
Exploit de estouro de buffer heap para CVE-2022-27666 na implementação IPsec ESP6 do kernel Linux. Inclui compilação do kernel, configuração de depuração com stub GDB e etapas de exploração para a versão 5.13.19.
Estouro de buffer de heap na implementação IPsec ESP6 do kernel Linux (linux 5.13.19).
Instalar dependências:
apt update && apt install -y \
build-essential bc bison flex \
libssl-dev libelf-dev libncurses-dev \
dwarves pahole gcc make wget xz-utils git python3 libfuse3-dev
Baixar e extrair:
cd /home/ubuntu/
wget https://cdn.kernel.org/pub/linux/kernel/v5.x/linux-5.13.19.tar.xz
tar xf linux-5.13.19.tar.xz
cd linux-5.13.19
Configurar:
cp /boot/config-$(uname -r) .config
make olddefconfig
# Enable full debug symbols and GDB support
scripts/config --enable CONFIG_DEBUG_INFO
scripts/config --enable CONFIG_DEBUG_INFO_DWARF4
scripts/config --disable CONFIG_DEBUG_INFO_REDUCED
scripts/config --enable CONFIG_FRAME_POINTER
scripts/config --enable CONFIG_GDB_SCRIPTS
# Build ESP modules — CVE target
scripts/config --module CONFIG_INET6_ESP
scripts/config --module CONFIG_INET_ESP
# Disable KASLR for easier debugging
scripts/config --disable CONFIG_RANDOMIZE_BASE
# Disable module signing to load unsigned modules
scripts/config --disable CONFIG_MODULE_SIG
scripts/config --disable CONFIG_MODULE_SIG_FORCE
scripts/config --disable CONFIG_SYSTEM_TRUSTED_KEYS
scripts/config --disable CONFIG_SYSTEM_REVOCATION_KEYS
# Disable BTF to avoid pahole build errors
scripts/config --disable CONFIG_DEBUG_INFO_BTF
# Disable watchdog to prevent panic/reboot during GDB breakpoints
scripts/config --disable CONFIG_SOFTLOCKUP_DETECTOR
scripts/config --disable CONFIG_HARDLOCKUP_DETECTOR
scripts/config --disable CONFIG_DETECT_HUNG_TASK
scripts/config --disable CONFIG_WQ_WATCHDOG
make olddefconfig
Compilar e instalar:
make -j$(nproc) 2>&1 | tee ~/build.log
make modules_install
make install
update-grub
# Find menu entry index
grep -E "menuentry|submenu" /boot/grub/grub.cfg | grep -v "^#" | head -20
# Set default (adjust index as needed)
vi /etc/default/grub
# GRUB_DEFAULT="1>2"
update-grub
reboot
Verificar após reinicialização:
uname -r # should print 5.13.19
# Auto-load esp6 on boot and load it now
echo "esp6" >> /etc/modules
modprobe esp6
# Verify
modinfo esp6
grep CONFIG_INET6_ESP /boot/config-5.13.19 # CONFIG_INET6_ESP=m
Desabilitar serviços desnecessários para acelerar a inicialização e evitar interferência durante os testes:
# Cloud / network wait
systemctl disable cloud-init cloud-config cloud-final \
cloud-init-local systemd-networkd-wait-online
# Prevent crash reporter from interfering with kernel panics
systemctl disable apport
# Prevent random disk I/O during testing
systemctl disable apt-daily apt-daily-upgrade \
apt-daily.timer apt-daily-upgrade.timer
# Not needed in a dev VM
systemctl disable snapd multipathd fwupd
IP=<VM-IP>
scp ubuntu@${IP}:~/linux-5.13.19/vmlinux .
scp ubuntu@${IP}:~/linux-5.13.19/net/ipv6/esp6.ko .
scp ubuntu@${IP}:/usr/bin/fusermount3 ./exploit/bin/
scp ubuntu@${IP}:/usr/lib/x86_64-linux-gnu/libfuse3.so.3 ./exploit/lib/
scp -r ubuntu@${IP}:/usr/include/fuse3 ./exploit/include/
Adicionar ao XML do domínio:
<domain type='kvm' xmlns:qemu='http://libvirt.org/schemas/domain/qemu/1.0'>
...
<qemu:commandline>
<qemu:arg value='-s'/>
</qemu:commandline>
</domain>
Adicionar dentro de <devices> no XML do domínio:
<filesystem type='mount' accessmode='passthrough'>
<source dir='/path/to/your/host/dir'/>
<target dir='hostshare'/>
</filesystem>
Montar dentro da VM:
mkdir -p /pwn
mount -t 9p -o trans=virtio hostshare /pwn