105 lines
3.7 KiB
Diff
105 lines
3.7 KiB
Diff
From 88277f4e2054966f093c29a167cc9d2ad767dd37 Mon Sep 17 00:00:00 2001
|
||
From: Philip Withnall <pwithnall@gnome.org>
|
||
Date: Tue, 28 Apr 2026 15:47:30 +0100
|
||
Subject: [PATCH 1/2] gdbusauthmechanismsha1: Validate cookie context
|
||
MIME-Version: 1.0
|
||
Content-Type: text/plain; charset=UTF-8
|
||
Content-Transfer-Encoding: 8bit
|
||
|
||
Without validation, the server could send a malicious context which
|
||
contains path traversal characters, allowing it to exfiltrate a SHA-1
|
||
hashed copy of arbitrary data from the client’s file system.
|
||
|
||
To exploit this successfully would require the client to choose to
|
||
connect peer-to-peer to a malicious D-Bus server and to choose the SHA-1
|
||
authentication mechanism in preference to all the other mechanisms. This
|
||
is vanishingly unlikely.
|
||
|
||
Signed-off-by: Philip Withnall <pwithnall@gnome.org>
|
||
|
||
Fixes: #3931
|
||
---
|
||
gio/gdbusauthmechanismsha1.c | 36 ++++++++++++++++++++++++++++++++++++
|
||
1 file changed, 36 insertions(+)
|
||
|
||
diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c
|
||
index c8aa08977..7f348d862 100644
|
||
--- a/gio/gdbusauthmechanismsha1.c
|
||
+++ b/gio/gdbusauthmechanismsha1.c
|
||
@@ -1198,6 +1198,34 @@ mechanism_client_initiate (GDBusAuthMechanism *mechanism,
|
||
return initial_response;
|
||
}
|
||
|
||
+/* Context names must be valid ASCII, nonzero length, and may not contain the
|
||
+ * characters slash ("/"), backslash ("\"), space (" "), newline ("\n"),
|
||
+ * carriage return ("\r"), tab ("\t"), or period (".").
|
||
+ *
|
||
+ * See https://dbus.freedesktop.org/doc/dbus-specification.html#auth-mechanisms-sha */
|
||
+static gboolean
|
||
+validate_cookie_context (const char *cookie_context)
|
||
+{
|
||
+ size_t i = 0;
|
||
+
|
||
+ g_return_val_if_fail (cookie_context != NULL, FALSE);
|
||
+
|
||
+ for (i = 0; cookie_context[i] != '\0'; i++)
|
||
+ {
|
||
+ if ((uint8_t) cookie_context[i] >= 128 ||
|
||
+ cookie_context[i] == '/' ||
|
||
+ cookie_context[i] == '\\' ||
|
||
+ cookie_context[i] == ' ' ||
|
||
+ cookie_context[i] == '\n' ||
|
||
+ cookie_context[i] == '\r' ||
|
||
+ cookie_context[i] == '\t' ||
|
||
+ cookie_context[i] == '.')
|
||
+ return FALSE;
|
||
+ }
|
||
+
|
||
+ return (i > 0);
|
||
+}
|
||
+
|
||
static void
|
||
mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
|
||
const gchar *data,
|
||
@@ -1232,6 +1260,14 @@ mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
|
||
}
|
||
|
||
cookie_context = tokens[0];
|
||
+ if (!validate_cookie_context (tokens[0]))
|
||
+ {
|
||
+ g_free (m->priv->reject_reason);
|
||
+ m->priv->reject_reason = g_strdup_printf ("Malformed cookie_context '%s'", tokens[0]);
|
||
+ m->priv->state = G_DBUS_AUTH_MECHANISM_STATE_REJECTED;
|
||
+ goto out;
|
||
+ }
|
||
+
|
||
cookie_id = g_ascii_strtoll (tokens[1], &endp, 10);
|
||
if (*endp != '\0')
|
||
{
|
||
|
||
From dd797f572cda38571aeda60334b365178f81b157 Mon Sep 17 00:00:00 2001
|
||
From: RHEL Packaging Agent <redhat-ymir-agent@redhat.com>
|
||
Date: Mon, 20 Jul 2026 06:43:46 +0000
|
||
Subject: [PATCH 2/2] Fix: use guint8 instead of uint8_t for portability
|
||
|
||
The upstream commit used uint8_t which requires <stdint.h>, but the
|
||
older GLib 2.80 codebase does not include that header in this file.
|
||
Use GLib's own guint8 type instead, which is always available.
|
||
---
|
||
gio/gdbusauthmechanismsha1.c | 2 +-
|
||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||
|
||
diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c
|
||
index 7f348d862..6e6b2b876 100644
|
||
--- a/gio/gdbusauthmechanismsha1.c
|
||
+++ b/gio/gdbusauthmechanismsha1.c
|
||
@@ -1212,7 +1212,7 @@ validate_cookie_context (const char *cookie_context)
|
||
|
||
for (i = 0; cookie_context[i] != '\0'; i++)
|
||
{
|
||
- if ((uint8_t) cookie_context[i] >= 128 ||
|
||
+ if ((guint8) cookie_context[i] >= 128 ||
|
||
cookie_context[i] == '/' ||
|
||
cookie_context[i] == '\\' ||
|
||
cookie_context[i] == ' ' ||
|