์ธํ”„๋Ÿฐ ์˜๋ฌธ ๋ธŒ๋žœ๋“œ ๋กœ๊ณ 
์ธํ”„๋Ÿฐ ์˜๋ฌธ ๋ธŒ๋žœ๋“œ ๋กœ๊ณ 
BEST

๋ฆฌ๋ˆ…์Šค ์ปค๋„ ํ•ดํ‚น. A๋ถ€ํ„ฐ Z๊นŒ์ง€

๋ฆฌ๋ˆ…์Šค ์ปค๋„์˜ ๊ฐ์ข… ๋ณดํ˜ธ ๊ธฐ๋ฒ•๊ณผ ๊ทธ์— ๋Œ€ํ•œ ์šฐํšŒ ๋ฐฉ์•ˆ ๋ฐ ๋‹ค์–‘ํ•œ ์ทจ์•ฝ์ ๋“ค์„ ๋ถ„์„ํ•ด๋ณด๋Š” ๊ฐ•์˜์ด๋ฉฐ, ๊ฐ•์˜๋ณ„๋กœ ์‹ค์Šต ์˜ˆ์ œ๊ฐ€ ์ œ๊ณต ๋ฉ๋‹ˆ๋‹ค.

์ค‘๊ธ‰์ž๋ฅผ ์œ„ํ•ด ์ค€๋น„ํ•œ
[๋ณด์•ˆ] ๊ฐ•์˜์ž…๋‹ˆ๋‹ค.

์ด๋Ÿฐ ๊ฑธ ๋ฐฐ์šธ ์ˆ˜ ์žˆ์–ด์š”

  • ๋ฆฌ๋ˆ…์Šค ์ปค๋„ ํ•ดํ‚น

  • CTF ์ปค๋„ ๋ฌธ์ œ ํ’€์ด

  • Linux Kernel Exploit

๐Ÿ’ก  ๊ฐ•์˜ ํŠน์ง• 

์ด ๊ฐ•์˜๋Š” ๋ฆฌ๋ˆ…์Šค ์ปค๋„ ํ•ดํ‚น์— ๋Œ€ํ•œ ์ „๋ฐ˜์ ์ธ ์ง€์‹์„ ํ•™์Šตํ•˜๋Š” ๊ฐ•์˜์ž…๋‹ˆ๋‹ค.

๋ฆฌ๋ˆ…์Šค ์ปค๋„ ํ•ดํ‚น์€ ๊ตญ๋‚ด์—์„œ ๊ณต๋ถ€ํ•  ์ˆ˜ ์žˆ๋Š” ์ž๋ฃŒ๊ฐ€ ๋งค์šฐ ๋ถ€์กฑํ•œ ๋ถ„์•ผ์ด๋ฉฐ, ํ™˜๊ฒฝ ๊ตฌ์„ฑ ๋‹จ๊ณ„๋ถ€ํ„ฐ ์ˆ˜๋งŽ์€ ์• ๋กœ ์‚ฌํ•ญ์ด ์žˆ๋Š” ๋ถ„์•ผ์ž…๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ, ์ด ๊ฐ•์˜๋ฅผ ์ˆ˜๊ฐ•ํ•˜์‹œ๋ฉด ํ™˜๊ฒฝ ๊ตฌ์„ฑ์€ ๋ฌผ๋ก ์ด๊ณ  ๋‹ค์–‘ํ•œ ๋ณดํ˜ธ ๊ธฐ๋ฒ•์˜ ์šฐํšŒ ๋ฐฉ๋ฒ•๊ณผ ๊ฐ์ข… ์ทจ์•ฝ์ ์— ๋Œ€ํ•ด ์‰ฝ๊ฒŒ ๊ณต๋ถ€ํ•˜์‹ค ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋˜, ๋‹จ์ˆœํžˆ ํŠน์ • ํˆด ์‚ฌ์šฉ๋ฒ•๋งŒ์„ ๊ฐ€๋ฅด์น˜๊ฑฐ๋‚˜ ์ด๋ฏธ ์ž˜ ์•Œ๋ ค์ง„ ํ•ดํ‚น ๊ธฐ์ˆ ๋“ค์„ ๋‹ค์‹œ ์†Œ๊ฐœํ•˜๋Š” ์ˆ˜์ค€์— ๋ถˆ๊ณผํ•œ ์—ฌํƒ€ ์ •๋ณด๋ณด์•ˆ ๊ฐ•์˜๋“ค๊ณผ ๋‹ฌ๋ฆฌ, low-level์—์„œ์˜ ๋™์ž‘ ์›๋ฆฌ์— ์ž…๊ฐํ•˜์—ฌ ๊ฐ์ข… ์ต์Šคํ”Œ๋กœ์ž‡ ํ…Œํฌ๋‹‰๋“ค์„ ์†Œ๊ฐœํ•œ๋‹ค๋Š” ๊ฒƒ์ด ์ด ๊ฐ•์˜์˜ ํŠน์ง•์ž…๋‹ˆ๋‹ค.

