flawopen.com/Teardowns/cve-2023-4211-arm-mali-gpu-kernel-race-condition

● CVE-2023-4211 · CVSS 5.5 · 中
セキュリティ研究 · FlawOpen

技術解説とコード分析:CVE-2023-4211: Arm Mali GPU Kernel Memory Race Condition Teardown

vulnerabilidade に関する技術的なソースコード解析と堅牢化対策:脆弱性の根本原因と安全な実装パッチの詳細。

💡 わかりやすい解説 (ELI5)

直感的な物理的アナロジー解説:Imagine a hotel where guests return room keys to the front desk. A dishonest guest hands in their key, and while the clerk is marking the room empty in the computer, the guest's accomplice runs into the room, replaces the door lock with their own, and starts renting out the room privately without the hotel knowing.

主要な概念と専門用語

Mali kbase Driver
The Linux kernel module interfacing Arm Mali GPU cores with user-space rendering libraries.
Page Table Mapping (mmap)
Mapping GPU hardware physical memory pages into user-space process virtual memory addresses.
Race Condition
A timing bug where two execution threads attempt to access and modify shared resources simultaneously without adequate synchronization.
Privilege Escalation
Gaining kernel execution privileges from an unprivileged sandbox application.

根本原因の分析 (Root Cause)

根本原因は、オープンソースシステムにおける未検証の境界パラメータに起因し、状態の非同期化とセキュリティ制御の迂回を可能にします。

ステップ・バイ・ステップの攻撃フロー

Step 1

攻撃フェーズ:Multi-Threaded Memory Allocation

技術的な脆弱性悪用メカニズムと実行フローの詳細:The attacker launches two threads mapping GPU memory chunks via mmap().

Step 2

攻撃フェーズ:Race Unmap Against Access

技術的な脆弱性悪用メカニズムと実行フローの詳細:Thread A invokes munmap() while Thread B simultaneously queues GPU drawing commands on the same region.

Step 3

攻撃フェーズ:Free Memory Access

技術的な脆弱性悪用メカニズムと実行フローの詳細:The kernel frees the memory pages, but Thread B's GPU commands execute against the freed pages.

Step 4

攻撃フェーズ:Kernel Control Hijack

技術的な脆弱性悪用メカニズムと実行フローの詳細:The attacker sprays page tables into the slot, rewriting GPU descriptors to access all physical device RAM.

ソースコード比較:脆弱 vs 堅牢化

脆弱な実装
// VULNERABLE: drivers/gpu/arm/midgard/mali_kbase_mem.c
int kbase_mem_free(struct kbase_context *kctx, u64 gpu_addr) {
    struct kbase_va_region *reg = kbase_region_tracker_find(kctx, gpu_addr);
    
    // ROOT CAUSE:
    // Memory region is unmapped and freed WITHOUT holding the context's page lock!
    // Concurrent GPU commands can still dereference 'reg' while it is being destroyed!
    kbase_gpu_vm_lock(kctx);
    kbase_mem_free_region(kctx, reg); // Frees underlying pages
    kbase_gpu_vm_unlock(kctx);
    return 0;
}
堅牢化されたセキュアパッチ
// SECURE: drivers/gpu/arm/midgard/mali_kbase_mem.c patch
int kbase_mem_free(struct kbase_context *kctx, u64 gpu_addr) {
    // 1. Acquire global context lock BEFORE looking up region
    kbase_gpu_vm_lock(kctx);
    
    struct kbase_va_region *reg = kbase_region_tracker_find(kctx, gpu_addr);
    if (!reg) {
        kbase_gpu_vm_unlock(kctx);
        return -EINVAL;
    }
    
    // 2. Wait for all in-flight GPU job chains to complete before deallocating
    kbase_wait_for_in_flight_jobs(kctx, reg);
    
    kbase_mem_free_region(kctx, reg);
    kbase_gpu_vm_unlock(kctx);
    return 0;
}

エンジニアリング&システム堅牢化チェックリスト

参考資料