|
Message-ID: <91958601-caf7-d895-5f98-e60e3f393ca7@riseup.net> Date: Mon, 18 Nov 2019 18:58:00 +0000 From: Patrick Schleizer <adrelanos@...eup.net> To: lkrg-users@...ts.openwall.com Subject: bug: LKRG kills VirtualBox host VMs Debian buster host. LKRG 0.7. This happened while VirtualBox 2 VMs were already running and installing LRKG. sudo dmesg | grep lkrg [ 336.576805] [p_lkrg] Loading LKRG... [ 337.126382] [p_lkrg] LKRG initialized successfully! [ 337.137161] [p_lkrg] <Exploit Detection> Not valid call - pCFI violation: process[EMT-2 | 2067] !!! [ 337.137164] [p_lkrg] <Exploit Detection> Frame[1] nr_entries[8]: [0xffffffffc106513b]. Full Stack: [ 337.137193] [p_lkrg] <Exploit Detection> Trying to kill process[EMT-2 | 2067]! [ 337.137234] [p_lkrg] <Exploit Detection> Stack pointer corruption (ROP?) - pCFI violation: process[EMT-2 | 2067] !!! [ 337.137235] [p_lkrg] <Exploit Detection> Trying to kill process[EMT-2 | 2067]! [ 337.485911] [p_lkrg] <Exploit Detection> Not valid call - pCFI violation: process[EMT-3 | 2116] !!! [ 337.485915] [p_lkrg] <Exploit Detection> Frame[1] nr_entries[8]: [0xffffffffc106513b]. Full Stack: [ 337.485959] [p_lkrg] <Exploit Detection> Trying to kill process[EMT-3 | 2116]! [ 337.486014] [p_lkrg] <Exploit Detection> Stack pointer corruption (ROP?) - pCFI violation: process[EMT-3 | 2116] !!! [ 337.486016] [p_lkrg] <Exploit Detection> Trying to kill process[EMT-3 | 2116]! This happened after reboot when trying start a VM: Nov 18 08:30:58 debian kernel: vboxdrv: 0000000000000000 VMMR0.r0 Nov 18 08:30:59 debian kernel: vboxdrv: 0000000000000000 VBoxDDR0.r0 Nov 18 08:30:59 debian kernel: vboxpci: created IOMMU domain 000000000278fc42 Nov 18 08:30:59 debian kernel: [p_lkrg] <Exploit Detection> Not valid call - pCFI violation: process[EMT-1 | 5252] !!! Nov 18 08:30:59 debian kernel: [p_lkrg] <Exploit Detection> Frame[1] nr_entries[8]: [0xffffffffc106513b]. Full Stack: Nov 18 08:30:59 debian kernel: --- . --- Nov 18 08:30:59 debian kernel: schedule+0x1/0x80 Nov 18 08:30:59 debian kernel: 0xffffffffc106513b Nov 18 08:30:59 debian kernel: 0xffffffffc1065428 Nov 18 08:30:59 debian kernel: 0xffffffffc108817d Nov 18 08:30:59 debian kernel: 0xffffffffc1088c24 Nov 18 08:30:59 debian kernel: supdrvIOCtl+0xca6/0x36a0 [vboxdrv] Nov 18 08:30:59 debian kernel: VBoxDrvLinuxIOCtl_6_0_14+0x15c/0x230 [vboxdrv] Nov 18 08:30:59 debian kernel: do_vfs_ioctl+0xa4/0x630 Nov 18 08:30:59 debian kernel: --- END --- Nov 18 08:30:59 debian kernel: [p_lkrg] <Exploit Detection> Trying to kill process[EMT-1 | 5252]! Nov 18 08:30:59 debian kernel: [p_lkrg] <Exploit Detection> Stack pointer corruption (ROP?) - pCFI violation: process[EMT-1 | 5252] !!! Nov 18 08:30:59 debian kernel: [p_lkrg] <Exploit Detection> Trying to kill process[EMT-1 | 5252]! Nov 18 08:30:59 debian kernel: vboxpci: freeing IOMMU domain 000000000278fc42 Nov 18 08:31:08 debian kernel: [p_lkrg] System is clean! Nov 18 08:31:24 debian kernel: [p_lkrg] System is clean! Nov 18 08:31:28 debian kernel: [p_lkrg] System is clean! Nov 18 08:31:28 debian kernel: [p_lkrg] System is clean! Nov 18 08:31:39 debian kernel: [p_lkrg] System is clean! Kind regards, Patrick
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.