โ–ฒ ๋ฆฌ๋ˆ…์Šค ์ปค๋„์˜ ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ๊ถŒํ•œ ์ƒ์Šน์„ ์ผ์œผํ‚จ ๋ชจ์Šต

์ตœ๊ทผ ๋ช‡ ๋…„๊ฐ„ major ํ•œ CTF์—์„œ๋Š” ๋ฆฌ๋ˆ…์Šค ์ปค๋„ ๋ฌธ์ œ๊ฐ€ ๊พธ์ค€ํžˆ ์ถœ์ œ๋์Šต๋‹ˆ๋‹ค. ์ตœ๊ทผ์˜ ๊ฒฝ์šฐ ์ถœ์ œ ๋นˆ๋„๊ฐ€ ๋”์šฑ ์ฆ๊ฐ€ํ•˜๋Š” ์ถ”์„ธ๊ณ ์š”. ์ด ๊ฐ•์˜๋ฅผ "์™„๋ฒฝํžˆ" ์ดํ•ดํ•˜์‹ ๋‹ค๋ฉด, CTF์—์„œ ์ถœ์ œ๋˜๋Š” ๋ฆฌ๋ˆ…์Šค ์ปค๋„ ๋ฌธ์ œ๋“ค์€ ๋Œ€๋ถ€๋ถ„ ํ•ด๊ฒฐํ•˜์‹ค ์ˆ˜ ์žˆ์„ ๊ฒƒ์ด๋ฉฐ, ๋ฆฌ์–ผ ์›”๋“œ์—์„œ ์ทจ์•ฝ์ ์„ ์ฐพ๋Š” ๋ฐ๋„ ํฐ ๋„์›€์„ ๋ฐ›์œผ์‹ค ์ˆ˜ ์žˆ์„ ๊ฑฐ๋ผ ๋ง์”€๋“œ๋ฆฌ๊ณ  ์‹ถ์Šต๋‹ˆ๋‹ค.

๋งˆ์ง€๋ง‰์œผ๋กœ ์ด ๊ฐ•์˜์˜ ๊ฐ€์žฅ ํฐ ํŠน์ง•์€, ๊ฐ•์˜๋งˆ๋‹ค ๊ฐ•์‚ฌ๊ฐ€ ์ง์ ‘ ์ œ์ž‘ํ•œ ์‹ค์Šต ์˜ˆ์ œ ํŒŒ์ผ์„ ์ œ๊ณตํ•ด ์ค€๋‹ค๋Š” ์ ์ž…๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์‹ค์Šต ์˜ˆ์ œ ํŒŒ์ผ์„ ํ†ตํ•ด ์ˆ˜๊ฐ•์ƒ ์—ฌ๋Ÿฌ๋ถ„๋“ค์ด ์ง์ ‘ ๊ฐ•์˜๋ฅผ ๋”ฐ๋ผ ํ•ด ๋ณด๊ณ , ๋””๋ฒ„๊น…์„ ํ•ด๋ณด์‹ค ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.


๐Ÿ“–  ๊ฐ ์„น์…˜์—์„œ๋Š” ๋ฌด์—‡์„ ๋ฐฐ์šฐ๋‚˜์š”? 

 

โ–ฒ ์„น์…˜ 4.6. userfaultfd ํ™œ์šฉ ๊ธฐ๋ฒ• ๊ฐ•์˜ ์ž๋ฃŒ

์ด ๊ฐ•์˜๋Š” ๋Œ€๋ถ€๋ถ„ ์œ„์˜ ์˜ˆ์‹œ์™€ ๊ฐ™์ด ํ‚ค๋…ธํŠธ๋ฅผ ์ด์šฉํ•œ ๋ฐœํ‘œ๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

 

  • ์„น์…˜ 0. ๊ฐ•์˜ ํ”„๋กค๋กœ๊ทธ

๋ณธ๊ฒฉ์ ์œผ๋กœ ๊ฐ•์˜๋ฅผ ์‹œ์ž‘ํ•˜๊ธฐ์— ์•ž์„œ, ๊ฐ•์‚ฌ์— ๋Œ€ํ•œ ๊ฐ„๋‹จํ•œ ์†Œ๊ฐœ์™€ ๊ฐ•์˜ ๊ณ„ํš์„ ์„ค๋ช…ํ•ด ๋“œ๋ฆฌ๋Š” ์„น์…˜์ž…๋‹ˆ๋‹ค.

 

  • ์„น์…˜ 1. ๋ฆฌ๋ˆ…์Šค ์ปค๋„ ํ•ดํ‚น ๋ฐฐ๊ฒฝ์ง€์‹

๋ฆฌ๋ˆ…์Šค ์ปค๋„์„ ํ•ดํ‚นํ•˜๊ธฐ ์œ„ํ•œ ๊ธฐ๋ณธ์ ์ธ ๋ฐฐ๊ฒฝ์ง€์‹์„ ๊ณต๋ถ€ํ•˜๋Š” ์„น์…˜์ž…๋‹ˆ๋‹ค.

 

  • ์„น์…˜ 2. ๋ฆฌ๋ˆ…์Šค ์ปค๋„ ๋ถ„์„ ํ™˜๊ฒฝ ์„ธํŒ…

๋ฆฌ๋ˆ…์Šค ์ปค๋„์„ ๋””๋ฒ„๊น…ํ•  ์ˆ˜ ์žˆ๋Š” ํ™˜๊ฒฝ์„ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ณด๋Š” ์„น์…˜์ž…๋‹ˆ๋‹ค. ๋ฆฌ์–ผ ์›”๋“œ๋ฅผ ์œ„ํ•œ ํ™˜๊ฒฝ ์„ธํŒ… ๊ณผ์ •์—์„œ๋Š” ๋ฆฌ๋ˆ…์Šค ์ปค๋„๊ณผ ํŒŒ์ผ ์‹œ์Šคํ…œ์„ ์ง์ ‘ ๋นŒ๋“œํ•ด๋ณผ ๊ฒƒ์ด๋ฉฐ, CTF๋ฅผ ์œ„ํ•œ ํ™˜๊ฒฝ ์„ธํŒ… ๊ณผ์ •์—์„œ๋Š” ๋ฌธ์ œ๋ฅผ ํ’€๊ธฐ ์œ„ํ•œ ์ค€๋น„ ๊ณผ์ •์„ ์•Œ์•„๋ณผ ์˜ˆ์ •์ž…๋‹ˆ๋‹ค.

 

  • ์„น์…˜ 3. ๋ฆฌ๋ˆ…์Šค ์ปค๋„์˜ ๋ณดํ˜ธ ๊ธฐ๋ฒ• ๋ฐ ์šฐํšŒ ๋ฐฉ์•ˆ

๋ฆฌ๋ˆ…์Šค ์ปค๋„์˜ ๋‹ค์–‘ํ•œ ๋ณดํ˜ธ ๊ธฐ๋ฒ•์— ๋Œ€ํ•ด ์•Œ์•„๋ณด๊ณ , ๊ฐ ๋ณดํ˜ธ ๊ธฐ๋ฒ•๋“ค์„ ์šฐํšŒํ•  ์ˆ˜ ์žˆ๋Š” ํ…Œํฌ๋‹‰๋“ค์„ ์‹ค์Šต์„ ํ†ตํ•ด ๊ณต๋ถ€ํ•ด๋ณด๋Š” ์„น์…˜์ž…๋‹ˆ๋‹ค. ๊ณต๋ถ€ํ•ด๋ณผ ๋ณดํ˜ธ ๊ธฐ๋ฒ•๋“ค์€ ์ธํ…” ๊ณ„์—ด ์•„ํ‚คํ…์ณ์˜ ๋ณดํ˜ธ ๊ธฐ๋ฒ•๋“ค์ด๋ฉฐ, ์ด 6๊ฐ€์ง€์˜ ๋ณดํ˜ธ ๊ธฐ๋ฒ•์„ ๊ณต๋ถ€ํ•ด ๋ณผ ์˜ˆ์ •์ž…๋‹ˆ๋‹ค. ๋˜, ์ด๋ฒˆ ์„น์…˜๋ถ€ํ„ฐ๋Š” ๊ฐ ๊ฐ•์˜๋งˆ๋‹ค ์‹ค์Šต ์˜ˆ์ œ ํŒŒ์ผ์ด ์ œ๊ณต๋ฉ๋‹ˆ๋‹ค.

 

  • ์„น์…˜ 4. ๋‹ค์–‘ํ•œ ์ปค๋„ ๊ณต๊ฒฉ ํ…Œํฌ๋‹‰ ์‹ค์Šต

๋ฆฌ๋ˆ…์Šค ์ปค๋„ ์ทจ์•ฝ์ ์ด ํ„ฐ์ง€๋Š” ์ƒํ™ฉ์—์„œ ๊ถŒํ•œ ์ƒ์Šน์„ ์ผ์œผํ‚ฌ ์ˆ˜ ์žˆ๋Š” ๋‹ค์–‘ํ•œ ํ…Œํฌ๋‹‰๋“ค์„ ๊ณต๋ถ€ํ•ด๋ณด๋Š” ์„น์…˜์ž…๋‹ˆ๋‹ค.

 

  • ์„น์…˜ 5. ๋‹ค์–‘ํ•œ ๋ฆฌ๋ˆ…์Šค ์ปค๋„ ์ทจ์•ฝ์  ๋ถ„์„

๋ฆฌ๋ˆ…์Šค ์ปค๋„์—์„œ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋Š” ๋‹ค์–‘ํ•œ ์œ ํ˜•์˜ ์ทจ์•ฝ์ ์„ ์•Œ์•„๋ณด๋Š” ์„น์…˜์ž…๋‹ˆ๋‹ค.

 

  • ์„น์…˜ 6. ๋Œ€ํšŒ ๋ฌธ์ œ ์‹ค์Šต - Input Test Driver

์‹ค์ œ๋กœ CTF์— ์ถœ์ œ๋œ ๋ฆฌ๋ˆ…์Šค ์ปค๋„ ๋ฌธ์ œ๋ฅผ ํ’€์–ด๋ณด๋Š” ์„น์…˜์ž…๋‹ˆ๋‹ค. ํ’€์–ด๋ณผ ๋ฌธ์ œ๋Š”, ๊ฐ•์‚ฌ๊ฐ€ ์†Œ์†๋œ ํŒ€์—์„œ ์šด์˜ํ–ˆ๋˜ ๋Œ€ํšŒ์ธ 2020 Defenit CTF์—์„œ ์ถœ์ œ๋œ Input Test Driver ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค.

 

  • ์„น์…˜ 7. ๊ฐ•์˜ ์—ํ•„๋กœ๊ทธ

๋ฆฌ๋ˆ…์Šค ์ปค๋„์„ ๊ณต๋ถ€ํ•  ๋•Œ ๋„์›€์ด ๋˜๋Š” ๋ ˆํผ๋Ÿฐ์Šค๋ฅผ ์†Œ๊ฐœํ•œ ๋’ค, ๊ฐ•์˜๋ฅผ ๋งˆ๋ฌด๋ฆฌํ•˜๋Š” ์„น์…˜์ž…๋‹ˆ๋‹ค.


โœ๏ธ  ๊ฐ•์˜๋ฅผ ๋“ฃ๊ธฐ ์œ„ํ•œ ๋ฐฐ๊ฒฝ์ง€์‹

 

  • ์ตœ์†Œ ๋ฐฐ๊ฒฝ์ง€์‹

1. C ์–ธ์–ด

 

  • ๊ถŒ์žฅ ๋ฐฐ๊ฒฝ์ง€์‹

1. ์‹œ์Šคํ…œ ํ•ดํ‚น ๊ด€๋ จ ์ง€์‹ (BOF, ROP, UAF ๋“ฑ)
2. ์–ด์…ˆ๋ธ”๋ฆฌ ์–ธ์–ด (x86_64)


๐Ÿ™‹๐Ÿปโ€โ™‚๏ธ ์˜ˆ์ƒ ์งˆ๋ฌธ Q&A

 

Q. ์ €๋Š” ์‹œ์Šคํ…œ ํ•ดํ‚น์„ ํ•ด๋ณธ ์ ๋„ ์—†๊ณ  ์–ด์…ˆ๋ธ”๋ฆฌ ์–ธ์–ด๋„ ๋ชจ๋ฅด๋Š”๋ฐ ๊ฐ•์˜๋ฅผ ๋“ค์–ด๋„ ๋ ๊นŒ์š”?
A. ๊ฐ ๊ฐ•์˜๋ฅผ ์ œ์ž‘ํ•  ๋•Œ, ์‹œ์Šคํ…œ ํ•ดํ‚น์ด ์ฃผ ๋ถ„์•ผ๊ฐ€ ์•„๋‹ˆ์‹  ๋ถ„๋“ค๋„ ๋“ค์„ ์ˆ˜ ์žˆ๋„๋ก ์ œ์ž‘ํ–ˆ๊ธฐ ๋•Œ๋ฌธ์—, ์ƒˆ๋กœ์šด ์šฉ์–ด๊ฐ€ ๋“ฑ์žฅํ•  ๋•Œ๋งˆ๋‹ค ๊ฐ•์˜์— ๊ทธ์— ๋Œ€ํ•œ ์„ค๋ช…์ด ๋“ค์–ด๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.

ํ•˜์ง€๋งŒ, ์ด๋Š” ์š”์•ฝ๋œ ์„ค๋ช…์ด๊ธฐ ๋•Œ๋ฌธ์— ๋ชจ๋ฅด๋Š” ๊ฐœ๋…์ด ๋“ฑ์žฅํ–ˆ์„ ๋•Œ ๊ตฌ๊ธ€ ๊ฒ€์ƒ‰๊ณผ ๋ณ‘ํ–‰ํ•ด์„œ ๊ณต๋ถ€ํ•˜์…”์•ผ ํ•˜๋ฉฐ, ์‹œ์Šคํ…œ ํ•ดํ‚น ๊ด€๋ จ ์ง€์‹์ด ์—†๋Š” ์ƒํƒœ์—์„œ ์ˆ˜๊ฐ•ํ•˜์‹ค ๊ฒฝ์šฐ ํ•™์Šต ๊ธฐ๊ฐ„์ด ํ›จ์”ฌ ๊ธธ์–ด์ง„๋‹ค๋Š” ์ ์„ ์—ผ๋‘์— ๋‘์…”์•ผ ํ•ฉ๋‹ˆ๋‹ค.

 

 

Q. ๋ฆฌ๋ˆ…์Šค๋Š” ์–ด๋–ค ๋ฒ„์ „์„ ์‚ฌ์šฉํ•˜์‹œ๋‚˜์š”?
A. ์ œ ๊ฒฝ์šฐ ์šฐ๋ถ„ํˆฌ 18.04 ๋ฒ„์ „์„ ์‚ฌ์šฉํ–ˆ์Šต๋‹ˆ๋‹ค.(https://releases.ubuntu.com/18.04/)

 

 

Q. ๊ฐ•์˜๊ฐ€ ์—ฐ์žฌ์‹ ๊ฐ•์˜๋˜๋ฐ, ๋‚จ์€ ๊ฐ•์˜๋Š” ์–ธ์ œ ์˜ฌ๋ผ์˜ค๋‚˜์š”?
A. ํ˜„์žฌ ๋ชจ๋“  ๊ฐ•์˜์˜ ์—…๋กœ๋“œ๊ฐ€ ์™„๋ฃŒ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

 

์ด๋Ÿฐ ๋ถ„๋“ค๊ป˜
์ถ”์ฒœ๋“œ๋ ค์š”!

ํ•™์Šต ๋Œ€์ƒ์€
๋ˆ„๊ตฌ์ผ๊นŒ์š”?

  • ๋ฆฌ๋ˆ…์Šค ์ปค๋„ ํ•ดํ‚น์„ ์ฒ˜์Œ ๊ณต๋ถ€ํ•ด๋ณด๊ณ  ์‹ถ์€ ๋ถ„๋“ค

  • ํฌ๋„ˆ๋ธ”์„ ๊ณต๋ถ€ํ•ด ๋ณด์•˜๊ณ , ์ด์ œ ๋ฆฌ๋ˆ…์Šค ์ปค๋„ ์ต์Šคํ”Œ๋กœ์ž‡์— ์ž…๋ฌธํ•˜๊ณ  ์‹ถ์œผ์‹  ๋ถ„๋“ค

์„ ์ˆ˜ ์ง€์‹,
ํ•„์š”ํ• ๊นŒ์š”?

  • C์–ธ์–ด

์•ˆ๋…•ํ•˜์„ธ์š”
๊น€ํ˜„์šฐ์ž…๋‹ˆ๋‹ค.

603

๋ช…

์ˆ˜๊ฐ•์ƒ

24

๊ฐœ

์ˆ˜๊ฐ•ํ‰

62

๊ฐœ

๋‹ต๋ณ€

4.8

์ 

๊ฐ•์˜ ํ‰์ 

1

๊ฐœ

๊ฐ•์˜

๋ฆฌ๋ˆ…์Šค ์ปค๋„ ํ•ด์ปค ๋ฐ ์ปจํŠธ๋ฆฌ๋ทฐํ„ฐ๋กœ ํ™œ๋™ ์ค‘์ธ ๊น€ํ˜„์šฐ(V4bel)์ž…๋‹ˆ๋‹ค.

โฆ  Contact: imv4bel@gmail.com

 

Awards

โฆ  Pwn2Own Berlin 2025 Red Hat Linux in the LPE category WIN (Theori, $15,000)
โฆ  Google kernelCTF LTS-6.6.75/COS-105 1-day WIN (CVE-2025-21756, $71,337)
โฆ  Google kernelCTF LTS-6.6.56/COS-109 0-day WIN (CVE-2024-50264, $81,337)
โฆ  Google kernelCTF LTS-6.6.35 0-day WIN (CVE-2024-41010, $51,337)

 

Vulnerability Reports

โฆ  CVE-2024-27394 (Linux Kernel TCP Use-After-Free)
โฆ  CVE-2024-27395 (Linux Kernel OpenvSwitch Use-After-Free)
โฆ  CVE-2024-27396 (Linux Kernel GTP Use-After-Free)
โฆ  CVE-2023-51779 (Linux Kernel Bluetooth socket Use-After-Free)
โฆ  CVE-2023-51780 (Linux Kernel ATM socket Use-After-Free)
โฆ  CVE-2023-51781 (Linux Kernel Appletalk socket Use-After-Free)
โฆ  CVE-2023-51782 (Linux Kernel Rose socket Use-After-Free)
โฆ  CVE-2023-32269 (Linux Kernel NET/ROM socket Use-After-Free)
โฆ  CVE-2022-41218 (Linux Kernel DVB core Use-After-Free)
โฆ  CVE-2022-45884 (Linux Kernel DVB core Use-After-Free)
โฆ  CVE-2022-45885 (Linux Kernel DVB core Use-After-Free)
โฆ  CVE-2022-45886 (Linux Kernel DVB core Use-After-Free)
โฆ  CVE-2022-45919 (Linux Kernel DVB core Use-After-Free)
โฆ  CVE-2022-40307 (Linux Kernel Device Driver Use-After-Free)
โฆ  CVE-2022-41848 (Linux Kernel Device Driver Use-After-Free)
โฆ  CVE-2022-41849 (Linux Kernel Device Driver Use-After-Free)
โฆ  CVE-2022-41850 (Linux Kernel Device Driver Use-After-Free)
โฆ  CVE-2022-44032 (Linux Kernel Device Driver Use-After-Free)
โฆ  CVE-2022-44033 (Linux Kernel Device Driver Use-After-Free)
โฆ  CVE-2022-44034 (Linux Kernel Device Driver Use-After-Free)
โฆ  CVE-2022-45888 (Linux Kernel Device Driver Use-After-Free)

 

Linux Kernel Contributions

โฆ  vsock: prevent null-ptr-deref in vsock_*[has_data|has_space]
(github.com/torvalds/linux/commit/91751e248256efc111e52e15115840c35d85abaf)
โฆ  vsock/virtio: cancel close work in the destructor
(github.com/torvalds/linux/commit/df137da9d6d166e87e40980e36eb8e0bc90483ef)
โฆ  vsock/virtio: discard packets if the transport changes
(github.com/torvalds/linux/commit/2cb7c756f605ec02ffe562fb26828e4bcc5fdfc1)
โฆ  vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans
(github.com/torvalds/linux/commit/6ca575374dd9a507cdd16dfa0e78c2e9e20bd05f)
โฆ  hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer
(github.com/torvalds/linux/commit/e629295bd60abf4da1db85b82819ca6a4f6c1e79)
โฆ  tcp: Fix Use-After-Free in tcp_ao_connect_init
(github.com/torvalds/linux/commit/80e679b352c3ce5158f3f778cfb77eb767e586fb)
โฆ  net: openvswitch: Fix Use-After-Free in ovs_ct_exit
(github.com/torvalds/linux/commit/5ea7b72d4fac2fdbc0425cd8f2ea33abe95235b2)
โฆ  net: gtp: Fix Use-After-Free in gtp_dellink
(github.com/torvalds/linux/commit/f2a904107ee2b647bb7794a1a82b67740d7c8a64)
โฆ  Bluetooth: af_bluetooth: Fix Use-After-Free in bt_sock_recvmsg
(github.com/torvalds/linux/commit/2e07e8348ea454615e268222ae3fc240421be768)
โฆ  atm: Fix Use-After-Free in do_vcc_ioctl
(github.com/torvalds/linux/commit/24e90b9e34f9e039f56b5f25f6e6eb92cdd8f4b3)
โฆ  appletalk: Fix Use-After-Free in atalk_ioctl
(github.com/torvalds/linux/commit/189ff16722ee36ced4d2a2469d4ab65a8fee4198)
โฆ  net/rose: Fix Use-After-Free in rose_ioctl
(github.com/torvalds/linux/commit/810c38a369a0a0ce625b5c12169abce1dd9ccd53)
โฆ  media: dvb-core: Fix use-after-free due to race at dvb_register_device()
(github.com/torvalds/linux/commit/627bb528b086b4136315c25d6a447a98ea9448d3)
โฆ  af_key: Fix heap information leak
(github.com/torvalds/linux/commit/2f4796518315ab246638db8feebfcb494212e7ee)
โฆ  netrom: Fix use-after-free caused by accept on already connected socket
(github.com/torvalds/linux/commit/611792920925fb088ddccbe2783c7f92fdfb6b64)
โฆ  net/rose: Fix to not accept on connected socket
(github.com/torvalds/linux/commit/14caefcf9837a2be765a566005ad82cd0d2a429f)
โฆ  net/x25: Fix to not accept on connected socket
(github.com/torvalds/linux/commit/f2b0b5210f67c56a3bcdf92ff665fb285d6e0067)
โฆ  efi: capsule-loader: Fix use-after-free in efi_capsule_write
(github.com/torvalds/linux/commit/9cb636b5f6a8cc6d1b50809ec8f8d33ae0c84c95)
โฆ  HID: roccat: Fix Use-After-Free in roccat_read
(github.com/torvalds/linux/commit/cacdb14b1c8d3804a3a7d31773bc7569837b71a4)
โฆ  video: fbdev: smscufx: Fix use-after-free in ufx_ops_open()
(github.com/torvalds/linux/commit/5610bcfe8693c02e2e4c8b31427f1bdbdecc839c)
โฆ  video: fbdev: smscufx: Fix several use-after-free bugs
(github.com/torvalds/linux/commit/cc67482c9e5f2c80d62f623bcc347c29f9f648e1)
โฆ  char: xillybus: Fix trivial bug with mutex
(github.com/torvalds/linux/commit/c002f04c0bc79ec00d4beb75fb631d5bf37419bd)
โฆ  bpf: Always use maximal size for copy_array()
(github.com/torvalds/linux/commit/45435d8da71f9f3e6860e6e6ea9667b6ec17ec64)
โฆ  media: dvb-core: Fix UAF due to refcount races at releasing
(github.com/torvalds/linux/commit/fd3d91ab1c6ab0628fe642dd570b56302c30a792)

๋”๋ณด๊ธฐ

์ปค๋ฆฌํ˜๋Ÿผ

์ „์ฒด

33๊ฐœ โˆ™ (5์‹œ๊ฐ„ 31๋ถ„)

ํ•ด๋‹น ๊ฐ•์˜์—์„œ ์ œ๊ณต:

์ˆ˜์—…์ž๋ฃŒ
๊ฐ•์˜ ๊ฒŒ์‹œ์ผ: 
๋งˆ์ง€๋ง‰ ์—…๋ฐ์ดํŠธ์ผ: 

์ˆ˜๊ฐ•ํ‰

์ „์ฒด

24๊ฐœ

4.8

24๊ฐœ์˜ ์ˆ˜๊ฐ•ํ‰

  • ์œค์ค€์›๋‹˜์˜ ํ”„๋กœํ•„ ์ด๋ฏธ์ง€
    ์œค์ค€์›

    ์ˆ˜๊ฐ•ํ‰ 1

    โˆ™

    ํ‰๊ท  ํ‰์  5.0

    5

    33% ์ˆ˜๊ฐ• ํ›„ ์ž‘์„ฑ

    ํ˜„์žฌ ํ•œ๊ตญ์–ด๋กœ๋œ ์ปค๋„ ํ•ดํ‚น ์ž๋ฃŒ๊ฐ€ ๋งŽ์ด ์—†๋Š”๋ฐ, ์ด ๊ฐ•์˜์— ์ž˜ ์ •๋ฆฌ๋˜์–ด ์žˆ๊ณ  ์ž…๋ฌธ ์ž๋ฃŒ๋กœ์„œ ์ข‹์€ ๊ฑฐ ๊ฐ™๋‹ค.

    • ๊น€ํ˜„์šฐ
      ์ง€์‹๊ณต์œ ์ž

      ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค ๐Ÿ˜Š๐Ÿ˜Š

  • LK๋‹˜์˜ ํ”„๋กœํ•„ ์ด๋ฏธ์ง€
    LK

    ์ˆ˜๊ฐ•ํ‰ 5

    โˆ™

    ํ‰๊ท  ํ‰์  5.0

    5

    100% ์ˆ˜๊ฐ• ํ›„ ์ž‘์„ฑ

    ๊ตญ๋‚ด์—์„œ ์ฐป๊ธฐํž˜๋“  ์ปค๋„ํ•ดํ‚น๊ฐ•์˜๋ฅผ ์‰ฝ๊ฒŒ์„ค๋ช…ํ•ด์ฃผ์–ด์„œ ์ž…๋ฌธํ•˜๊ธฐ์ข‹์•˜๋‹ค

    • ๊น€ํ˜„์šฐ
      ์ง€์‹๊ณต์œ ์ž

      ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค :)

