Kernel Address Leak in Samsung KNOX v2.6
The 'pm_qos' module exposes an interface to kernel space for specifying QoS dependencies. In order to aid in debugging this interface, the module exposes a 'debugfs' interface, available under '/sys/kernel/debug/pm_qos'. This file is world-readable, and allows any user to query the current QOS constraints. The code which prints out each constraint is available under the 'pm_qos_debug_show_one' function in the file 'kernel/power/qos.c'. As seen above, the function prints out the QOS constraint entries (which are static variables stored in the kernel's BSS). To avoid leaking the BSS addresses to unprivileged users, the function uses the format specifier '%pk'. Note that the 'k' character in this format specifier is lowercase, instead of the correct specifier - '%pK' (using an uppercase 'K'). As format specifiers are case-sensitive, the 'vsnprintf' implementation simply ignores the lowercase 'k' - therefore always printing the pointer above. For devices with Samsung KNOX v2.6 (e.g., Galaxy S7 and Galaxy S7 Edge), this allows an attacker to bypass KASLR. This is since t-base (the KNOX security kernel) is loaded at a fixed address, and the attacker can simply read the address of the 'pm_qos' module from the debugfs interface.