Article 77ZVP Specially Crafted NTFS File-System Image Allows Root Access on Linux With NTFS3 Driver

Specially Crafted NTFS File-System Image Allows Root Access on Linux With NTFS3 Driver

by
hubie
from SoylentNews on (#77ZVP)

An Anonymous Coward writes:

https://www.phoronix.com/news/NTFS3-Vulnerability-For-Root

A reported security vulnerability for the NTFS3 driver has gone unaddressed since being reported earlier this summer. The vulnerability allows a pre-crafted NTFS image on a USB flash drive or similar to allow the user to gain root access to the running Linux system.

After being reported privately two months ago and going unresolved, a SUID injection leading to local privilege escalation was made public. A Phoronix reader noted the disclosure via the NTFS3 mailing list.

Vova Tokarev who discovered the issue noted:

"A pre-crafted NTFS image (e.g. USB drive) with $LXUID=0, $LXGID=0, $LXMOD=0104755 already in the MFT produces a setuid-root binary the moment the volume is mounted. No setxattr() is involved -- the EAs are on disk. The -EPERM check doesn't help.

The root cause is still at fs/ntfs3/xattr.c:1022:

inode->i_mode = le32_to_cpu(value[2]);

This loads S_ISUID/S_ISGID directly from untrusted on-disk data. Desktop automounters (udisks) mount NTFS with suid by default, so plugging in a crafted USB gives any local user euid=0.

Suggested one-line fix:

- inode->i_mode = le32_to_cpu(value[2]);
+ inode->i_mode = le32_to_cpu(value[2]) & ~(S_ISUID | S_ISGID);

I have a full PoC and working demo."

Those interested can find the proof of concept and demo along with more information via this mailing list post.

As of writing the vulnerability has yet to be addressed by the mainline NTFS3 kernel driver. This doesn't appear to impact the newer NTFS driver alternative that also continues maturing within the mainline kernel tree.

Original Submission

Read more of this story at SoylentNews.

External Content
Source RSS or Atom Feed
Feed Location https://soylentnews.org/index.rss
Feed Title SoylentNews
Feed Link https://soylentnews.org/
Feed Copyright Copyright 2014, SoylentNews
Reply 0 comments