summaryrefslogtreecommitdiffstats
path: root/meta
diff options
context:
space:
mode:
authorVijay Anusuri <vanusuri@mvista.com>2024-07-16 12:54:35 +0530
committerSteve Sakoman <steve@sakoman.com>2024-07-23 06:05:47 -0700
commit60df41d7e5e076fb8543acf1054771b844d87c02 (patch)
tree0f47bd27a3cae204aabff49c418a7c42d1fa4062 /meta
parentfbd068df2185c40db4bb73cf4c1d498d2f0dd03c (diff)
downloadpoky-60df41d7e5e076fb8543acf1054771b844d87c02.tar.gz
openssh: fix CVE-2024-39894
ssh(1) in OpenSSH versions 9.5p1 to 9.7p1 (inclusive). Logic error in ObscureKeystrokeTiming option. A logic error in the implementation of the ssh(1) ObscureKeystrokeTiming option rendered the feature ineffective and additionally exposed limited keystroke timing information when terminal echo was disabled, e.g. while entering passwords to su(8) or sudo(8). This condition could be avoided for affected versions by disabling the feature using ObscureKeystrokeTiming=no. References: https://www.openssh.com/security.html https://www.openssh.com/txt/release-9.8 Upstream-Status: Backport [https://github.com/openssh/openssh-portable/commit/146c420d29d055cc75c8606327a1cf8439fe3a08] (From OE-Core rev: 644716564d8c223c71be635e2f1794c74ae23d7f) Signed-off-by: Vijay Anusuri <vanusuri@mvista.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'meta')
-rw-r--r--meta/recipes-connectivity/openssh/openssh/CVE-2024-39894.patch35
-rw-r--r--meta/recipes-connectivity/openssh/openssh_9.6p1.bb1
2 files changed, 36 insertions, 0 deletions
diff --git a/meta/recipes-connectivity/openssh/openssh/CVE-2024-39894.patch b/meta/recipes-connectivity/openssh/openssh/CVE-2024-39894.patch
new file mode 100644
index 0000000000..898295340d
--- /dev/null
+++ b/meta/recipes-connectivity/openssh/openssh/CVE-2024-39894.patch
@@ -0,0 +1,35 @@
1From 146c420d29d055cc75c8606327a1cf8439fe3a08 Mon Sep 17 00:00:00 2001
2From: "djm@openbsd.org" <djm@openbsd.org>
3Date: Mon, 1 Jul 2024 04:31:17 +0000
4Subject: [PATCH] upstream: when sending ObscureKeystrokeTiming chaff packets,
5 we
6
7can't rely on channel_did_enqueue to tell that there is data to send. This
8flag indicates that the channels code enqueued a packet on _this_ ppoll()
9iteration, not that data was enqueued in _any_ ppoll() iteration in the
10timeslice. ok markus@
11
12OpenBSD-Commit-ID: 009b74fd2769b36b5284a0188ade182f00564136
13
14Upstream-Status: Backport [import from ubuntu https://git.launchpad.net/ubuntu/+source/openssh/tree/debian/patches/CVE-2024-39894.patch?h=ubuntu/noble-security
15Upstream commit https://github.com/openssh/openssh-portable/commit/146c420d29d055cc75c8606327a1cf8439fe3a08]
16CVE: CVE-2024-39894
17Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
18---
19 clientloop.c | 7 ++++---
20 1 file changed, 4 insertions(+), 3 deletions(-)
21
22--- a/clientloop.c
23+++ b/clientloop.c
24@@ -612,8 +612,9 @@ obfuscate_keystroke_timing(struct ssh *s
25 if (timespeccmp(&now, &chaff_until, >=)) {
26 /* Stop if there have been no keystrokes for a while */
27 stop_reason = "chaff time expired";
28- } else if (timespeccmp(&now, &next_interval, >=)) {
29- /* Otherwise if we were due to send, then send chaff */
30+ } else if (timespeccmp(&now, &next_interval, >=) &&
31+ !ssh_packet_have_data_to_write(ssh)) {
32+ /* If due to send but have no data, then send chaff */
33 if (send_chaff(ssh))
34 nchaff++;
35 }
diff --git a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
index 3cdf0327b0..8bc4f4269a 100644
--- a/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
+++ b/meta/recipes-connectivity/openssh/openssh_9.6p1.bb
@@ -28,6 +28,7 @@ SRC_URI = "http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar
28 file://0001-regress-banner.sh-log-input-and-output-files-on-erro.patch \ 28 file://0001-regress-banner.sh-log-input-and-output-files-on-erro.patch \
29 file://0001-systemd-Add-optional-support-for-systemd-sd_notify.patch \ 29 file://0001-systemd-Add-optional-support-for-systemd-sd_notify.patch \
30 file://CVE-2024-6387.patch \ 30 file://CVE-2024-6387.patch \
31 file://CVE-2024-39894.patch \
31 " 32 "
32SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c" 33SRC_URI[sha256sum] = "910211c07255a8c5ad654391b40ee59800710dd8119dd5362de09385aa7a777c"
33 34