{"id":14510,"date":"2021-03-12T12:35:45","date_gmt":"2021-03-12T11:35:45","guid":{"rendered":"https:\/\/www.secuinfra.com\/?p=14510"},"modified":"2022-04-01T10:26:20","modified_gmt":"2022-04-01T08:26:20","slug":"cyber-defense-expert-discovers-vulnerability-in-linux-audit-framework","status":"publish","type":"post","link":"https:\/\/www.secuinfra.com\/en\/news\/cyber-defense-expert-discovers-vulnerability-in-linux-audit-framework\/","title":{"rendered":"Cyber defense expert discovers vulnerability in Linux audit framework"},"content":{"rendered":"<p>To support our customers with technical expertise and the latest industry knowledge, our cyber defense experts address fundamental questions and undergo mandatory training on a broad variety of products.<\/p>\n<p>It was in carrying out this kind of fundamental research in the Linux audit framework (Auditd) that we discovered a not insignificant vulnerability.<\/p>\n<p>After a thorough evaluation, we determined that file monitoring can be circumvented with sufficient authorizations. Specifically, the user must have the <em>CAP_DAC_READ_SEARCH<\/em> capability. This is typically true of the \u201c<em>root<\/em>\u201d administrator account. Under these conditions, the user can open files with the \u201c<em>open_by_handle_at<\/em>\u201d syscall and read and modify them at will without generating an entry in the Auditd log. We verified that this vulnerability can be exploited on <em>CentOS7, CentOS8<\/em>\u00a0and\u00a0<em>Ubuntu16.04<\/em>.<\/p>\n<p>The vulnerability was reported to the manufacturer <em>RedHat, Inc.<\/em> in mid-November 2020.\u00a0In accordance with standard disclosure practice, we gave the manufacturer 90 days to rectify the vulnerability.\u00a0The problem has been published under the reference <a  href=\"https:\/\/access.redhat.com\/security\/cve\/CVE-2020-35501\"  dpc-external=\"true\"  target=\"_blank\"  rel=\"nofollow\" ><em>CVE-2020-35501<\/em><\/a>.<\/p>\n<p>To keep our customers secure, our employees are deeply involved in the technical aspects of all processes. It is testament to the conscientiousness of our cyber defense experts that they managed to find this vulnerability.<\/p>\n<p>Please feel free to <a href=\"https:\/\/www.secuinfra.com\/en\/contact\/\">contact us<\/a> for more information about the discovery of the vulnerability and possible countermeasures.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>To support our customers with technical expertise and the latest industry knowledge, our cyber defense experts address fundamental questions and undergo mandatory training on a broad variety of products. It [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":14503,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[60],"tags":[],"dpc_coauthors":[],"class_list":["post-14510","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/posts\/14510","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/comments?post=14510"}],"version-history":[{"count":0,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/posts\/14510\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/media\/14503"}],"wp:attachment":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/media?parent=14510"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/categories?post=14510"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/tags?post=14510"},{"taxonomy":"dpc_coauthors","embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/dpc_coauthors?post=14510"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}