docs: nf_tables (CVE-2024-1086) kernel confirmed vulnerable; module gap scoped
build / build (clang / debug) (push) Waiting to run
build / build (clang / default) (push) Waiting to run
build / build (gcc / debug) (push) Waiting to run
build / build (gcc / default) (push) Waiting to run
build / sanitizers (ASan + UBSan) (push) Waiting to run
build / clang-tidy (push) Waiting to run
build / drift-check (CISA KEV + Debian tracker) (push) Waiting to run
build / static-build (push) Waiting to run
build / build (clang / debug) (push) Waiting to run
build / build (clang / default) (push) Waiting to run
build / build (gcc / debug) (push) Waiting to run
build / build (gcc / default) (push) Waiting to run
build / sanitizers (ASan + UBSan) (push) Waiting to run
build / clang-tidy (push) Waiting to run
build / drift-check (CISA KEV + Debian tracker) (push) Waiting to run
build / static-build (push) Waiting to run
Ran the full methodology on the flagship kernel primitive:
- Built Notselwyn's public universal PoC on jammy 5.15.0-25 (below patched
branch 5.15.149) and ran it: hit the deliberate post-root `kernel BUG at
mm/slub.c:379` / panic — the cross-cache slab corruption fired. Kernel is
genuinely exploitable.
- Diffed technique: the module is an honest trigger+groom SCAFFOLD (real
NFT_GOTO+NFT_DROP double-free + msg_msg cg-96 groom) whose pipapo arb-write is
FALLBACK-DEPTH (exact pipapo_elem layout is a documented TODO) -> honest
EXPLOIT_FAIL. Notselwyn uses a heavier universal cross-cache -> dirty-pagetable
technique (~2000 LOC, multi-file, static libnftnl/libmnl, no per-kernel
offsets). Completing the module's full-chain is substantial dedicated
exploit-dev, not a spot-the-bug fix.
The piece that was actually broken and is now fixed+pushed is the offset
resolver (cd9bea6): env-provided offsets were wiped under kptr_restrict, which
blocked the entire --full-chain path. Recorded in docs/EXPLOITED.md.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0118iUgHY44hdRtANgyCmu7y
This commit is contained in:
+43
-7
@@ -88,14 +88,50 @@ tamper check).
|
|||||||
|---|---|---|
|
|---|---|---|
|
||||||
| `dirty_pipe` | CVE-2022-0847 | Ubuntu 22.04.0's 5.15.0-25.25 almost certainly carries the backported fix (USN-5317); `detect()` is version-only so says VULNERABLE. Needs a genuinely pre-fix kernel (e.g. 5.13.0-19, or mainline 5.16.10) to verify the exploit. |
|
| `dirty_pipe` | CVE-2022-0847 | Ubuntu 22.04.0's 5.15.0-25.25 almost certainly carries the backported fix (USN-5317); `detect()` is version-only so says VULNERABLE. Needs a genuinely pre-fix kernel (e.g. 5.13.0-19, or mainline 5.16.10) to verify the exploit. |
|
||||||
|
|
||||||
## Not yet exploit-tested (the bulk — ~30 modules)
|
## Kernel primitives — offset path fixed; `nf_tables` gap scoped (this session)
|
||||||
|
|
||||||
- **🟡 kernel primitives** (`nf_tables`, `nft_set_uaf`, `nft_payload`,
|
**Resolver bug fixed (`core/offsets.c`, commit `cd9bea6`).** The documented
|
||||||
`nft_fwd_dup`, `netfilter_xtcompat`, `af_packet`, `af_packet2`, `af_unix_gc`,
|
env-var offset override (`SKELETONKEY_MODPROBE_PATH` etc.) was **silently wiped on
|
||||||
`cls_route4`, `fuse_legacy`, `stackrot`, `sequoia`, `nft_pipapo`, `vsock_uaf`,
|
every default host**: `parse_symfile` reads `/proc/kallsyms`, which returns
|
||||||
`pintheft`): return `EXPLOIT_FAIL` by design; landing root needs a per-kernel
|
all-zero addresses under `kptr_restrict`, and then *unconditionally* zeroed
|
||||||
`--dump-offsets` + `--full-chain` (modprobe_path finisher) pass on a vulnerable
|
`modprobe_path`/`init_task` — clobbering the values `apply_env` had just set. Net
|
||||||
kernel.
