Skip to content
GoogleGHSA-fq5m-gg8q-qqr3

Grub-Legacy: Memory Corruption Vulnerabilities in Grub-Legacy's XFS Implementation

HighCVE-2023-4949 · Published Nov 10, 2023 · updated Jan 20, 2024

### Summary An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementation. This may allow attackers to execute arbitrary code undetectably. This affects variants of grub-legacy that run disk or from UEFI firmware. Other (less severe) memory corruption vulnerabilities exist, which may lead to the same outcome if exploited under the right conditions. ### Severity High - grub-legacy is used as a bootloader in certain embedded devices. There, plugging in a drive or accessing the system drive is trivial, either through physical access or through being root on the device. ### Proof of Concept Use dd to copy the [malicious partition](https://github.com/google/security-research/blob/master/pocs/grub/xfs_small.bin) to any partition in a disk image. Do not mount the partition but instead, use dd to overwrite one of the drive’s/image’s partitions. Example: ```Unset dd if=fxs_small.bin of=/dev/sdb2 ``` For demonstration purposes, we suggest using a virtual machine running Ubuntu 9.04. For our PoC, it is sufficient to run any kind of ...

GitHub advisory

Affected versions

PackageAffectedFixed in
security-research
Product
all versionsNo fix yet
Details and references

### Summary An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementation. This may allow attackers to execute arbitrary code undetectably. This affects variants of grub-legacy that run disk or from UEFI firmware. Other (less severe) memory corruption vulnerabilities exist, which may lead to the same outcome if exploited under the right conditions. ### Severity High - grub-legacy is used as a bootloader in certain embedded devices. There, plugging in a drive or accessing the system drive is trivial, either through physical access or through being root on the device. ### Proof of Concept Use dd to copy the [malicious partition](https://github.com/google/security-research/blob/master/pocs/grub/xfs_small.bin) to any partition in a disk image. Do not mount the partition but instead, use dd to overwrite one of the drive’s/image’s partitions. Example: ```Unset dd if=fxs_small.bin of=/dev/sdb2 ``` For demonstration purposes, we suggest using a virtual machine running Ubuntu 9.04. For our PoC, it is sufficient to run any kind of grub-legacy loader and interrupt it so that it’s possible to run commands. Using the “root” command, we can set the base drive that contains our malicious partition. Once the drive and partition have been selected (e.g. root(hd1,0) ) it is possible to trigger the bug by reading any file, for example by executing the cat command as shown in below screenshot. You can run the ubuntu virtual machine in a similar fashion, like so: ```Unset $ qemu-system-x86_64 -nographic -m 2048 -serial telnet:localhost:8888,server,nowait -enable-kvm -device ahci,id=ahci0,bus=pci.0 -drive file=./ubuntu9.04.qcow2,if=none,id=drive-sata-disk0,format=qcow2 -drive file=./xfs_small.bin,if=none,id=drive-sata-disk1,format=raw -device ide-hd,bus=ahci0.0,drive=drive-sata-disk0,id=drive-sata-disk0 -device ide-hd,bus=ahci0.1,drive=drive-sata-disk1,id=drive-sata-disk1 ``` Similar to what is shown in our screenshot, this will add a separate drive which contains the payload. When booting, interrupt the bootloader using the ESC button and switch to a console by typing ‘c’. Now, type ```Unset $ root (hd1,0) $ cat /asdf ``` And notice that the bootloader crashes and the system resets. ### Further Analysis By abusing a stack-based buffer overflow in grub-legacy (hereafter: grub), it is possible to execute arbitrary code in all known versions of grub-legacy that support the XFS file system. This can be exploited without user interaction, for example by using only root access, by modifying the hard drive given physical access or by plugging in a specially prepared drive. The exact conditions vary from system to system, however the vulnerability can affect both systems that boot automatically (with no interactive grub console) and systems that allow users to interact with grub. The vulnerability lies in grub’s XFS file system implementation and triggers automatically when grub tries to access any kind of file. As long as an attacker can modify the partition header and some portion of the partition on disk, it is possible to exploit the buffer overflow and overwrite the return value of the xfs_dir function such that attacker code (as read from the disk) is executed. When grub’s file system backend tries to open a file on a XFS partition (for example via grub_open), it calls xfs_dir and that function allocates linkbuf on the stack. That buffer is used to store data used to implement symbolic links. Importantly, that buffer is dynamically sized based on the xfs.bsize variable that is read from the superblock in xfs_mount. Information in the superblock is not strictly validated when the partition is mounted and should be considered untrusted since attackers with access to the disk can modify xfs.bsize. The function initially reads the first i

Severity from
GitHub (reviewed advisory)

More Google advisories

All Google
Advisory
Microsoft Edge: Arbitrary Perms
MediumDec 14, 2023
Envoy: ALTS Bug
MediumNov 29, 2023
Oracle VM VirtualBox: Integer Overflow Leading To Out-Of-Bounds Read in virtioNetR3CtrlMac
HighNov 16, 2023
Oracle VM VirtualBox: Intra-Object Out-Of-Bounds Write in virtioNetR3CtrlMultiQueue
HighNov 16, 2023
Oracle VM VirtualBox: Intra-Object Out-Of-Bounds Write in virtioNetR3CtrlVlan
HighNov 16, 2023
Java: DoS Vulnerability in JSON-JAVA
HighNov 14, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.