds).