OpenBSD Kernel Relinking Issue

Discussion in 'News Aggregator' started by Packet Storm, 20 Jun 2023.

  1. Packet Storm

    Packet Storm Guest

    The automatic and mandatory-by-default reordering of OpenBSD kernels is not transactional and as a result, a local unpatched exploit exists which allows tampering or replacement of the kernel. Arbitrary build artifacts are cyclically relinked with no data integrity or provenance being maintained or verified for the objects being consumed with respect to the running kernel before and during the execution of the mandatory kernel_reorder process in the supplied /etc/rc and /usr/libexec scripts. The reordering occurs at the end of installation process and also automatically every reboot cycle thereafter unless manually bypassed by a knowledgeable party.

    Continue reading...
     

Share This Page

Loading...