目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-26475 PoC — radare2 安全漏洞

来源
关联漏洞
标题: radare2 安全漏洞 (CVE-2024-26475)
Description:radare2是一套用于处理二进制文件的库和工具。 radare2 v.0.9.7 到 v.5.8.6版本存在安全漏洞,该漏洞源于允许本地攻击者通过 grub_sfs_read_extent 函数造成拒绝服务。
Description
An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent function.
介绍
# CVE-2024-26475

## Authors
Sherlock Fang, Vlad Tronciu, Ayam Babu

## Description
An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent function.

## Attack Vectors
Crafting a payload to cause “treeblock = grub_malloc(data->blocksize);” points to NULL in memory, so that when the value of “treeblock” is assigned to “tree = (struct grub_sfs_btree *) treeblock;”, “treeblock” also points to NULL. The extent of exploitability depends on specific contexts, but such a null pointer dereference vulnerability would cause the program a defial of service, which affects the overall program performance.

## Explanation of Vulnerability
Inside function grub_sfs_read_extent there exists a security vulnerability due to the lack of a check for the state of tree_block. The subsequent code proceeds to use tree_block without verifying that it points to a valid memory allocation. This will lead to the dereference of a NULL pointer when the tree is assgned the value of treeblock cast to a struct grub_sfs_btree* and then used in the call to grub_disk_read. Dereferencing a NULL pointer us undefined behaviour in C and typically results in a segmentation fault or access violation, causing the program to crash.

[<img width="500" alt="image" src="https://github.com/TronciuVlad/CVE-2024-26475/blob/main/vulnerable_function.png">](https://github.com/TronciuVlad/CVE-2024-26475/blob/main/vulnerable_function.png)

## Solution

We fixed the vulnerability by adding a check of the allocation state of grub_malloc, as shown below.

[<img width="500" alt="image" src="https://github.com/TronciuVlad/CVE-2024-26475/blob/main/solution.png">](https://github.com/TronciuVlad/CVE-2024-26475/blob/main/solution.png)

## References
https://cwe.mitre.org/data/definitions/476.html
<br>
https://github.com/radareorg/radare2/issues/22586
<br>
https://github.com/radareorg/radare2/commit/8419d7d0cbe61c687dcb8a35de0acccb2ee4c220
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →