diff options
| author | Jose Quaresma <quaresma.jose@gmail.com> | 2024-07-03 13:17:01 +0100 |
|---|---|---|
| committer | Steve Sakoman <steve@sakoman.com> | 2024-07-09 06:02:55 -0700 |
| commit | 15480684aaadef90ca883a5ed4f484a1acc65438 (patch) | |
| tree | d43937e893f76e8a25bca40c9feaf6cf57266757 /meta | |
| parent | d0e754f0586bebe2f1f0d07ba9009f898e8f0902 (diff) | |
| download | poky-15480684aaadef90ca883a5ed4f484a1acc65438.tar.gz | |
openssh: fix CVE-2024-6387
sshd(8) in Portable OpenSSH versions 8.5p1 to 9.7p1 (inclusive).
Race condition resulting in potential remote code execution.
A race condition in sshd(8) could allow remote code execution as root on non-OpenBSD systems.
This attack could be prevented by disabling the login grace timeout (LoginGraceTime=0 in sshd_config)
though this makes denial-of service against sshd(8) considerably easier.
For more information, please refer to the release notes [1] and the
report from the Qualys Security Advisory Team [2] who discovered the bug.
[1] https://www.openssh.com/txt/release-9.8
[2] https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt
References:
https://www.openssh.com/security.html
(From OE-Core rev: 39537bf4f9c0e25c63e984da367e6915da986ff5)
Signed-off-by: Jose Quaresma <jose.quaresma@foundries.io>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'meta')
| -rw-r--r-- | meta/recipes-connectivity/openssh/openssh/CVE-2024-6387.patch | 27 | ||||
| -rw-r--r-- | meta/recipes-connectivity/openssh/openssh_9.6p1.bb | 1 |
2 files changed, 28 insertions, 0 deletions
diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2024-6387.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2024-6387.patch new file mode 100644 index 0000000000..3e7c707100 --- /dev/null +++ b/meta/recipes-connectivity/openssh/openssh/CVE-2024-6387.patch | |||
| @@ -0,0 +1,27 @@ | |||
| 1 | Description: fix signal handler race condition | ||
| 2 | Bug-Ubuntu: https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/2070497 | ||
| 3 | |||
| 4 | CVE: CVE-2024-6387 | ||
| 5 | |||
| 6 | Upstream-Status: Backport | ||
| 7 | https://git.launchpad.net/ubuntu/+source/openssh/commit/?h=applied/ubuntu/jammy-devel&id=b059bcfa928df4ff2d103ae2e8f4e3136ee03efc | ||
| 8 | |||
| 9 | Signed-off-by: Jose Quaresma <jose.quaresma@foundries.io> | ||
| 10 | |||
| 11 | --- a/log.c | ||
| 12 | +++ b/log.c | ||
| 13 | @@ -452,12 +452,14 @@ void | ||
| 14 | sshsigdie(const char *file, const char *func, int line, int showfunc, | ||
| 15 | LogLevel level, const char *suffix, const char *fmt, ...) | ||
| 16 | { | ||
| 17 | +#if 0 | ||
| 18 | va_list args; | ||
| 19 | |||
| 20 | va_start(args, fmt); | ||
| 21 | sshlogv(file, func, line, showfunc, SYSLOG_LEVEL_FATAL, | ||
| 22 | suffix, fmt, args); | ||
| 23 | va_end(args); | ||
| 24 | +#endif | ||
| 25 | _exit(1); | ||
| 26 | } | ||
| 27 | |||
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb index d941664b41..3cdf0327b0 100644 --- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb +++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb | |||
| @@ -27,6 +27,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar | |||
| 27 | file://add-test-support-for-busybox.patch \ | 27 | file://add-test-support-for-busybox.patch \ |
| 28 | file://0001-regress-banner.sh-log-input-and-output-files-on-erro.patch \ | 28 | file://0001-regress-banner.sh-log-input-and-output-files-on-erro.patch \ |
| 29 | file://0001-systemd-Add-optional-support-for-systemd-sd_notify.patch \ | 29 | file://0001-systemd-Add-optional-support-for-systemd-sd_notify.patch \ |
| 30 | file://CVE-2024-6387.patch \ | ||
| 30 | " | 31 | " |
| 31 | SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c" | 32 | SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c" |
| 32 | 33 | ||
