diff options
| author | Peter Marko <peter.marko@siemens.com> | 2025-04-24 19:39:36 +0200 |
|---|---|---|
| committer | Steve Sakoman <steve@sakoman.com> | 2025-05-02 08:20:11 -0700 |
| commit | f9ef163a431edbf8e30b9c35b903547b2cbb3f24 (patch) | |
| tree | 3ae24649454e1a5d72fc933aa48d9af110eb26ab | |
| parent | 46aa1e0ebaf76ea4f0244e7034087d5b15b7936f (diff) | |
| download | poky-f9ef163a431edbf8e30b9c35b903547b2cbb3f24.tar.gz | |
ppp: patch CVE-2024-58250
Backport patch to remove vulnerable component.
This is a breaking change, but there will be no other fix for this CVE
as upstream did the deletion without providing a fix first.
If someone really needs this feature, which the commit message describes
as deprecated, bbappend with patch removal is possible.
License-Update: passprompt plugin removed
(From OE-Core rev: 5350ef531ded14f0b4c32c211aaf993354be1ec9)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
| -rw-r--r-- | meta/recipes-connectivity/ppp/ppp/CVE-2024-58250.patch | 194 | ||||
| -rw-r--r-- | meta/recipes-connectivity/ppp/ppp_2.5.0.bb | 2 |
2 files changed, 195 insertions, 1 deletions
diff --git a/meta/recipes-connectivity/ppp/ppp/CVE-2024-58250.patch b/meta/recipes-connectivity/ppp/ppp/CVE-2024-58250.patch new file mode 100644 index 0000000000..55d36c5baa --- /dev/null +++ b/meta/recipes-connectivity/ppp/ppp/CVE-2024-58250.patch | |||
| @@ -0,0 +1,194 @@ | |||
| 1 | From 0a66ad22e54c72690ec2a29a019767c55c5281fc Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Paul Mackerras <paulus@ozlabs.org> | ||
| 3 | Date: Fri, 18 Oct 2024 20:22:57 +1100 | ||
| 4 | Subject: [PATCH] pppd: Remove passprompt plugin | ||
| 5 | |||
| 6 | This is prompted by a number of factors: | ||
| 7 | |||
| 8 | * It was more useful back in the dial-up days, but no-one uses dial-up | ||
| 9 | any more | ||
| 10 | |||
| 11 | * In many cases there will be no terminal accessible to the prompter | ||
| 12 | program at the point where the prompter is run | ||
| 13 | |||
| 14 | * The passwordfd plugin does much the same thing but does it more | ||
| 15 | cleanly and securely | ||
| 16 | |||
| 17 | * The handling of privileges and file descriptors needs to be audited | ||
| 18 | thoroughly. | ||
| 19 | |||
| 20 | Signed-off-by: Paul Mackerras <paulus@ozlabs.org> | ||
| 21 | |||
| 22 | CVE: CVE-2024-58250 | ||
| 23 | Upstream-Status: Backport [https://github.com/ppp-project/ppp/commit/0a66ad22e54c72690ec2a29a019767c55c5281fc] | ||
| 24 | Signed-off-by: Peter Marko <peter.marko@siemens.com> | ||
| 25 | --- | ||
| 26 | pppd/plugins/Makefile.am | 6 +- | ||
| 27 | pppd/plugins/passprompt.c | 137 -------------------------------------- | ||
| 28 | 2 files changed, 1 insertion(+), 142 deletions(-) | ||
| 29 | delete mode 100644 pppd/plugins/passprompt.c | ||
| 30 | |||
| 31 | diff --git a/pppd/plugins/Makefile.am b/pppd/plugins/Makefile.am | ||
| 32 | index 2826148..9480d51 100644 | ||
| 33 | --- a/pppd/plugins/Makefile.am | ||
| 34 | +++ b/pppd/plugins/Makefile.am | ||
| 35 | @@ -1,4 +1,4 @@ | ||
| 36 | -pppd_plugin_LTLIBRARIES = minconn.la passprompt.la passwordfd.la winbind.la | ||
| 37 | +pppd_plugin_LTLIBRARIES = minconn.la passwordfd.la winbind.la | ||
| 38 | pppd_plugindir = $(PPPD_PLUGIN_DIR) | ||
| 39 | |||
| 40 | PLUGIN_CPPFLAGS = -I${top_srcdir} | ||
| 41 | @@ -8,10 +8,6 @@ minconn_la_CPPFLAGS = $(PLUGIN_CPPFLAGS) | ||
| 42 | minconn_la_LDFLAGS = $(PLUGIN_LDFLAGS) | ||
| 43 | minconn_la_SOURCES = minconn.c | ||
| 44 | |||
| 45 | -passprompt_la_CPPFLAGS = $(PLUGIN_CPPFLAGS) | ||
| 46 | -passprompt_la_LDFLAGS = $(PLUGIN_LDFLAGS) | ||
| 47 | -passprompt_la_SOURCES = passprompt.c | ||
| 48 | - | ||
| 49 | passwordfd_la_CPPFLAGS = $(PLUGIN_CPPFLAGS) | ||
| 50 | passwordfd_la_LDFLAGS = $(PLUGIN_LDFLAGS) | ||
| 51 | passwordfd_la_SOURCES = passwordfd.c | ||
| 52 | diff --git a/pppd/plugins/passprompt.c b/pppd/plugins/passprompt.c | ||
| 53 | deleted file mode 100644 | ||
| 54 | index 7779d51..0000000 | ||
| 55 | --- a/pppd/plugins/passprompt.c | ||
| 56 | +++ /dev/null | ||
| 57 | @@ -1,137 +0,0 @@ | ||
| 58 | -/* | ||
| 59 | - * passprompt.c - pppd plugin to invoke an external PAP password prompter | ||
| 60 | - * | ||
| 61 | - * Copyright 1999 Paul Mackerras, Alan Curry. | ||
| 62 | - * | ||
| 63 | - * This program is free software; you can redistribute it and/or | ||
| 64 | - * modify it under the terms of the GNU General Public License | ||
| 65 | - * as published by the Free Software Foundation; either version | ||
| 66 | - * 2 of the License, or (at your option) any later version. | ||
| 67 | - */ | ||
| 68 | - | ||
| 69 | -#include <errno.h> | ||
| 70 | -#include <unistd.h> | ||
| 71 | -#include <sys/wait.h> | ||
| 72 | -#include <sys/param.h> | ||
| 73 | -#include <limits.h> | ||
| 74 | -#include <stdio.h> | ||
| 75 | -#include <syslog.h> | ||
| 76 | -#include <stdarg.h> | ||
| 77 | -#include <stdint.h> | ||
| 78 | -#include <stdbool.h> | ||
| 79 | -#include <string.h> | ||
| 80 | - | ||
| 81 | -#include <pppd/pppd.h> | ||
| 82 | -#include <pppd/upap.h> | ||
| 83 | -#include <pppd/eap.h> | ||
| 84 | -#include <pppd/options.h> | ||
| 85 | - | ||
| 86 | -char pppd_version[] = PPPD_VERSION; | ||
| 87 | - | ||
| 88 | -static char promptprog[PATH_MAX+1]; | ||
| 89 | -static int promptprog_refused = 0; | ||
| 90 | - | ||
| 91 | -static struct option options[] = { | ||
| 92 | - { "promptprog", o_string, promptprog, | ||
| 93 | - "External PAP password prompting program", | ||
| 94 | - OPT_STATIC, NULL, PATH_MAX }, | ||
| 95 | - { NULL } | ||
| 96 | -}; | ||
| 97 | - | ||
| 98 | -static int promptpass(char *user, char *passwd) | ||
| 99 | -{ | ||
| 100 | - int p[2]; | ||
| 101 | - pid_t kid; | ||
| 102 | - int readgood, wstat, ret; | ||
| 103 | - ssize_t red; | ||
| 104 | - | ||
| 105 | - if (promptprog_refused || promptprog[0] == 0 || access(promptprog, X_OK) < 0) | ||
| 106 | - return -1; /* sorry, can't help */ | ||
| 107 | - | ||
| 108 | - if (!passwd) | ||
| 109 | - return 1; | ||
| 110 | - | ||
| 111 | - if (pipe(p)) { | ||
| 112 | - warn("Can't make a pipe for %s", promptprog); | ||
| 113 | - return 0; | ||
| 114 | - } | ||
| 115 | - if ((kid = fork()) == (pid_t) -1) { | ||
| 116 | - warn("Can't fork to run %s", promptprog); | ||
| 117 | - close(p[0]); | ||
| 118 | - close(p[1]); | ||
| 119 | - return 0; | ||
| 120 | - } | ||
| 121 | - if (!kid) { | ||
| 122 | - /* we are the child, exec the program */ | ||
| 123 | - char *argv[5], fdstr[32]; | ||
| 124 | - ppp_sys_close(); | ||
| 125 | - closelog(); | ||
| 126 | - close(p[0]); | ||
| 127 | - ret = seteuid(getuid()); | ||
| 128 | - if (ret != 0) { | ||
| 129 | - warn("Couldn't set effective user id"); | ||
| 130 | - } | ||
| 131 | - ret = setegid(getgid()); | ||
| 132 | - if (ret != 0) { | ||
| 133 | - warn("Couldn't set effective user id"); | ||
| 134 | - } | ||
| 135 | - sprintf(fdstr, "%d", p[1]); | ||
| 136 | - argv[0] = promptprog; | ||
| 137 | - argv[1] = strdup(user); | ||
| 138 | - argv[2] = strdup(ppp_remote_name()); | ||
| 139 | - argv[3] = fdstr; | ||
| 140 | - argv[4] = 0; | ||
| 141 | - execv(*argv, argv); | ||
| 142 | - _exit(127); | ||
| 143 | - } | ||
| 144 | - | ||
| 145 | - /* we are the parent, read the password from the pipe */ | ||
| 146 | - close(p[1]); | ||
| 147 | - readgood = 0; | ||
| 148 | - do { | ||
| 149 | - red = read(p[0], passwd + readgood, MAXSECRETLEN-1 - readgood); | ||
| 150 | - if (red == 0) | ||
| 151 | - break; | ||
| 152 | - if (red < 0) { | ||
| 153 | - if (errno == EINTR && !ppp_signaled(SIGTERM)) | ||
| 154 | - continue; | ||
| 155 | - error("Can't read secret from %s: %m", promptprog); | ||
| 156 | - readgood = -1; | ||
| 157 | - break; | ||
| 158 | - } | ||
| 159 | - readgood += red; | ||
| 160 | - } while (readgood < MAXSECRETLEN - 1); | ||
| 161 | - close(p[0]); | ||
| 162 | - | ||
| 163 | - /* now wait for child to exit */ | ||
| 164 | - while (waitpid(kid, &wstat, 0) < 0) { | ||
| 165 | - if (errno != EINTR || ppp_signaled(SIGTERM)) { | ||
| 166 | - warn("error waiting for %s: %m", promptprog); | ||
| 167 | - break; | ||
| 168 | - } | ||
| 169 | - } | ||
| 170 | - | ||
| 171 | - if (readgood < 0) | ||
| 172 | - return 0; | ||
