Received: by 2002:a25:1506:0:0:0:0:0 with SMTP id 6csp433346ybv; Fri, 7 Feb 2020 02:05:05 -0800 (PST) X-Google-Smtp-Source: APXvYqx1YJHm1ffz755m1MpfAp7ojydFgLDln2yQn+7+Ni3jzp2NIJC/79tpOshi8AkA4aag5yP5 X-Received: by 2002:a9d:66ca:: with SMTP id t10mr2012182otm.352.1581069905273; Fri, 07 Feb 2020 02:05:05 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1581069905; cv=none; d=google.com; s=arc-20160816; b=aptb2LLZ8lULiz4GAed7918MRzLK1lB4Vim6e7n9ZZrReisrLk3hG5zFdATmp/wklM GdBrTzvFFeTMp6zqtWd3l5BZpy0t80CG2BLu87nwci2J5rIngAJoLEOphFgocYj2eIxn yUtK1v092O5OF7ffZLRUlp9yX508TB3M7VQ1NP275auzF0Dy5i1qM8uB5KJVW+4qi44x xMqc4pfYKHPyBCQ7Hm/76z78PfwSlu2Njpx3OL9GTHl+OZw1KtFJa6XFX/QvF9b6JJuq wk0mO3E33Ltv8Zz5e9AlTl3Yu/6MQ4wZOz4jrauYJ4niWHSuSEKhlyG0Ja2O3mDbbdIo PjAQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:from:subject:mime-version :message-id:date:dkim-signature; bh=PqRD4UbVhW58Tl+hqtfrY0XqJZDl4mnYLCjvYwU+muU=; b=vBP62YS62jpDzKKIplQ8LQ4dIL4srnmgVNYu+BIKin2n9YFNxSlJxrQjncKmcQvZGj LuTkhuh4YJj6Gc2RZ+Dy2ld+OvTTLwfYNAAwoqLTN7iV6rlIs+7eKUxT9Oj1D4kt/sPk WM1XoUr4Ex6Z5azsLImMBfX/FRAEj1MsCltou4HcP6FQ2fvb2MoAL0moIpFSy/1tiGhb Kh8rU18F4tC/2ScCNU3t92up4tRTg3tRjQc+ZcSm7vi/eCh5CUnM18sUVr6u2v38FAlu nbQC2U77FG1GclRzXm2qhWigKnewdZbbT+PnrZpmFbgQmryvjd9llM1CQV3T9y0emwVT RtGQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b="bYYROw/t"; spf=pass (google.com: best guess record for domain of linux-bluetooth-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id q195si3647914oic.83.2020.02.07.02.04.39; Fri, 07 Feb 2020 02:05:05 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-bluetooth-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b="bYYROw/t"; spf=pass (google.com: best guess record for domain of linux-bluetooth-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726587AbgBGKEN (ORCPT + 99 others); Fri, 7 Feb 2020 05:04:13 -0500 Received: from mail-qv1-f73.google.com ([209.85.219.73]:50805 "EHLO mail-qv1-f73.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726619AbgBGKEJ (ORCPT ); Fri, 7 Feb 2020 05:04:09 -0500 Received: by mail-qv1-f73.google.com with SMTP id c1so813190qvw.17 for ; Fri, 07 Feb 2020 02:04:08 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=date:message-id:mime-version:subject:from:to:cc; bh=PqRD4UbVhW58Tl+hqtfrY0XqJZDl4mnYLCjvYwU+muU=; b=bYYROw/t06LnGxEegtu8dkHpt81thJWvDlz7xRDTZzCCyEeE3CgC9SuCbdhERyO4oK IThTTjOGvDpcz38PmYV0zYNBPj2pmIId1tBts/UkRWRT8Muhaarwj0W981o2Y4M5rJwQ Ha9jDbvEgn23OumhugnI7NhO2HAdlQ9wrIyGM7zhbcI7r2i2BnA5SX+GhSWK3n1SMc25 rjMAL2oBVJ6mL9bAAWxNgfApo2JyLCK6xc/FGvVORwZE/OLYXfm2Qspp9UlKjfV6NYkI 3tUWp37az9OuHSu1j0tigFSjpOth/ukXPbmepEYqzHL8f3t+B4vy4Rat0fJNGc1A8Eit spKg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:message-id:mime-version:subject:from:to:cc; bh=PqRD4UbVhW58Tl+hqtfrY0XqJZDl4mnYLCjvYwU+muU=; b=Irg/N3BvwNOXrLsZoN8br1DqjZCH1Q7ztxW6gBdbGAIhZybysIvi7VzLQKVma59azg 90OOWVxrlyjbQliUCJ4AL8pcF448B0JRsSAYUO7E7ACDXjKKT4Vc9qB/MUjnPbAj4STJ w+wcPRz+v4VD5VdsmCcb1d3bWCpPoHCHCD3vLluUqqFLzsCdvoHOPSiGoe6j+dLwofGs I44Do2X5ykCtBJctkBApOq1YuzSTM5+awanYlgGK18+gYMNsrkjc5uoaNacmnIvWcymX L8GbE1FKhHjlM26Pf7Ljp6NOsjfVpQaFTgjF6qT6s/ke0mvzLFfizYuvEb8D2vxUbFKO E6VA== X-Gm-Message-State: APjAAAWzxEjwA7S6KBVveRuoX/uJ0m34zHaEgz58INo25/phfrJzF9ly hBfIPsZ0oa5p1xj2FCaQkvRu9jq1yQZPQMnVWKT6HMeBM3GS3oqQAdykB2Tu6iUGea64PSsfSaz wQmx9qF8IYbj1YEae8nsW3AjNAvDfOJlfSqAai6SLkOJskwuPJI4A6BO+leCxpaVKIahlucyvzO baLBKb0fwiIQ8= X-Received: by 2002:a05:6214:17cd:: with SMTP id cu13mr5858602qvb.192.1581069847854; Fri, 07 Feb 2020 02:04:07 -0800 (PST) Date: Fri, 7 Feb 2020 18:04:00 +0800 Message-Id: <20200207180348.Bluez.v2.1.Ia71869d2f3e19a76a6a352c61088a085a1d41ba6@changeid> Mime-Version: 1.0 X-Mailer: git-send-email 2.25.0.341.g760bfbb309-goog Subject: [Bluez PATCH v2] bluetooth: secure bluetooth stack from bluedump attack From: Howard Chung To: linux-bluetooth@vger.kernel.org, marcel@holtmann.org Cc: chromeos-bluetooth-upstreaming@chromium.org, Howard Chung , "David S. Miller" , Johan Hedberg , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Jakub Kicinski Content-Type: text/plain; charset="UTF-8" Sender: linux-bluetooth-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-bluetooth@vger.kernel.org Attack scenario: 1. A Chromebook (let's call this device A) is paired to a legitimate Bluetooth classic device (e.g. a speaker) (let's call this device B). 2. A malicious device (let's call this device C) pretends to be the Bluetooth speaker by using the same BT address. 3. If device A is not currently connected to device B, device A will be ready to accept connection from device B in the background (technically, doing Page Scan). 4. Therefore, device C can initiate connection to device A (because device A is doing Page Scan) and device A will accept the connection because device A trusts device C's address which is the same as device B's address. 5. Device C won't be able to communicate at any high level Bluetooth profile with device A because device A enforces that device C is encrypted with their common Link Key, which device C doesn't have. But device C can initiate pairing with device A with just-works model without requiring user interaction (there is only pairing notification). After pairing, device A now trusts device C with a new different link key, common between device A and C. 6. From now on, device A trusts device C, so device C can at anytime connect to device A to do any kind of high-level hijacking, e.g. speaker hijack or mouse/keyboard hijack. Since we don't know whether the repairing is legitimate or not, leave the decision to user space if all the conditions below are met. - the pairing is initialized by peer - the authorization method is just-work - host already had the link key to the peer Signed-off-by: Howard Chung --- Changes in v2: - Remove the HCI_PERMIT_JUST_WORK_REPAIR debugfs option - Fix the added code in classic - Add a similar fix for LE net/bluetooth/hci_event.c | 10 ++++++++++ net/bluetooth/smp.c | 18 ++++++++++++++++++ 2 files changed, 28 insertions(+) diff --git a/net/bluetooth/hci_event.c b/net/bluetooth/hci_event.c index 6ddc4a74a5e4..334d7ccd8d6e 100644 --- a/net/bluetooth/hci_event.c +++ b/net/bluetooth/hci_event.c @@ -4557,6 +4557,16 @@ static void hci_user_confirm_request_evt(struct hci_dev *hdev, goto confirm; } + /* If there already exists link key in local host, leave the + * decision to user space since the remote device could be + * legitimate or malicious. + */ + if (hci_find_link_key(hdev, &ev->bdaddr)) { + bt_dev_warn(hdev, "Local host already has link key"); + confirm_hint = 2; + goto confirm; + } + BT_DBG("Auto-accept of user confirmation with %ums delay", hdev->auto_accept_delay); diff --git a/net/bluetooth/smp.c b/net/bluetooth/smp.c index 83449a88a182..f58426dea4de 100644 --- a/net/bluetooth/smp.c +++ b/net/bluetooth/smp.c @@ -2118,6 +2118,7 @@ static u8 smp_cmd_pairing_random(struct l2cap_conn *conn, struct sk_buff *skb) u8 *pkax, *pkbx, *na, *nb; u32 passkey; int err; + struct smp_ltk *key; BT_DBG("conn %p", conn); @@ -2168,6 +2169,23 @@ static u8 smp_cmd_pairing_random(struct l2cap_conn *conn, struct sk_buff *skb) smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, sizeof(smp->prnd), smp->prnd); SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK); + + key = hci_find_ltk(hcon->hdev, &hcon->dst, hcon->dst_type, + hcon->role); + + /* If there already exists link key in local host, leave the + * decision to user space since the remote device could be + * legitimate or malicious. + */ + if (smp->method == JUST_WORKS && key) { + err = mgmt_user_confirm_request(hcon->hdev, &hcon->dst, + hcon->type, + hcon->dst_type, passkey, + 2); + if (err) + return SMP_UNSPECIFIED; + set_bit(SMP_FLAG_WAIT_USER, &smp->flags); + } } mackey_and_ltk: -- 2.25.0.341.g760bfbb309-goog