¡¾Íþвͨ¸æ¡¿Linux PolkitȨÏÞÌáÉýÎó²î£¨CVE-2021-4034£©
2022-01-27
Ò». Îó²î¸ÅÊö
1ÔÂ26ÈÕ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼CERT¼à²âµ½QualysÑо¿ÍŶӹûÕæÅû¶ÁËÔÚPolkitµÄpkexec Öз¢Ã÷µÄÒ»¸öȨÏÞÌáÉýÎó²î£¨CVE-2021-4034) £¬Ò²±»³ÆÎªPwnKit¡£¸ÃÎó²îÊÇÓÉÓÚpkexec ÎÞ·¨×¼È·´¦Öóͷ£Å²ÓòÎÊý£¬´Ó¶ø½«ÇéÐαäÁ¿×÷ΪÏÂÁîÖ´ÐУ¬¾ßÓÐí§ÒâÓû§È¨Ï޵Ĺ¥»÷Õß¶¼¿ÉÒÔÔÚĬÈÏÉèÖÃÏÂͨ¹ýÐÞ¸ÄÇéÐαäÁ¿À´Ê¹ÓôËÎó²î£¬´Ó¶ø»ñµÃÊÜÓ°ÏìÖ÷»úµÄroot ȨÏÞ¡£ÏÖÔÚ¸ÃÎó²îµÄϸ½ÚºÍPoCÒѹûÕæ£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
Polkit£¨PolicyKit£©ÊÇÀàUnixϵͳÖÐÒ»¸öÓ¦ÓóÌÐò¼¶±ðµÄ¹¤¾ß¼¯£¬Í¨¹ý½ç˵ºÍÉóºËȨÏÞ¹æÔò£¬ÊµÏÖ²î±ðÓÅÏȼ¶Àú³Ì¼äµÄͨѶ¡£pkexecÊÇPolkit¿ªÔ´Ó¦Óÿò¼ÜµÄÒ»²¿·Ö£¬¿ÉÒÔʹÊÚȨ·ÇÌØÈ¨Óû§Æ¾Ö¤½ç˵µÄÕ½ÂÔÒÔÌØÈ¨Óû§µÄÉí·ÝÖ´ÐÐÏÂÁî¡£
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒѵÚһʱ¼äÀֳɸ´ÏÖ¡£
²Î¿¼Á´½Ó£º
https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
2009Äê5ÔÂÖÁ½ñÐû²¼µÄËùÓÐ Polkit °æ±¾
×¢£ºPolkitԤװÔÚCentOS¡¢Ubuntu¡¢Debian¡¢Redhat¡¢Fedora¡¢Gentoo¡¢MageiaµÈ¶à¸öLinux¿¯ÐаæÉÏ£¬ËùÓб£´æPolkitµÄLinuxϵͳ¾ùÊÜÓ°Ïì¡£
²»ÊÜÓ°Ïì°æ±¾
CentOS£º
CentOS 6£ºpolkit-0.96-11.el6_10.2
CentOS 7£ºpolkit-0.112-26.el7_9.1
CentOS 8.0£ºpolkit-0.115-13.el8_5.1
CentOS 8.2£ºpolkit-0.115-11.el8_2.2
CentOS 8.4£ºpolkit-0.115-11.el8_4.2
Ubuntu£º
Ubuntu 14.04 ESM£ºpolicykit-1-0.105-4ubuntu3.14.04.6+esm1
Ubuntu 16.04 ESM£ºpolicykit-1-0.105-14.1ubuntu0.5+esm1
Ubuntu 18.04 LTS£ºpolicykit-1-0.105-20ubuntu0.18.04.6
Ubuntu 20.04 LTS£ºpolicykit-1-0.105-26ubuntu1.2
Ubuntu 21.10£ºpolicykit-1-0.105-31ubuntu0.1
Debain£º
Debain stretch£ºpolicykit-1 0.105-18+deb9u2
Debain buster£ºpolicykit-1 0.105-25+deb10u1
Debain bullseye£ºpolicykit-1 0.105-31+deb11u1
Debain bookworm,bullseye£ºpolicykit-1 0.105-31.1
Èý. Îó²î¼ì²â
3.1 °æ±¾¼ì²â
LinuxϵͳÓû§¿ÉÒÔͨ¹ýÉó²éPolkit°æÔÀ´ÅжÏÄ¿½ñϵͳÊÇ·ñÔÚÊÜÓ°Ïì¹æÄ£ÄÚ£¬Ö÷Á÷Linux¿¯ÐаæÏÂÁîÈçÏ£º
CentOS£º
|
rpm -qa polkit |
Ubuntu£º
|
dpkg -l policykit-1 |
ËÄ. Îó²î·À»¤
4.1 ¹Ù·½Éý¼¶
1¡¢ÏÖÔÚ¹Ù·½ÒÑÐû²¼²¹¶¡ÐÞ¸´´ËÎó²î£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±×°ÖþÙÐзÀ»¤¡£ÏÂÔØÁ´½Ó£ºhttps://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683
2¡¢ÏÖÔÚÖ÷Á÷Linux¿¯Ðаæ¾ùÒÑÐû²¼Çå¾²²¹¶¡»ò¸üа汾ÐÞ¸´´ËÎó²î£¬½¨ÒéÓû§¾¡¿ì×°Öò¹¶¡»ò²ÎÕÕ¹Ù·½²½·¥¾ÙÐзÀ»¤£º
|
Linux¿¯Ðаæ |
¹Ù·½Í¨¸æ |
|
Ubuntu |
https://ubuntu.com/security/CVE-2021-4034 |
|
Debain |
https://security-tracker.debian.org/tracker/CVE-2021-4034 |
|
Redhat |
https://access.redhat.com/security/cve/CVE-2021-4034 |
|
Gentoo |
https://bugs.gentoo.org/show_bug.cgi?id=CVE-2021-4034 |
|
Mageia |
https://advisories.mageia.org/CVE-2021-4034.html |
×¢£ºÈçCentOS¡¢Ubuntu¡¢DebianµÈʹÓðü¹ÜÀíÆ÷¸üÐÂPolkitµÄLinux¿¯Ðа棬¿ÉÖ±½ÓÔËÐÐÏÂÁÐÏÂÁî¾ÙÐиüÐÂÐÞ¸´£º
CentOS£º
|
yum clean all && yum makecache yum update polkit -y |
Ubuntu£º
|
sudo apt-get update sudo apt-get install policykit-1 |
Debian£º
|
apt upgrade policykit-1 |
4.2 ÔÝʱ·À»¤²½·¥
ÈôÊÜÓ°ÏìÓû§Ê¹ÓõIJÙ×÷ϵͳ»¹Î´Ðû²¼ÐÞ¸´³ÌÐò£¬»òÔÝʱÎÞ·¨×°Öò¹¶¡¸üУ¬ÔÚ²»Ó°ÏìÓªÒµµÄÇéÐÎÏ¿ÉʹÓÃÒÔϲ½·¥¾ÙÐÐÔÝʱ·À»¤¡£
Ö´ÐÐÏÂÁÐϵͳÏÂÁîÒÆ³ý pkexec µÄ suidλ£º
|
chmod 0755 /usr/bin/pkexec |
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ





