From 3164e5a1c5f85f43e0b552900002c0bd8f2d313d Mon Sep 17 00:00:00 2001 From: Peter Robinson Date: Wed, 19 Jan 2022 15:25:33 +0000 Subject: [PATCH] add patches for compat build --- ...mctl-fix-memory-leak-in-get_password.patch | 38 ++++++++++++ ...e-SHA-256-the-default-hash-algorithm.patch | 61 +++++++++++++++++++ 2 files changed, 99 insertions(+) create mode 100644 0001-evmctl-fix-memory-leak-in-get_password.patch create mode 100644 0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch diff --git a/0001-evmctl-fix-memory-leak-in-get_password.patch b/0001-evmctl-fix-memory-leak-in-get_password.patch new file mode 100644 index 0000000..e6657d1 --- /dev/null +++ b/0001-evmctl-fix-memory-leak-in-get_password.patch @@ -0,0 +1,38 @@ +From 2f1740eab432abc8e85172531d97eba33342474c Mon Sep 17 00:00:00 2001 +From: Bruno Meneguele +Date: Mon, 16 Aug 2021 12:11:15 -0300 +Subject: [PATCH] evmctl: fix memory leak in get_password + +The variable "password" is not freed nor returned in case get_password() +succeeds. Return it instead of the intermediary variable "pwd". Issue found +by Coverity scan tool. + +src/evmctl.c:2565: leaked_storage: Variable "password" going out of scope + leaks the storage it points to. + +Signed-off-by: Bruno Meneguele +--- + src/evmctl.c | 7 ++++++- + 1 file changed, 6 insertions(+), 1 deletion(-) + +diff --git a/src/evmctl.c b/src/evmctl.c +index a8065bbe124a..ab7173723095 100644 +--- a/src/evmctl.c ++++ b/src/evmctl.c +@@ -2625,7 +2625,12 @@ static char *get_password(void) + return NULL; + } + +- return pwd; ++ if (pwd == NULL) { ++ free(password); ++ return NULL; ++ } ++ ++ return password; + } + + int main(int argc, char *argv[]) +-- +2.31.1 + diff --git a/0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch b/0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch new file mode 100644 index 0000000..e6dc92d --- /dev/null +++ b/0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch @@ -0,0 +1,61 @@ +From 916a0f97fd244a48fde429a63ddc04ed1ed94f8b Mon Sep 17 00:00:00 2001 +From: Bruno Meneguele +Date: Mon, 16 Aug 2021 17:58:35 -0300 +Subject: [PATCH] libimaevm: make SHA-256 the default hash algorithm + +The SHA-1 algorithm is considered a weak hash algorithm and there has been +some movement within certain distros to drop its support completely or at +least drop it from the default behavior. ima-evm-utils uses it as the +default algorithm in case the user doesn't explicitly ask for another +through the --hashalgo/-a option. With that, make SHA-256 the default hash +algorithm instead. + +Signed-off-by: Bruno Meneguele +--- + README | 2 +- + src/evmctl.c | 2 +- + src/libimaevm.c | 2 +- + 3 files changed, 3 insertions(+), 3 deletions(-) + +diff --git a/README b/README +index 87cd3b5cd7da..0dc02f551673 100644 +--- a/README ++++ b/README +@@ -41,7 +41,7 @@ COMMANDS + OPTIONS + ------- + +- -a, --hashalgo sha1 (default), sha224, sha256, sha384, sha512 ++ -a, --hashalgo sha1, sha224, sha256 (default), sha384, sha512 + -s, --imasig make IMA signature + -d, --imahash make IMA hash + -f, --sigfile store IMA signature in .sig file instead of xattr +diff --git a/src/evmctl.c b/src/evmctl.c +index a8065bbe124a..e0e55bc0b122 100644 +--- a/src/evmctl.c ++++ b/src/evmctl.c +@@ -2496,7 +2496,7 @@ static void usage(void) + + printf( + "\n" +- " -a, --hashalgo sha1 (default), sha224, sha256, sha384, sha512, streebog256, streebog512\n" ++ " -a, --hashalgo sha1, sha224, sha256 (default), sha384, sha512, streebog256, streebog512\n" + " -s, --imasig make IMA signature\n" + " -d, --imahash make IMA hash\n" + " -f, --sigfile store IMA signature in .sig file instead of xattr\n" +diff --git a/src/libimaevm.c b/src/libimaevm.c +index 8e9615796153..f6c72b878d88 100644 +--- a/src/libimaevm.c ++++ b/src/libimaevm.c +@@ -88,7 +88,7 @@ static const char *const pkey_hash_algo_kern[PKEY_HASH__LAST] = { + struct libimaevm_params imaevm_params = { + .verbose = LOG_INFO, + .x509 = 1, +- .hash_algo = "sha1", ++ .hash_algo = "sha256", + }; + + static void __attribute__ ((constructor)) libinit(void); +-- +2.31.1 +