From 39f5547924d6b098c9f1ca6bb52d3791b28bc274 Mon Sep 17 00:00:00 2001 From: RHEL Packaging Agent Date: Tue, 11 Aug 2026 09:41:17 +0000 Subject: [PATCH] Fix CVE-2026-72693: openvt -u process matching made more conservative Backport upstream commit 78d5ae119742e87baa7dbe0f5c4107e7533fd698 to fix CVE-2026-72693 in openvt's -u option. The patch makes process matching more conservative by using controlling terminal matching via /proc//stat instead of file descriptor stat checking, adds rejection of root as a pre-authenticated user, and documents the tighter -u behavior in the man page. CVE: CVE-2026-72693 Upstream patches: - https://github.com/legionus/kbd/commit/78d5ae119742e87baa7dbe0f5c4107e7533fd698.patch Resolves: RHEL-235979 This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent. Assisted-by: Ymir --- kbd-2.0.4-CVE-2026-72693.patch | 150 +++++++++++++++++++++++++++++++++ kbd.spec | 10 ++- 2 files changed, 159 insertions(+), 1 deletion(-) create mode 100644 kbd-2.0.4-CVE-2026-72693.patch diff --git a/kbd-2.0.4-CVE-2026-72693.patch b/kbd-2.0.4-CVE-2026-72693.patch new file mode 100644 index 0000000..ed39831 --- /dev/null +++ b/kbd-2.0.4-CVE-2026-72693.patch @@ -0,0 +1,150 @@ +From b62cff4ac4918e9a2c46755cdece125fd29f936c Mon Sep 17 00:00:00 2001 +From: Alexey Gladkov +Date: Tue, 12 May 2026 10:20:50 +0200 +Subject: [PATCH] openvt: make -u process matching more conservative + +The -u mode relies on the current VT owner to decide which user should +be used for the new login session. Make that check stricter by requiring +a matching process owner and controlling terminal instead of relying on +the ownership of an inherited file descriptor. + +Also reject root as a pre-authenticated target and document the tighter +behavior in the man page. + +Signed-off-by: Alexey Gladkov +--- + docs/man/man1/openvt.1 | 12 +++++++- + src/openvt.c | 64 +++++++++++++++++++++++++++++++++++++----- + 2 files changed, 68 insertions(+), 8 deletions(-) + +diff --git a/docs/man/man1/openvt.1 b/docs/man/man1/openvt.1 +index 4712547..9b7ecd3 100644 +--- a/docs/man/man1/openvt.1 ++++ b/docs/man/man1/openvt.1 +@@ -35,7 +35,9 @@ will be made the new current VT; + .TP + .I "\-u, \-\-user" + Figure out the owner of the current VT, and run login as that user. +-Suitable to be called by init. Shouldn't be used with \-c or \-l; ++Suitable to be called by init. Shouldn't be used with \-c or \-l. ++This option refuses to pre-authenticate root and requires a process owned by ++the VT owner whose controlling terminal is the current VT; + .TP + .I "\-l, \-\-login" + Make the command a login shell. A \- is prepended to the name of the command +@@ -64,6 +66,14 @@ If + is compiled with a getopt_long() and you wish to set + options to the command to be run, then you must supply + the end of options \-\- flag before the command. ++.PP ++The ++.B \-u ++option uses ++.BR "login -f" ++and therefore bypasses normal password authentication for the detected user. ++It is intended only for controlled init or keyboard-request configurations. ++Use a normal authenticated login command when authentication is required. + .BR + .SH EXAMPLES + .B openvt +diff --git a/src/openvt.c b/src/openvt.c +index 1dcf2f4..fbd85fe 100644 +--- a/src/openvt.c ++++ b/src/openvt.c +@@ -66,6 +66,51 @@ static void + exit(ret); + } + ++static int ++proc_pid_stat(const char *pid, uid_t *uid, dev_t *tty) ++{ ++ char filename[NAME_MAX + 12]; ++ char line[BUFSIZ]; ++ char *lp, *rp; ++ FILE *fp; ++ struct stat st; ++ long tty_nr; ++ ++ snprintf(filename, sizeof(filename), "/proc/%s/stat", pid); ++ fp = fopen(filename, "r"); ++ if (!fp) ++ return -1; ++ ++ if (fstat(fileno(fp), &st)) { ++ fclose(fp); ++ return -1; ++ } ++ ++ if (!fgets(line, sizeof(line), fp)) { ++ fclose(fp); ++ return -1; ++ } ++ fclose(fp); ++ ++ rp = strrchr(line, ')'); ++ if (!rp) ++ return -1; ++ ++ /* ++ * /proc//stat fields after comm are: ++ * state ppid pgrp session tty_nr ... ++ */ ++ if (!rp || sscanf(rp + 1, " %*c %*d %*d %*d %ld", &tty_nr) != 1) ++ return -1; ++ ++ if (tty_nr <= 0) ++ return -1; ++ ++ *uid = st.st_uid; ++ *tty = (dev_t) tty_nr; ++ return 0; ++} ++ + /* + * Support for Spawn_Console: openvt running from init + * added by Joshua Spoerri, Thu Jul 18 21:13:16 EDT 1996 +@@ -97,8 +142,7 @@ authenticate_user(int curvt) + DIR *dp; + struct dirent *dentp; + struct stat buf; +- dev_t console_dev; +- ino_t console_ino; ++ dev_t console_rdev; + uid_t console_uid; + char filename[NAME_MAX + 12]; + struct passwd *pwnam; +@@ -118,10 +162,12 @@ authenticate_user(int curvt) + kbd_error(EXIT_FAILURE, errsv, "%s", filename); + } + } +- console_dev = buf.st_dev; +- console_ino = buf.st_ino; ++ console_rdev = buf.st_rdev; + console_uid = buf.st_uid; + ++ if (console_uid == 0) ++ kbd_error(EXIT_FAILURE, 0, _("Refusing to pre-authenticate root on current tty.")); ++ + /* get the owner of current tty */ + if (!(pwnam = getpwuid(console_uid))) + kbd_error(EXIT_FAILURE, errno, "getpwuid"); +@@ -129,12 +175,16 @@ authenticate_user(int curvt) + /* check to make sure that user has a process on that tty */ + /* this will fail for example when X is running on the tty */ + while ((dentp = readdir(dp))) { +- sprintf(filename, "/proc/%s/fd/0", dentp->d_name); ++ uid_t proc_uid; ++ dev_t proc_tty; ++ ++ if (dentp->d_name[0] < '0' || dentp->d_name[0] > '9') ++ continue; + +- if (stat(filename, &buf)) ++ if (proc_pid_stat(dentp->d_name, &proc_uid, &proc_tty) < 0) + continue; + +- if (buf.st_dev == console_dev && buf.st_ino == console_ino && buf.st_uid == console_uid) ++ if (proc_uid == console_uid && proc_tty == console_rdev) + goto got_a_process; + } + diff --git a/kbd.spec b/kbd.spec index 20db2a8..6c611b8 100644 --- a/kbd.spec +++ b/kbd.spec @@ -1,6 +1,6 @@ Name: kbd Version: 2.0.4 -Release: 11%{?dist} +Release: 11%{?dist}.1 Summary: Tools for configuring the console (keyboard, virtual terminals, etc.) Group: System Environment/Base @@ -32,6 +32,9 @@ Patch6: kbd-2.0.2-unicode-start-font.patch Patch7: kbd-2.0.4-covscan-fixes.patch # Patch8: fixes vlock when console or terminal is closed abruptly, bz 2178798 Patch8: kbd-2.0.4-vlock-stdin-closed-inf-loop.patch +# CVE-2026-72693: openvt -u process matching more conservative +# https://github.com/legionus/kbd/commit/78d5ae119742e87baa7dbe0f5c4107e7533fd698 +Patch9: kbd-2.0.4-CVE-2026-72693.patch BuildRequires: bison, flex, gettext, pam-devel, check-devel BuildRequires: console-setup, xkeyboard-config @@ -76,6 +79,7 @@ cp -fp %{SOURCE6} . %patch6 -p1 -b .unicode-start-font %patch7 -p1 -b .covscan-fixes %patch8 -p1 -b .vlock-stdin-closed-inf-loop +%patch9 -p1 -b .CVE-2026-72693 # 7-bit maps are obsolete; so are non-euro maps pushd data/keymaps/i386 @@ -201,6 +205,10 @@ make check /lib/kbd/keymaps/legacy %changelog +* Tue Aug 11 2026 RHEL Packaging Agent - 2.0.4-11.1 +- Fix CVE-2026-72693: openvt -u process matching more conservative + Resolves: RHEL-235979 + * Tue Apr 18 2023 Vitezslav Crhonek - 2.0.4-11 - Fix vlock when console or terminal is closed abruptly Resolves: #2178798