CVE-2025-0395: fix underallocation of abort_msg_s struct

Resolves: RHEL-75938
This commit is contained in:
Patsy Griffin 2025-01-31 16:31:03 -05:00
parent 835c6731c5
commit 38cc5f2c2b
2 changed files with 59 additions and 1 deletions

54
glibc-RHEL-75938.patch Normal file
View File

@ -0,0 +1,54 @@
commit 68ee0f704cb81e9ad0a78c644a83e1e9cd2ee578
Author: Siddhesh Poyarekar <siddhesh@sourceware.org>
Date: Tue Jan 21 16:11:06 2025 -0500
Fix underallocation of abort_msg_s struct (CVE-2025-0395)
Include the space needed to store the length of the message itself, in
addition to the message string. This resolves BZ #32582.
Signed-off-by: Siddhesh Poyarekar <siddhesh@sourceware.org>
Reviewed: Adhemerval Zanella <adhemerval.zanella@linaro.org>
diff -Nrup a/assert/assert.c b/assert/assert.c
--- a/assert/assert.c 2025-01-29 14:45:37.480532858 -0500
+++ b/assert/assert.c 2025-01-29 14:54:03.824306418 -0500
@@ -18,6 +18,7 @@
#include <assert.h>
#include <atomic.h>
#include <ldsodefs.h>
+#include <libc-pointer-arith.h>
#include <libintl.h>
#include <stdio.h>
#include <stdlib.h>
@@ -66,7 +67,8 @@ __assert_fail_base (const char *fmt, con
(void) __fxprintf (NULL, "%s", str);
(void) fflush (stderr);
- total = (total + 1 + GLRO(dl_pagesize) - 1) & ~(GLRO(dl_pagesize) - 1);
+ total = ALIGN_UP (total + sizeof (struct abort_msg_s) + 1,
+ GLRO(dl_pagesize));
struct abort_msg_s *buf = __mmap (NULL, total, PROT_READ | PROT_WRITE,
MAP_ANON | MAP_PRIVATE, -1, 0);
if (__glibc_likely (buf != MAP_FAILED))
diff -Nrup a/sysdeps/posix/libc_fatal.c b/sysdeps/posix/libc_fatal.c
--- a/sysdeps/posix/libc_fatal.c 2025-01-29 14:45:36.603528055 -0500
+++ b/sysdeps/posix/libc_fatal.c 2025-01-29 15:57:20.910535347 -0500
@@ -20,6 +20,7 @@
#include <errno.h>
#include <fcntl.h>
#include <ldsodefs.h>
+#include <libc-pointer-arith.h>
#include <paths.h>
#include <stdarg.h>
#include <stdbool.h>
@@ -123,7 +124,8 @@ __libc_message (const char *fmt, ...)
WRITEV_FOR_FATAL (fd, iov, nlist, total);
- total = (total + 1 + GLRO(dl_pagesize) - 1) & ~(GLRO(dl_pagesize) - 1);
+ total = ALIGN_UP (total + sizeof (struct abort_msg_s) + 1,
+ GLRO(dl_pagesize));
struct abort_msg_s *buf = __mmap (NULL, total,
PROT_READ | PROT_WRITE,
MAP_ANON | MAP_PRIVATE, -1, 0);

View File

@ -157,7 +157,7 @@ end \
Summary: The GNU libc libraries
Name: glibc
Version: %{glibcversion}
Release: 161%{?dist}
Release: 162%{?dist}
# In general, GPLv2+ is used by programs, LGPLv2+ is used for
# libraries.
@ -1093,6 +1093,7 @@ Patch785: glibc-RHEL-46761-4.patch
Patch786: glibc-RHEL-75810-2.patch
Patch787: glibc-RHEL-75810-3.patch
Patch788: glibc-RHEL-46761-5.patch
Patch789: glibc-RHEL-75938.patch
##############################################################################
# Continued list of core "glibc" package information:
@ -3086,6 +3087,9 @@ update_gconv_modules_cache ()
%endif
%changelog
* Wed Jan 29 2025 Patsy Griffin <patsy@redhat.com> - 2.34-162
- CVE-2025-0395: fix underallocation of abort_msg_s struct (RHEL-75938)
* Tue Jan 28 2025 Frédéric Bérat <fberat@redhat.com> - 2.34-161
- Backport: debug: Add regression tests for BZ 30932 (RHEL-46761)