flawopen.com/Teardowns/cve-2024-26585-linux-tls-zerocopy-use-after-free

● CVE-2024-26585 · CVSS 4.7 · 中危
安全研究 · FlawOpen

深度技术拆解:CVE-2024-26585: Linux Kernel TLS Subsystem Use-After-Free Teardown

CVE-2024-26585 源代码级技术深度解析与系统加固工程指南:深入剖析漏洞触发条件、攻击利用链条与加固补丁的具体实现。

💡 通俗易懂的原理解析 (ELI5)

通俗原理解析:Imagine you order a meal for delivery. The chef starts cooking, but you call and cancel the order. Because the kitchen staff wasn't notified properly, the delivery driver picks up an empty plate, drives to a new customer's house, and serves them whatever was left on the counter, contaminating the new customer's food.

核心概念与专有名词

Kernel TLS (kTLS)
Linux kernel facility to perform symmetric TLS encryption/decryption directly inside the network socket layer for maximum throughput.
Zero-Copy Networking
Transmitting data directly from application buffers to the network card without intermediate CPU memory copying.
Asynchronous Crypto (aead_request)
Offloading cryptographic AES-GCM operations to asynchronous hardware accelerators.
Slab Corruption
Corrupting Linux kernel slab cache structures (kmalloc-512), destabilizing kernel execution.

根本原因剖析 (Root Cause)

根本原因在于开源系统中未经验证的边界参数,导致状态不同步并绕过安全控制。

攻击执行流程分解

Step 1

攻击阶段剖析:Open kTLS Socket

技术利用机制与执行路径分析:The attacker creates a TLS socket and enables kernel encryption offload via setsockopt(TCP_ULP, "tls").

Step 2

攻击阶段剖析:Submit Asynchronous Zero-Copy Payload

技术利用机制与执行路径分析:The attacker sends data using MSG_ZEROCOPY, queuing pages for hardware crypto.

Step 3

攻击阶段剖析:Abrupt Socket Teardown

技术利用机制与执行路径分析:The attacker closes the socket before the crypto accelerator completes its async callback.

Step 4

内存损坏(Kernel Memory Corruption)

技术利用机制与执行路径分析:The cleanup handler frees memory pages that the delayed hardware callback subsequently overwrites.

源代码对比:漏洞与安全实现

存在漏洞的实现
// VULNERABLE: net/tls/tls_sw.c before patch
static void tls_encrypt_done(void *data, int err) {
    struct tls_context *ctx = data;
    struct tls_sw_context_tx *ctx_tx = tls_sw_ctx_tx(ctx);

    // ROOT CAUSE:
    // Asynchronous completion callback assumes socket context is still locked!
    // If the socket was closed while crypto was in flight, ctx_tx is already freed!
    clear_bit(TLS_TX_SYNC_MORE, &ctx_tx->tx_bitmask);
    tls_free_open_rec(ctx);
}
加固后的安全修复
// SECURE: net/tls/tls_sw.c patch
static void tls_encrypt_done(void *data, int err) {
    struct tls_context *ctx = data;
    
    // 1. Verify context reference counter before dereferencing context pointers
    if (!refcount_inc_not_zero(&ctx->refcount)) {
        return; // Socket is already dying, abort callback safely!
    }
    
    struct tls_sw_context_tx *ctx_tx = tls_sw_ctx_tx(ctx);
    clear_bit(TLS_TX_SYNC_MORE, &ctx_tx->tx_bitmask);
    tls_free_open_rec(ctx);
    
    // 2. Drop reference cleanly
    refcount_dec(&ctx->refcount);
}

工程与系统安全加固清单

参考来源