flawopen.com/Teardowns/cve-2024-26585-linux-tls-zerocopy-use-after-free
CVE-2024-26585 源代码级技术深度解析与系统加固工程指南:深入剖析漏洞触发条件、攻击利用链条与加固补丁的具体实现。
通俗原理解析:Imagine you order a meal for delivery. The chef starts cooking, but you call and cancel the order. Because the kitchen staff wasn't notified properly, the delivery driver picks up an empty plate, drives to a new customer's house, and serves them whatever was left on the counter, contaminating the new customer's food.
Kernel TLS (kTLS)Zero-Copy NetworkingAsynchronous Crypto (aead_request)Slab Corruptionkmalloc-512), destabilizing kernel execution.根本原因在于开源系统中未经验证的边界参数,导致状态不同步并绕过安全控制。
技术利用机制与执行路径分析:The attacker creates a TLS socket and enables kernel encryption offload via setsockopt(TCP_ULP, "tls").
技术利用机制与执行路径分析:The attacker sends data using MSG_ZEROCOPY, queuing pages for hardware crypto.
技术利用机制与执行路径分析:The attacker closes the socket before the crypto accelerator completes its async callback.
技术利用机制与执行路径分析:The cleanup handler frees memory pages that the delayed hardware callback subsequently overwrites.
// VULNERABLE: net/tls/tls_sw.c before patch
static void tls_encrypt_done(void *data, int err) {
struct tls_context *ctx = data;
struct tls_sw_context_tx *ctx_tx = tls_sw_ctx_tx(ctx);
// ROOT CAUSE:
// Asynchronous completion callback assumes socket context is still locked!
// If the socket was closed while crypto was in flight, ctx_tx is already freed!
clear_bit(TLS_TX_SYNC_MORE, &ctx_tx->tx_bitmask);
tls_free_open_rec(ctx);
}
// SECURE: net/tls/tls_sw.c patch
static void tls_encrypt_done(void *data, int err) {
struct tls_context *ctx = data;
// 1. Verify context reference counter before dereferencing context pointers
if (!refcount_inc_not_zero(&ctx->refcount)) {
return; // Socket is already dying, abort callback safely!
}
struct tls_sw_context_tx *ctx_tx = tls_sw_ctx_tx(ctx);
clear_bit(TLS_TX_SYNC_MORE, &ctx_tx->tx_bitmask);
tls_free_open_rec(ctx);
// 2. Drop reference cleanly
refcount_dec(&ctx->refcount);
}
refcount_inc_not_zero() on shared context handles inside asynchronous completion handlers。