flawopen.com/Teardowns/cve-2023-4211-arm-mali-gpu-kernel-race-condition
vulnerabilidade に関する技術的なソースコード解析と堅牢化対策:脆弱性の根本原因と安全な実装パッチの詳細。
直感的な物理的アナロジー解説:Imagine a hotel where guests return room keys to the front desk. A dishonest guest hands in their key, and while the clerk is marking the room empty in the computer, the guest's accomplice runs into the room, replaces the door lock with their own, and starts renting out the room privately without the hotel knowing.
Mali kbase DriverPage Table Mapping (mmap)Race ConditionPrivilege Escalation根本原因は、オープンソースシステムにおける未検証の境界パラメータに起因し、状態の非同期化とセキュリティ制御の迂回を可能にします。
技術的な脆弱性悪用メカニズムと実行フローの詳細:The attacker launches two threads mapping GPU memory chunks via mmap().
技術的な脆弱性悪用メカニズムと実行フローの詳細:Thread A invokes munmap() while Thread B simultaneously queues GPU drawing commands on the same region.
技術的な脆弱性悪用メカニズムと実行フローの詳細:The kernel frees the memory pages, but Thread B's GPU commands execute against the freed pages.
技術的な脆弱性悪用メカニズムと実行フローの詳細:The attacker sprays page tables into the slot, rewriting GPU descriptors to access all physical device RAM.
// VULNERABLE: drivers/gpu/arm/midgard/mali_kbase_mem.c
int kbase_mem_free(struct kbase_context *kctx, u64 gpu_addr) {
struct kbase_va_region *reg = kbase_region_tracker_find(kctx, gpu_addr);
// ROOT CAUSE:
// Memory region is unmapped and freed WITHOUT holding the context's page lock!
// Concurrent GPU commands can still dereference 'reg' while it is being destroyed!
kbase_gpu_vm_lock(kctx);
kbase_mem_free_region(kctx, reg); // Frees underlying pages
kbase_gpu_vm_unlock(kctx);
return 0;
}
// SECURE: drivers/gpu/arm/midgard/mali_kbase_mem.c patch
int kbase_mem_free(struct kbase_context *kctx, u64 gpu_addr) {
// 1. Acquire global context lock BEFORE looking up region
kbase_gpu_vm_lock(kctx);
struct kbase_va_region *reg = kbase_region_tracker_find(kctx, gpu_addr);
if (!reg) {
kbase_gpu_vm_unlock(kctx);
return -EINVAL;
}
// 2. Wait for all in-flight GPU job chains to complete before deallocating
kbase_wait_for_in_flight_jobs(kctx, reg);
kbase_mem_free_region(kctx, reg);
kbase_gpu_vm_unlock(kctx);
return 0;
}
kbase_gpu_vm_lock) across all lookup and deallocation code paths を強制適用してください。kbase_va_region) to prevent premature destruction を使用してください。