From 88277f4e2054966f093c29a167cc9d2ad767dd37 Mon Sep 17 00:00:00 2001 From: Philip Withnall Date: Tue, 28 Apr 2026 15:47:30 +0100 Subject: [PATCH 1/2] gdbusauthmechanismsha1: Validate cookie context MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Without validation, the server could send a malicious context which contains path traversal characters, allowing it to exfiltrate a SHA-1 hashed copy of arbitrary data from the client’s file system. To exploit this successfully would require the client to choose to connect peer-to-peer to a malicious D-Bus server and to choose the SHA-1 authentication mechanism in preference to all the other mechanisms. This is vanishingly unlikely. Signed-off-by: Philip Withnall Fixes: #3931 --- gio/gdbusauthmechanismsha1.c | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c index c8aa08977..7f348d862 100644 --- a/gio/gdbusauthmechanismsha1.c +++ b/gio/gdbusauthmechanismsha1.c @@ -1198,6 +1198,34 @@ mechanism_client_initiate (GDBusAuthMechanism *mechanism, return initial_response; } +/* Context names must be valid ASCII, nonzero length, and may not contain the + * characters slash ("/"), backslash ("\"), space (" "), newline ("\n"), + * carriage return ("\r"), tab ("\t"), or period ("."). + * + * See https://dbus.freedesktop.org/doc/dbus-specification.html#auth-mechanisms-sha */ +static gboolean +validate_cookie_context (const char *cookie_context) +{ + size_t i = 0; + + g_return_val_if_fail (cookie_context != NULL, FALSE); + + for (i = 0; cookie_context[i] != '\0'; i++) + { + if ((uint8_t) cookie_context[i] >= 128 || + cookie_context[i] == '/' || + cookie_context[i] == '\\' || + cookie_context[i] == ' ' || + cookie_context[i] == '\n' || + cookie_context[i] == '\r' || + cookie_context[i] == '\t' || + cookie_context[i] == '.') + return FALSE; + } + + return (i > 0); +} + static void mechanism_client_data_receive (GDBusAuthMechanism *mechanism, const gchar *data, @@ -1232,6 +1260,14 @@ mechanism_client_data_receive (GDBusAuthMechanism *mechanism, } cookie_context = tokens[0]; + if (!validate_cookie_context (tokens[0])) + { + g_free (m->priv->reject_reason); + m->priv->reject_reason = g_strdup_printf ("Malformed cookie_context '%s'", tokens[0]); + m->priv->state = G_DBUS_AUTH_MECHANISM_STATE_REJECTED; + goto out; + } + cookie_id = g_ascii_strtoll (tokens[1], &endp, 10); if (*endp != '\0') { From dd797f572cda38571aeda60334b365178f81b157 Mon Sep 17 00:00:00 2001 From: RHEL Packaging Agent Date: Mon, 20 Jul 2026 06:43:46 +0000 Subject: [PATCH 2/2] Fix: use guint8 instead of uint8_t for portability The upstream commit used uint8_t which requires , but the older GLib 2.80 codebase does not include that header in this file. Use GLib's own guint8 type instead, which is always available. --- gio/gdbusauthmechanismsha1.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c index 7f348d862..6e6b2b876 100644 --- a/gio/gdbusauthmechanismsha1.c +++ b/gio/gdbusauthmechanismsha1.c @@ -1212,7 +1212,7 @@ validate_cookie_context (const char *cookie_context) for (i = 0; cookie_context[i] != '\0'; i++) { - if ((uint8_t) cookie_context[i] >= 128 || + if ((guint8) cookie_context[i] >= 128 || cookie_context[i] == '/' || cookie_context[i] == '\\' || cookie_context[i] == ' ' ||