oss-sec mailing list archives
Re: CVE-2022-2602 - Linux kernel io_uring UAF
From: Thadeu Lima de Souza Cascardo <cascardo () canonical com>
Date: Thu, 27 Oct 2022 13:50:48 -0300
On Tue, Oct 18, 2022 at 01:59:51PM -0300, Thadeu Lima de Souza Cascardo wrote:
A local privilege escalation vulnerabilty involving Unix socket Garbage Collection and io_uring was reported and fixed as: 0091bfc81741b8d3aeb3b7ab8636f911b2de6e80 ("io_uring/af_unix: defer registered files gc to io_uring release") The vulnerability is a use-after-free that happens when an io_uring request is being processed on a registered file and the Unix GC runs and frees the io_uring fd and all the registered fds. The order at which the Unix GC processes the inflight fds may lead to registered fds be freed before the io_uring is released and has the chance to unregister and wait for such requests to finish. One way to trigger this race condition is to use userfaultfd and other similar strategies that cause the request to be held waiting for the attacker to trigger the free. This issue was reported as ZDI-CAN-17428 and has been assigned CVE-2022-2602. It affects upstream stable 5.4.y, 5.15.y and later versions. 5.10.y may be mitigated by the fact that commit 0f2122045b946241a9e549c2a76cea54fa58a7ff ("io_uring: don't rely on weak ->files references") is present, but it is safer to apply the fixes. A PoC will be posted in 7 days, on October 25th. Cascardo.
Sorry about posting this late, but here it is. Cascardo.
Attachment:
poc.c
Description:
Current thread:
- CVE-2022-2602 - Linux kernel io_uring UAF Thadeu Lima de Souza Cascardo (Oct 18)
- Re: CVE-2022-2602 - Linux kernel io_uring UAF David Bouman (Oct 19)
- Re: CVE-2022-2602 - Linux kernel io_uring UAF Thadeu Lima de Souza Cascardo (Oct 27)
- <Possible follow-ups>
- Re: CVE-2022-2602 - Linux kernel io_uring UAF John Smith (Nov 07)
- Re: CVE-2022-2602 - Linux kernel io_uring UAF Adam Reynolds (Nov 08)