flawopen.com/Teardowns/cve-2023-4211-arm-mali-gpu-kernel-race-condition

● CVE-2023-4211 · CVSS 5.5 · Mittel
Sicherheitsforschung · FlawOpen

CVE-2023-4211: Arm Mali GPU Kernel Memory Race Condition Teardown

Detaillierte technische Quellcode-Analyse und Härtungsmaßnahmen für vulnerabilidade: How an unlocked page table teardown in drivers/gpu/arm/midgard/mali_kbase_mem.c enabled commercial spyware to bypass Android sandboxes.

💡 Einfache Erklärung (ELI5)

Anschauliche Analogie: Imagine a hotel where guests return room keys to the front desk. A dishonest guest hands in their key, and while the clerk is marking the room empty in the computer, the guest's accomplice runs into the room, replaces the door lock with their own, and starts renting out the room privately without the hotel knowing.

Kernkonzepte & Begriffe

Mali kbase Driver
The Linux kernel module interfacing Arm Mali GPU cores with user-space rendering libraries.
Page Table Mapping (mmap)
Mapping GPU hardware physical memory pages into user-space process virtual memory addresses.
Race Condition
A timing bug where two execution threads attempt to access and modify shared resources simultaneously without adequate synchronization.
Privilege Escalation
Gaining kernel execution privileges from an unprivileged sandbox application.

Ursachenanalyse

Die Grundursache liegt in nicht validierten Grenzparametern in Open-Source-Systemen, die eine Zustandsdesynchronisation und die Umgehung von Sicherheitskontrollen ermöglichen.

Schritt-für-Schritt Angriffsablauf

Step 1

Angriffsphase: Multi-Threaded Memory Allocation

Technischer Ausführungsmechanismus: The attacker launches two threads mapping GPU memory chunks via mmap().

Step 2

Angriffsphase: Race Unmap Against Access

Technischer Ausführungsmechanismus: Thread A invokes munmap() while Thread B simultaneously queues GPU drawing commands on the same region.

Step 3

Angriffsphase: Free Memory Access

Technischer Ausführungsmechanismus: The kernel frees the memory pages, but Thread B's GPU commands execute against the freed pages.

Step 4

Angriffsphase: Kernel Control Hijack

Technischer Ausführungsmechanismus: The attacker sprays page tables into the slot, rewriting GPU descriptors to access all physical device RAM.

Quellcode: Verwundbar vs. Sicher

VERWUNDBARE IMPLEMENTIERUNG
// VULNERABLE: drivers/gpu/arm/midgard/mali_kbase_mem.c
int kbase_mem_free(struct kbase_context *kctx, u64 gpu_addr) {
    struct kbase_va_region *reg = kbase_region_tracker_find(kctx, gpu_addr);
    
    // ROOT CAUSE:
    // Memory region is unmapped and freed WITHOUT holding the context's page lock!
    // Concurrent GPU commands can still dereference 'reg' while it is being destroyed!
    kbase_gpu_vm_lock(kctx);
    kbase_mem_free_region(kctx, reg); // Frees underlying pages
    kbase_gpu_vm_unlock(kctx);
    return 0;
}
GEHÄRTETER SICHERHEITS-PATCH
// SECURE: drivers/gpu/arm/midgard/mali_kbase_mem.c patch
int kbase_mem_free(struct kbase_context *kctx, u64 gpu_addr) {
    // 1. Acquire global context lock BEFORE looking up region
    kbase_gpu_vm_lock(kctx);
    
    struct kbase_va_region *reg = kbase_region_tracker_find(kctx, gpu_addr);
    if (!reg) {
        kbase_gpu_vm_unlock(kctx);
        return -EINVAL;
    }
    
    // 2. Wait for all in-flight GPU job chains to complete before deallocating
    kbase_wait_for_in_flight_jobs(kctx, reg);
    
    kbase_mem_free_region(kctx, reg);
    kbase_gpu_vm_unlock(kctx);
    return 0;
}

Checkliste für Engineering & Systemsicherheit

Quellen