HomeSecuritySerious vulnerability found in Linux IPsec - and fixed

Serious vulnerability found in Linux IPsec – and fixed

A security vulnerability, named CVE-2022-27666, has been discovered in the IPSec (Encapsulating Security Payload) network security program on Linux systems.

Nothing is more annoying than a security bug in a security. Xiaochen Zou, a graduate student at the University of California, Riverside, was looking for bugs in Linux and he did find one. The vulnerability, CVE-2022-27666, in the IPSec esp6 (Encapsulating Security Payload) encryption module, can be used to gain privileges on local devices.

See also: QNAP: Serious Linux bug affects most NAS devices

The problem is the classic heap overflow hole. Xiaochen explained that the basic logic behind the bug is based on the fact that the buffer for receiving a user message in the esp6 module is an 8-page buffer, but the sender can send a message larger than 8 pages, which clearly creates an overflow in the buffer.

Vulnerability CVE-2022-27666 found in Linux network security
Vulnerability CVE-2022-27666 found in Linux network security

Like all buffer overflows, this means there's a big problem. Red Hat says in its security advisory that the CVE-2022-27666 vulnerability allows a local hacker, with normal privileges , to replace the kernel heap and could cause a local privilege escalation threat.

This is so bad that Red Hat and the National Institute of Standards and Technologies (NIST) give the vulnerability a high score of 7.8 on the Common Vulnerability Scoring System (CVSS).

See also: Hive ransomware: Changes Linux VMware ESXi cryptographer to Rust

Red Hat noted that if a Linux system is already using IPsec and has configured IPSec Security Associations (SAs), then no additional privileges are needed to exploit the CVE-2022-27666 vulnerability. Since almost everyone uses IPSec and SAs are essential to the network security protocol, this means that almost everyone is vulnerable to such attacks with this particular bug.

Xiaochen discovered that the latest Ubuntu, Fedora, and Debian Linux distributions can be compromised with this vulnerability. Additionally, Red Hat says that Red Hat Enterprise Linux (RHEL) 8 is vulnerable. Specifically, if your Linux contains a crypto module esp6 from 2017, which contains commits cac2661c53f3 and 03e2a30f6a27, then it is vulnerable to the attack.

Vulnerability CVE-2022-27666 found in Linux network security
Vulnerability CVE-2022-27666 found in Linux network security

Such an attack, via the CVE-2022-27666 vulnerability, can render a Linux system offline. However, Xiaochen looked into it further. During his research, he found a way to bypass Kernel Address-space Layout Randomization (KASLR). KASLR makes it harder to exploit memory vulnerabilities by placing processes at random rather than fixed memory addresses.

Then, after this process is terminated, an attacker can use Filesystem in User Space (FUSE) to create their own file system and map the device's memory to it. Consequently, all reading and writing that goes through this memory will be done by their own file system. Once this is achieved, it is relatively easy for the hacker to root the system. And as is known, when the attacker has root, everything is over. The attacker is now responsible for the entire computer. Therefore, the CVE-2022-27666 vulnerability is really very dangerous.

The good news is that the fix for the CVE-2022-27666 vulnerability is now available in Ubuntu, Debian, the Linux kernel , and most other distributions.

Source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS