A few days after Red Star OS was leaked to the West in the form of an ISO, security researchers have begun exposing its vulnerabilities.
According to this post on Seclists, the udev rules in US version 3.0 and the rc.sysint script in version 2.0 are both world writable. Both have root privilege.
Due to the file permissions management of Red Star 3.0, the device manager rules for HP LaserJet printers (1000 series), (/etc/udev/rules.d/85-hplj10xx.rules), can be modified to RUN+= arguments. These commands can be run in the udev daemon as root. There is a presentation on GitHub.
The main job of udev is to monitor the /dev (devices) directory, and when the device is connected to a USB port, it loads the appropriate ruleset.
By writing to the rc.sysint file in the older Red Star OS 2.0, an attacker can execute commands as root (demonstration).
Both vulnerabilities provide privilege escalation for local users.
Download redstar_desktop3.0_sign.iso