|
effect: every `--full-chain` primitive reported "offsets couldn't be resolved"
|
||||||
|
even with correct offsets supplied. Now the all-zero path only clears fields it
|
||||||
|
tagged `OFFSETS_FROM_KALLSYMS` itself. **This was the blocker for the entire
|
||||||
|
primitive full-chain path.** Verified fixed on Ubuntu 22.04.0 / 5.15.0-25:
|
||||||
|
`--full-chain` now prints `modprobe_path=0x… (env)`, the finisher engages, and the
|
||||||
|
arb-write fires.
|
||||||
|
|
||||||
|
**`nf_tables` (CVE-2024-1086) — kernel CONFIRMED vulnerable; module gap scoped.**
|
||||||
|
Followed the full methodology (test → confirm kernel → pull PoC → diff):
|
||||||
|
- **Kernel is genuinely vulnerable.** Built Notselwyn's public universal PoC
|
||||||
|
(`github.com/Notselwyn/CVE-2024-1086`, musl-static) on jammy 5.15.0-25 (below the
|
||||||
|
patched branch 5.15.149) and ran it: it drove the exploit and hit the deliberate
|
||||||
|
post-exploitation `kernel BUG at mm/slub.c:379` / `Kernel panic` — i.e. the
|
||||||
|
cross-cache slab corruption fired. Kernel confirmed exploitable.
|
||||||
|
- **The difference.** The module (its own header is honest about this) is a
|
||||||
|
**trigger + groom scaffold**: it builds the `NFT_GOTO+NFT_DROP` verdict combo
|
||||||
|
that `nft_verdict_init()` fails to reject, fires the double-free, and runs the
|
||||||
|
`msg_msg` cg-96 groom — all real. But its arb-write is "FALLBACK-DEPTH": the
|
||||||
|
exact `pipapo_elem` layout + value-pointer offset needed to redirect the write
|
||||||
|
at `modprobe_path` is a documented TODO, so the write doesn't land → honest
|
||||||
|
`EXPLOIT_FAIL`. Notselwyn's working exploit uses a *different, heavier* technique
|
||||||
|
entirely — **universal cross-cache → dirty-pagetable** (arbitrary physical R/W,
|
||||||
|
no per-kernel offsets), ~2000 LOC across multiple files with static
|
||||||
|
`libnftnl`/`libmnl`.
|
||||||
|
- **Scope of the remaining fix.** Making `nf_tables --full-chain` land root means
|
||||||
|
either (a) completing the module's own per-kernel `pipapo_elem` arb-write layout,
|
||||||
|
or (b) porting Notselwyn's universal technique. Both are substantial dedicated
|
||||||
|
exploit-dev — this is the hardest module in the corpus, not a spot-the-bug fix.
|
||||||
|
The offset resolver (above) is the piece that was actually broken and is now
|
||||||
|
fixed + pushed.
|
||||||
|
|
||||||
|
- **Other 🟡 kernel primitives** (`nft_set_uaf`, `nft_payload`, `nft_fwd_dup`,
|
||||||
|
`netfilter_xtcompat`, `af_packet`, `af_packet2`, `af_unix_gc`, `cls_route4`,
|
||||||
|
`fuse_legacy`, `stackrot`, `sequoia`, `nft_pipapo`, `vsock_uaf`, `pintheft`):
|
||||||
|
same shape — real trigger/groom scaffolds returning `EXPLOIT_FAIL` by design.
|
||||||
|
The resolver fix unblocks feeding them offsets; each still needs its arb-write
|
||||||
|
primitive completed against a matching vulnerable kernel.
|
||||||
- **Structural userspace** (`sudoedit_editor`, `sudo_chwoot`, `sudo_host`):
|
- **Structural userspace** (`sudoedit_editor`, `sudo_chwoot`, `sudo_host`):
|
||||||
need specific sudo versions + sudoers config; likely tractable.
|
need specific sudo versions + sudoers config; likely tractable.
|
||||||
- **2026 CVEs** (`copy_fail` ×5, `dirtydecrypt`, `fragnesia`, `cifswitch`,
|
- **2026 CVEs** (`copy_fail` ×5, `dirtydecrypt`, `fragnesia`, `cifswitch`,
|
||||||
|
|||||||
Reference in New Issue
Block a user