
CVE-2025-39866(UAF 및 경쟁 조건)에 대한 개념 증명
저자: Byte Reaper
이 POC는 CVE-2025-39866 취약점을 악용하려고 시도합니다. 이 취약점은 Linux 시스템 < 6.12.16에서 스레드에 대한 스핀락 부재로 인해 발생하는 경쟁 조건(race condition) 결함입니다. 첫 번째 스레드가 wb 구조체를 사용하려고 하는 동안 두 번째 스레드가 이 구조체를 해제하여, 첫 번째 스레드가 해제된 포인터를 다루게 되고 시스템 커널 패닉으로 이어집니다. 취약점 악용 아이디어는 다음과 같은 단계로 나눌 수 있습니다:
step 1 : Create thread 1 "main pid"
- get root dentry
- create file txt writeback target
- create strcut inode
- Create object wb
- save pointer wb in wb_old
Step 2:
- Create Thread 2 (kthread) that schedules a work item.
- The work item runs “inode_switch_wbs_work_fn” which updates “inode->i_wb” and schedules the critical free via “wb_put_many”.
step 3 :
- thread 2 : free wb_olb
- thread 1 -> pointer - free object wb (free old)
-> access free address -> crash kernel (segfault)
Linux x86_64
kernel linux < 6.12.16
1 - He created a Makefile and included these commands to compile and build the kernel module:
obj-m += exploit.o
KDIR := /usr/src/linux-headers-6.12.38+kali-amd64
PWD := $(shell pwd)
all:
make -C $(KDIR) M=$(PWD) modules
clean:
make -C $(KDIR) M=$(PWD) clean
# make clean
# make
1 - You will find a file named "exploit.ko," which is a kernel module. To load it into the kernel space, use the insmod tool :
# insmod exploit.ko
버그의 주요 문제는 스레드 동기화를 위한 "스핀락" 부재입니다. 여기서 해결 방법은 다음과 같습니다:
첫째 (Slab/Slub 할당), 각 스레드에 대해 특정 slab/slub을 할당하며, 어떤 스레드도 다른 스레드의 메모리 크기를 제어하거나 조작할 수 없습니다.
둘째 (동기화), 간섭과 경쟁 조건을 피하기 위해 Workqueue를 구성합니다. 각 스레드가 자신의 작업을 완료한 후 동시에 WB를 전환하거나 wb_wakeup_delayed 함수를 사용하는 대신 다른 스레드로 이동합니다.
셋째 (HLE/RTM): 커널에서 HLE/RTM 활성화는 프로세서 아키텍처에 따라 다르지만, 만약 이 두 기능을 지원한다면 왜 커널에서 사용하지 않을까요? 예를 들어 프로그램 흐름을 제어하거나 오류 발생 시 XBEGIN, XABORT, XEN 명령어를 통해 충돌 대신 다른 예외로 롤백(rollback)을 시도하는 데 사용할 수 있습니다.
MIT