In the Linux kernel, the following vulnerability has been resolved:
riscv: process: Fix kernel gp leakage
childregs represents the registers which are active for the new thread in user context. For a kernel thread, childregs->gp is never used since the kernel gp is not touched by switch_to. For a user mode helper, the gp value can be observed in user space after execve or possibly by other means.
[From the email thread]
The /* Kernel thread */ comment is somewhat inaccurate in that it is also used for user_mode_helper threads, which exec a user process, e.g. /sbin/init or when /proc/sys/kernel/core_pattern is a pipe. Such threads do not have PF_KTHREAD set and are valid targets for ptrace etc. even before they exec.
childregs is the *user* context during syscall execution and it is observable from userspace in at least five ways:
1. kernel_execve does not currently clear integer registers, so the starting register state for PID 1 and other user processes started by the kernel has sp = user stack, gp = kernel __global_pointer$, all other integer registers zeroed by the memset in the patch comment.
This is a bug in its own right, but I'm unwilling to bet that it is the only way to exploit the issue addressed by this patch.
2. ptrace(PTRACE_GETREGSET): you can PTRACE_ATTACH to a user_mode_helper thread before it execs, but ptrace requires SIGSTOP to be delivered which can only happen at user/kernel boundaries.
3. /proc/*/task/*/syscall: this is perfectly happy to read pt_regs for user_mode_helpers before the exec completes, but gp is not one of the registers it returns.
4. PERF_SAMPLE_REGS_USER: LOCKDOWN_PERF normally prevents access to kernel addresses via PERF_SAMPLE_REGS_INTR, but due to this bug kernel addresses are also exposed via PERF_SAMPLE_REGS_USER which is permitted under LOCKDOWN_PERF. I have not attempted to write exploit code.
5. Much of the tracing infrastructure allows access to user registers. I have not attempted to determine which forms of tracing allow access to user registers without already allowing access to kernel registers.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jun 27, 2024 | May 19, 2024 |
| Ubuntu | — | Upgrade linux-image-6.8.0-1008-ibmUpgrade linux-image-5.15.0-1064-gcpUpgrade linux-image-azureUpgrade linux-image-6.8.0-1008-oemUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-gke-5.15Upgrade linux-image-5.15.0-1048-gkeopUpgrade linux-image-lowlatency-64k-hwe-20.04Upgrade linux-image-azure-fdeUpgrade linux-image-raspi-nolpaeUpgrade linux-image-kvmUpgrade linux-image-5.15.0-1062-gkeUpgrade linux-image-6.8.0-1009-nvidiaUpgrade linux-image-5.15.0-116-lowlatencyUpgrade linux-image-5.15.0-116-lowlatency-64kUpgrade linux-image-ibm-classicUpgrade linux-image-generic-hwe-20.04Upgrade linux-image-ibm-lts-24.04Upgrade linux-image-5.15.0-1063-oracleUpgrade linux-image-oem-20.04bUpgrade linux-image-ibmUpgrade linux-image-raspiUpgrade linux-image-lowlatency-hwe-20.04Upgrade linux-image-generic-lpaeUpgrade linux-image-5.15.0-116-generic-lpaeUpgrade linux-image-lowlatencyUpgrade linux-image-gcp-lts-22.04Upgrade linux-image-nvidia-lowlatencyUpgrade linux-image-6.8.0-38-lowlatencyUpgrade linux-image-6.8.0-1010-azure-fdeUpgrade linux-image-5.15.0-1065-awsUpgrade linux-image-6.8.0-38-lowlatency-64kUpgrade linux-image-awsUpgrade linux-image-virtual-hwe-20.04Upgrade linux-image-aws-lts-22.04Upgrade linux-image-6.8.0-1006-gkeUpgrade linux-image-5.15.0-1062-kvmUpgrade linux-image-6.8.0-1010-gcpUpgrade linux-image-azure-fde-lts-22.04Upgrade linux-image-oem-20.04cUpgrade linux-image-6.8.0-38-generic-64kUpgrade linux-image-oem-24.04aUpgrade linux-image-6.8.0-1008-oracleUpgrade linux-image-5.15.0-1058-raspiUpgrade linux-image-nvidia-64kUpgrade linux-image-6.8.0-1009-nvidia-64kUpgrade linux-image-5.15.0-1060-nvidia-lowlatencyUpgrade linux-image-5.15.0-1060-nvidiaUpgrade linux-image-azure-cvmUpgrade linux-image-gkeopUpgrade linux-image-oem-24.04Upgrade linux-image-oem-20.04Upgrade linux-image-5.15.0-116-generic-64kUpgrade linux-image-5.15.0-1065-gcpUpgrade linux-image-oracle-lts-22.04Upgrade linux-image-generic-lpae-hwe-20.04Upgrade linux-image-intel-iotgUpgrade linux-image-intelUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-5.15.0-1060-intel-iotgUpgrade linux-image-6.8.0-1008-oracle-64kUpgrade linux-image-5.15.0-116-genericUpgrade linux-image-6.8.0-1010-azureUpgrade linux-image-5.15.0-1068-azureUpgrade linux-image-6.8.0-1011-awsUpgrade linux-image-gcpUpgrade linux-image-azure-lts-22.04Upgrade linux-image-generic-hwe-24.04Upgrade linux-image-generic-64kUpgrade linux-image-gkeUpgrade linux-image-generic-64k-hwe-20.04Upgrade linux-image-6.8.0-1007-raspiUpgrade linux-image-gkeop-5.15Upgrade linux-image-5.15.0-1035-xilinx-zynqmpUpgrade linux-image-oracle-64kUpgrade linux-image-oem-20.04dUpgrade linux-image-6.8.0-1007-intelUpgrade linux-image-nvidiaUpgrade linux-image-xilinx-zynqmpUpgrade linux-image-lowlatency-64kUpgrade linux-image-virtualUpgrade linux-image-5.15.0-1058-ibmUpgrade linux-image-genericUpgrade linux-image-oracleUpgrade linux-image-6.8.0-38-genericUpgrade linux-image-5.15.0-1068-azure-fde | Jul 12, 2024 | May 19, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 19, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub