@kees_cooki
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
Free Software Hacker he/him @kees@fosstodon.org
Portland, OR, USA
Joined February 2010
- Tweets435
- Following109
- Followers4.9K
- Likes394
Today's the 7th anniversary of founding the Kernel Self-Protection Project!
lore.kernel.org/kernel-harde…
We've come a long way, but there's still lots more work to do. :)
If you can't switch your C to Rust immediately, consider at least enabling all the sanity checking the compiler can already do for free:
-Wall
-D_FORTIFY_SOURCE=2
-fsanitize=bounds fsanitize-undefined-trap-on-error
-fstrict-flex-arrays (GCC 13+, Clang 16+)
I've started trying to document the various things I've learned about using Coccinelle to match code patterns in the Linux kernel here:
github.com/kees/kernel-tools…
It's hardly complete, but I wanted to start keeping notes somewhere I could find later. :)
I looked through these RCEs: they appear to all be command injection. (Though the MS issues don't have much detail.) Notably, there aren't any memory safety issues. But this is also more about web/net services, and command injection is the low hanging fruit in that environment.
This quoted post is unavailable.
Thank you @samitolvanen, Peter, Joao, @nullmodem, @embeddedgus, @nathanchance, Nick, Sedat, Josh, and everyone else who helped get KCFI developed and landed!
git.kernel.org/linus/865dad2…
I think -Wimplicit-fallthrough should be enabled by -Wall. Right now it's only on with -Wextra. Thoughts?
We've finally landed the run-time memcpy() overflow warning patch in linux-next:
git.kernel.org/pub/scm/linux…
So now I'm constantly reloading a search on lore, checking if anyone has run into new instances on real work loads. :P
lore.kernel.org/all/?q=%22de…
So many interesting finds in this research! I struggle to fit even one in a tweet:
"... while we may not be decreasing the # of vulns... there are indications [of] ... a notion of maturity, where vulns will be mostly absent from code older than a specific point in the past."
How Long Do Vulnerabilities Live in the Code? A Large-Scale Empirical Measurement Study on FOSS Vulnerability Lifetimes | USENIX usenix.org/conference/usenix…
Here are my notes on how I've been doing "no binary change" analysis of Linux kernel patches that are meant to not change executable output, motivated by our efforts to replace 1-element arrays with proper flexible arrays:
outflux.net/blog/archives/20…
tl;dr: diffoscope
Fantastic write-up, confirms the benefits of CFI and auto-var-init:
"automatic variable initialization ... kill[s] a whole class of bugs, but it also breaks some useful exploit primitives."
"[kernel]CFI is arguably the mitigation that takes the most effort to bypass"
This is probably the most complex exploit I've done so far. A UAF in Android kernel freed by kfree_rcu (introduces a delay) in a tight race + kCFI + Samsung RKP. Yet its still possible to gain arbitrary kernel RW, disable SE and root from untrusted app. github.blog/2022-06-16-the-a…
Everyone please go add -ftrivial-auto-var-init=zero to your default build flags. :)
GCC 12.1 Released! Lots of great improvements! gcc.gnu.org/pipermail/gcc/20…
Here's a new API for dealing with bounds-checking flexible array structs in C (i.e. to replace open-coded memcpy():
lore.kernel.org/linux-harden…
These new helpers got redesigned so many times before I was happy with them. :P
events.linuxfoundation.org/l…
The Linux Security Summit NA 2022 schedule is up! Come join us: Austin, TX, USA June 23/24.
noncombatant.org/2022/04/22/…
@fugueish: "A big part of the purpose — or, potential — for public vulnerability announcements and reports is to teach and learn, mature the engineering culture, and above all to avoid repeating these problems"
i.e. "actually describe the flaw in detail"
It feels a little bit like archaeology, but here are my notes on security things in Linux v5.10: addfd, SEV-ES, static calls, pRNG improvement, SafeSetID with gid, set_fs removal, sysfs_emit, nosymfollow, MTE, UBSAN-discovered fixes, and flex array work.
outflux.net/blog/archives/20…
I'm really happy to see kernel IBT support land. Coarse-grained forward edge CFI! (Supported on Tigerlake and later Intel systems, and Zen3 and later AMD systems.)
git.kernel.org/linus/7001052…
Based on the excellent by worLdle, I have replaced the country data with US states, and present: statele
outflux.net/statele/