flawopen.com/Teardowns/cve-2024-26585-linux-tls-zerocopy-use-after-free

● CVE-2024-26585 · CVSS 4.7 · Sedang
Riset Keamanan · FlawOpen

CVE-2024-26585: Linux Kernel TLS Subsystem Use-After-Free Teardown

Analisis teknis mendalam dan mitigasi rekayasa sistem untuk vulnerabilidade: How an asynchronous cryptographic callback race condition in net/tls/tls_sw.c freed network pages while still queued for zero-copy transmission.

💡 Penjelasan Sederhana (ELI5)

Analogi dunia nyata: Imagine you order a meal for delivery. The chef starts cooking, but you call and cancel the order. Because the kitchen staff wasn't notified properly, the delivery driver picks up an empty plate, drives to a new customer's house, and serves them whatever was left on the counter, contaminating the new customer's food.

Konsep Kunci & Istilah

Kernel TLS (kTLS)
Linux kernel facility to perform symmetric TLS encryption/decryption directly inside the network socket layer for maximum throughput.
Zero-Copy Networking
Transmitting data directly from application buffers to the network card without intermediate CPU memory copying.
Asynchronous Crypto (aead_request)
Offloading cryptographic AES-GCM operations to asynchronous hardware accelerators.
Slab Corruption
Corrupting Linux kernel slab cache structures (kmalloc-512), destabilizing kernel execution.

Analisis Akar Masalah (Root Cause)

Akar masalah bermula dari parameter batas yang tidak divalidasi pada sistem open source, yang memungkinkan desinkronisasi status dan bypass kontrol keamanan.

Alur Serangan Langkah demi Langkah

Step 1

Tahap serangan: Open kTLS Socket

Mekanisme eksploitasi teknis dan detail eksekusi: The attacker creates a TLS socket and enables kernel encryption offload via setsockopt(TCP_ULP, "tls").

Step 2

Tahap serangan: Submit Asynchronous Zero-Copy Payload

Mekanisme eksploitasi teknis dan detail eksekusi: The attacker sends data using MSG_ZEROCOPY, queuing pages for hardware crypto.

Step 3

Tahap serangan: Abrupt Socket Teardown

Mekanisme eksploitasi teknis dan detail eksekusi: The attacker closes the socket before the crypto accelerator completes its async callback.

Step 4

Kerusakan Memori : Kernel Memory Corruption

Mekanisme eksploitasi teknis dan detail eksekusi: The cleanup handler frees memory pages that the delayed hardware callback subsequently overwrites.

Kode Sumber: Rentan vs Aman

IMPLEMENTASI RENTAN
// VULNERABLE: net/tls/tls_sw.c before patch
static void tls_encrypt_done(void *data, int err) {
    struct tls_context *ctx = data;
    struct tls_sw_context_tx *ctx_tx = tls_sw_ctx_tx(ctx);

    // ROOT CAUSE:
    // Asynchronous completion callback assumes socket context is still locked!
    // If the socket was closed while crypto was in flight, ctx_tx is already freed!
    clear_bit(TLS_TX_SYNC_MORE, &ctx_tx->tx_bitmask);
    tls_free_open_rec(ctx);
}
PERBAIKAN AMAN & KUAT
// SECURE: net/tls/tls_sw.c patch
static void tls_encrypt_done(void *data, int err) {
    struct tls_context *ctx = data;
    
    // 1. Verify context reference counter before dereferencing context pointers
    if (!refcount_inc_not_zero(&ctx->refcount)) {
        return; // Socket is already dying, abort callback safely!
    }
    
    struct tls_sw_context_tx *ctx_tx = tls_sw_ctx_tx(ctx);
    clear_bit(TLS_TX_SYNC_MORE, &ctx_tx->tx_bitmask);
    tls_free_open_rec(ctx);
    
    // 2. Drop reference cleanly
    refcount_dec(&ctx->refcount);
}

Daftar Periksa Penguatan Sistem Rekayasa

Sumber