涉及程序: NetBSD 详细: NetBSD 发布安全公告,指出 NetBSD 系统存在漏洞。它对用户提供的一个系统调用参数缺少完善的验证机制,攻击者利用这个漏洞能以超级用户权限执行任意代码。问题是由于 \"sigreturn\" 系统调用和 \"process_write_regs\" kernel routine 对用户提供的 Status Register 没做充分的检查而造成的。 注意:此问题只存于 sh3 platform,它包括 dreamcast, evbsh3, hpcsh 和 mmeye 。 受影响系统: 在 sh3 platform 上的所有 NetBSD 版本 不受影响系统: NetBSD-current: May 16, 2001 NetBSD-1.5 branch: May 27, 2001 解决方案: 1)运行5月16日之前的 NetBSD-current 请升级到5月16日之后的版本 2)运行5月27日之前的 NetBSD-release-1-5 请升级到5月27日之后的版本 注意:请用户在建立新内核之前先安装以下补丁。该补丁有三个版本 /sys/arch/sh3/include/psl.h, /sys/arch/sh3/sh3/compat_13_machdep.c /sys/arch/sh3/sh3/sh3_machdep.c 安装命令可使用 patch(1) Index: include/psl.h =================================================================== RCS file: /cvsroot/syssrc/sys/arch/sh3/include/psl.h,v retrieving revision 1.1 retrieving revision 1.2 diff -u -r1.1 -r1.2 - --- include/psl.h 1999/09/13 10:31:21 1.1 +++ include/psl.h 2001/05/16 12:42:38 1.2 @@ -57,8 +57,8 @@ #define PSL_MBO 0x00000000 /* must be one bits */ #define PSL_MBZ 0x8ffffc0c /* must be zero bits */ - -#define PSL_USERSET 0 - -#define PSL_USERSTATIC (PSL_BL|PSL_RB|PSL_MD|PSL_IMASK) +#define PSL_USERSET 0 +#define PSL_USERSTATIC (PSL_BL|PSL_RB|PSL_MD|PSL_IMASK|PSL_MBO|PSL_MBZ) #ifdef _KERNEL #include
Index: sh3/compat_13_machdep.c =================================================================== RCS file: /cvsroot/syssrc/sys/arch/sh3/sh3/compat_13_machdep.c,v retrieving revision 1.2 retrieving revision 1.3 diff -u -r1.2 -r1.3 - --- sh3/compat_13_machdep.c 2000/12/22 22:58:55 1.2 +++ sh3/compat_13_machdep.c 2001/05/16 12:42:38 1.3 @@ -71,16 +71,9 @@ /* Restore register context. */ tf = p->p_md.md_regs; - - /* - - * Check for security violations. If we\`re returning to - - * protected mode, the CPU will validate the segment registers - - * automatically and generate a trap on violations. We handle - - * the trap, rather than doing all of the checking here. - - */ - -#ifdef TODO + /* Check for security violations. */ if (((context.sc_ssr ^ tf->tf_ssr) & PSL_USERSTATIC) != 0) return (EINVAL); - -#endif tf->tf_ssr = context.sc_ssr; Index: sh3/sh3_machdep.c =================================================================== RCS file: /cvsroot/syssrc/sys/arch/sh3/sh3/sh3_machdep.c,v retrieving revision 1.12 retrieving revision 1.13 diff -u -r1.12 -r1.13 - --- sh3/sh3_machdep.c 2001/04/24 04:31:09 1.12 +++ sh3/sh3_machdep.c 2001/05/16 12:42:38 1.13 @@ -350,21 +350,13 @@ /* Restore signal context. */ tf = p->p_md.md_regs; - - { - - /* - - * Check for security violations. If we\`re returning to - - * protected mode, the CPU will validate the segment registers - - * automatically and generate a trap on violations. We handle - - * the trap, rather than doing all of the checking here. - - */ - -#ifdef TODO - - if (((context.sc_ssr ^ tf->tf_ssr) & PSL_USERSTATIC) != 0) { - - return (EINVAL); - - } - -#endif - - tf->tf_ssr = context.sc_ssr; - - } + /* Check for security violations. */ + if (((context.sc_ssr ^ tf->tf_ssr) & PSL_USERSTATIC) != 0) + return (EINVAL); + + tf->tf_ssr = context.sc_ssr; + tf->tf_r0 = context.sc_r0; tf->tf_r1 = context.sc_r1;