| 173 | - passwd[readgood] = 0; | ||
| 174 | - if (!WIFEXITED(wstat)) | ||
| 175 | - warn("%s terminated abnormally", promptprog); | ||
| 176 | - if (WEXITSTATUS(wstat)) { | ||
| 177 | - warn("%s exited with code %d", promptprog, WEXITSTATUS(wstat)); | ||
| 178 | - /* code when cancel was hit in the prompt prog */ | ||
| 179 | - if (WEXITSTATUS(wstat) == 128) { | ||
| 180 | - promptprog_refused = 1; | ||
| 181 | - } | ||
| 182 | - return -1; | ||
| 183 | - } | ||
| 184 | - return 1; | ||
| 185 | -} | ||
| 186 | - | ||
| 187 | -void plugin_init(void) | ||
| 188 | -{ | ||
| 189 | - ppp_add_options(options); | ||
| 190 | - pap_passwd_hook = promptpass; | ||
| 191 | -#ifdef PPP_WITH_EAPTLS | ||
| 192 | - eaptls_passwd_hook = promptpass; | ||
| 193 | -#endif | ||
| 194 | -} | ||
diff --git a/meta/recipes-connectivity/ppp/ppp_2.5.0.bb b/meta/recipes-connectivity/ppp/ppp_2.5.0.bb index badf22db97..b50795109f 100644 --- a/meta/recipes-connectivity/ppp/ppp_2.5.0.bb +++ b/meta/recipes-connectivity/ppp/ppp_2.5.0.bb | |||
| @@ -7,7 +7,6 @@ BUGTRACKER = "http://ppp.samba.org/cgi-bin/ppp-bugs" | |||
| 7 | DEPENDS = "libpcap openssl virtual/crypt" | 7 | DEPENDS = "libpcap openssl virtual/crypt" |
| 8 | LICENSE = "BSD-3-Clause & BSD-3-Clause-Attribution & GPL-2.0-or-later & LGPL-2.0-or-later & PD & RSA-MD" | 8 | LICENSE = "BSD-3-Clause & BSD-3-Clause-Attribution & GPL-2.0-or-later & LGPL-2.0-or-later & PD & RSA-MD" |
| 9 | LIC_FILES_CHKSUM = "file://pppd/ccp.c;beginline=1;endline=29;md5=e2c43fe6e81ff77d87dc9c290a424dea \ | 9 | LIC_FILES_CHKSUM = "file://pppd/ccp.c;beginline=1;endline=29;md5=e2c43fe6e81ff77d87dc9c290a424dea \ |
| 10 | file://pppd/plugins/passprompt.c;beginline=1;endline=10;md5=3bcbcdbf0e369c9a3e0b8c8275b065d8 \ | ||
| 11 | file://pppd/tdb.c;beginline=1;endline=27;md5=4ca3a9991b011038d085d6675ae7c4e6 \ | 10 | file://pppd/tdb.c;beginline=1;endline=27;md5=4ca3a9991b011038d085d6675ae7c4e6 \ |
| 12 | file://chat/chat.c;beginline=1;endline=15;md5=0d374b8545ee5c62d7aff1acbd38add2" | 11 | file://chat/chat.c;beginline=1;endline=15;md5=0d374b8545ee5c62d7aff1acbd38add2" |
| 13 | 12 | ||
| @@ -24,6 +23,7 @@ SRC_URI = "https://download.samba.org/pub/${BPN}/${BP}.tar.gz \ | |||
| 24 | file://provider \ | 23 | file://provider \ |
| 25 | file://ppp@.service \ | 24 | file://ppp@.service \ |
| 26 | file://0001-Revert-lock-path-to-var-lock-435.patch \ | 25 | file://0001-Revert-lock-path-to-var-lock-435.patch \ |
| 26 | file://CVE-2024-58250.patch \ | ||
| 27 | " | 27 | " |
| 28 | 28 | ||
| 29 | SRC_URI[sha256sum] = "5cae0e8075f8a1755f16ca290eb44e6b3545d3f292af4da65ecffe897de636ff" | 29 | SRC_URI[sha256sum] = "5cae0e8075f8a1755f16ca290eb44e6b3545d3f292af4da65ecffe897de636ff" |