  • ๋ฐ•์ƒ์ค€๋‹˜์˜ ํ”„๋กœํ•„ ์ด๋ฏธ์ง€
    ๋ฐ•์ƒ์ค€

    ์ˆ˜๊ฐ•ํ‰ 1

    โˆ™

    ํ‰๊ท  ํ‰์  5.0

    5

    97% ์ˆ˜๊ฐ• ํ›„ ์ž‘์„ฑ

    ์ดˆ๋ณด์ž๋„ ์•Œ๊ธฐ ์‰ฝ๊ฒŒ ์„ค๋ช…ํ•ด์ฃผ์‹œ๊ณ  ์งˆ๋ฌธ ๋‹ต๋ณ€์ด ๋งค์šฐ ๋น ๋ฅด์‹œ๊ณ  ์นœ์ ˆํ•˜์‹ญ๋‹ˆ๋‹ค!! ๊ฐœ์ธ์ ์œผ๋กœ ์ •๋ง ์–ป์–ด๊ฐ€๋Š”๊ฒŒ ๋งŽ์•˜์–ด์š”

    • ๊น€ํ˜„์šฐ
      ์ง€์‹๊ณต์œ ์ž

      ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค ๐Ÿ™‚๐Ÿ™‚

  • ์„ค๊ตฌํ™”๋‹˜์˜ ํ”„๋กœํ•„ ์ด๋ฏธ์ง€
    ์„ค๊ตฌํ™”

    ์ˆ˜๊ฐ•ํ‰ 1

    โˆ™

    ํ‰๊ท  ํ‰์  5.0

    5

    100% ์ˆ˜๊ฐ• ํ›„ ์ž‘์„ฑ

    ๋ฆฌ๋ˆ…์Šค ์ปค๋„ ํ•ดํ‚น์„ ์ฒ˜์Œ ๋ฐฐ์šฐ๋Š” ์ž…์žฅ์—์„œ ๋งค์šฐ ์œ ์šฉํ•œ ๊ฐ•์˜์˜€์Šต๋‹ˆ๋‹ค. ํ•ต์‹ฌ ๋‚ด์šฉ์„ ์ดํ•ด๊ฐ€ ์‰ฝ๊ฒŒ ์„ค๋ช…ํ•ด์ฃผ์…จ๊ณ  QEMU๋ฅผ ํ†ตํ•œ ํ•™์Šต ์˜ˆ์ œ๋กœ ๋”์šฑ ์ดํ•ด๊ฐ€ ์‰ฌ์› ์Šต๋‹ˆ๋‹ค. https://defenit.kr/2019/12/03/Pwn/%E3%84%B4%20Research/linux-kenel-bpf/ ํŒ€ Defenit์˜ ์ปค๋„ LPE ์ทจ์•ฝ์  ๋ถ„์„ ์ž๋ฃŒ์ธ ์œ„ ๋งํฌ์™€ ์—ฐ๊ณ„ํ•ด์„œ ํ•™์Šตํ•˜๋ฉด ํ•™์Šต ํšจ๊ณผ๊ฐ€ ๋”์šฑ ์ข‹์€ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. ์—ฌ๋Ÿฌ๊ฐ€์ง€๋กœ ํ•™์Šต์— ๋„์›€ ๋งŽ์ด ๋ฐ›๊ณ  ๊ฐ‘๋‹ˆ๋‹ค. ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค.

    • ๊น€ํ˜„์šฐ
      ์ง€์‹๊ณต์œ ์ž

      ์ž์„ธํ•œ ํ›„๊ธฐ ๊ฐ์‚ฌ๋“œ๋ฆฝ๋‹ˆ๋‹ค :)

  • ์„ ๋Œ€๋‹˜์˜ ํ”„๋กœํ•„ ์ด๋ฏธ์ง€
    ์„ ๋Œ€

    ์ˆ˜๊ฐ•ํ‰ 1

    โˆ™

    ํ‰๊ท  ํ‰์  5.0

    5

    100% ์ˆ˜๊ฐ• ํ›„ ์ž‘์„ฑ

    ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค.

    • ๊น€ํ˜„์šฐ
      ์ง€์‹๊ณต์œ ์ž

      ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค ใ…Žใ…Ž

๋น„์Šทํ•œ ๊ฐ•์˜

๊ฐ™์€ ๋ถ„์•ผ์˜ ๋‹ค๋ฅธ ๊ฐ•์˜๋ฅผ ๋งŒ๋‚˜๋ณด์„ธ์š”!

์›” โ‚ฉ33,000

5๊ฐœ์›” ํ• ๋ถ€ ์‹œ

โ‚ฉ165,000