Impact
udev's scsi_id and v4l_id helper binaries, which parse input from the kernel, are vulnerable to malicious devices being plugged in, with intentionally crafted properties exposed to the respective kernel drivers, that send them down to userspace without sanitization.
For v4l_id, the ID_V4L_PRODUCT property is derived from the USB descriptor, and a custom device can set it to foo\nREMOVE_CMD=/path/to/exe to have udev run the selected executable as root.
For scsi_id, the ID_SCSI_SERIAL property is derived from the hardware's SCSI serial, which can be crafted to contain \n SYSTEMD_WANTS=foobar.service so that it can be used to activate a unit of the attacker's choice, including debug-shell.service which spawns a root console.
Patches
v260 16325b3 54f880b
v259.5 3513862 4425d85
v258.7 c20d21e 75c585b
v257.13 03bb697 5887e72
Workarounds
Disable the v4l and iscsi drivers in the kernel
References
Originally reported on yeswehack.com as YWH-PGM9780-98 and YWH-PGM9780-99
Impact
udev's
scsi_idandv4l_idhelper binaries, which parse input from the kernel, are vulnerable to malicious devices being plugged in, with intentionally crafted properties exposed to the respective kernel drivers, that send them down to userspace without sanitization.For
v4l_id, theID_V4L_PRODUCTproperty is derived from the USB descriptor, and a custom device can set it tofoo\nREMOVE_CMD=/path/to/exeto have udev run the selected executable as root.For
scsi_id, theID_SCSI_SERIALproperty is derived from the hardware's SCSI serial, which can be crafted to contain\n SYSTEMD_WANTS=foobar.serviceso that it can be used to activate a unit of the attacker's choice, includingdebug-shell.servicewhich spawns a root console.Patches
v260 16325b3 54f880b
v259.5 3513862 4425d85
v258.7 c20d21e 75c585b
v257.13 03bb697 5887e72
Workarounds
Disable the v4l and iscsi drivers in the kernel
References
Originally reported on yeswehack.com as YWH-PGM9780-98 and YWH-PGM9780-99