flawopen.com/Teardowns/cve-2023-4211-arm-mali-gpu-kernel-race-condition
Analyse technique détaillée du code source et mesures de durcissement pour vulnerabilidade : How an unlocked page table teardown in drivers/gpu/arm/midgard/mali_kbase_mem.c enabled commercial spyware to bypass Android sandboxes.
Analogie concrète : Imagine a hotel where guests return room keys to the front desk. A dishonest guest hands in their key, and while the clerk is marking the room empty in the computer, the guest's accomplice runs into the room, replaces the door lock with their own, and starts renting out the room privately without the hotel knowing.
Mali kbase DriverPage Table Mapping (mmap)Race ConditionPrivilege EscalationLa cause fondamentale provient de paramètres de limites non validés dans les systèmes open source, permettant une désynchronisation d'état et le contournement des contrôles de sécurité.
Mécanisme technique d'exploitation : The attacker launches two threads mapping GPU memory chunks via mmap().
Mécanisme technique d'exploitation : Thread A invokes munmap() while Thread B simultaneously queues GPU drawing commands on the same region.
Mécanisme technique d'exploitation : The kernel frees the memory pages, but Thread B's GPU commands execute against the freed pages.
Mécanisme technique d'exploitation : The attacker sprays page tables into the slot, rewriting GPU descriptors to access all physical device RAM.
// VULNERABLE: drivers/gpu/arm/midgard/mali_kbase_mem.c
int kbase_mem_free(struct kbase_context *kctx, u64 gpu_addr) {
struct kbase_va_region *reg = kbase_region_tracker_find(kctx, gpu_addr);
// ROOT CAUSE:
// Memory region is unmapped and freed WITHOUT holding the context's page lock!
// Concurrent GPU commands can still dereference 'reg' while it is being destroyed!
kbase_gpu_vm_lock(kctx);
kbase_mem_free_region(kctx, reg); // Frees underlying pages
kbase_gpu_vm_unlock(kctx);
return 0;
}
// SECURE: drivers/gpu/arm/midgard/mali_kbase_mem.c patch
int kbase_mem_free(struct kbase_context *kctx, u64 gpu_addr) {
// 1. Acquire global context lock BEFORE looking up region
kbase_gpu_vm_lock(kctx);
struct kbase_va_region *reg = kbase_region_tracker_find(kctx, gpu_addr);
if (!reg) {
kbase_gpu_vm_unlock(kctx);
return -EINVAL;
}
// 2. Wait for all in-flight GPU job chains to complete before deallocating
kbase_wait_for_in_flight_jobs(kctx, reg);
kbase_mem_free_region(kctx, reg);
kbase_gpu_vm_unlock(kctx);
return 0;
}
kbase_gpu_vm_lock) across all lookup and deallocation code paths.kbase_va_region) to prevent premature destruction.