Backport upstream commit 78d5ae119742e87baa7dbe0f5c4107e7533fd698
to fix CVE-2026-72693 in openvt's -u option. The patch makes
process matching more conservative by using controlling terminal
matching via /proc/<pid>/stat instead of file descriptor stat
checking, adds rejection of root as a pre-authenticated user,
and documents the tighter -u behavior in the man page.
CVE: CVE-2026-72693
Upstream patches:
- 78d5ae1197.patch
Resolves: RHEL-235979
This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.
Assisted-by: Ymir
151 lines
4.3 KiB
Diff
151 lines
4.3 KiB
Diff
From b62cff4ac4918e9a2c46755cdece125fd29f936c Mon Sep 17 00:00:00 2001
|
|
From: Alexey Gladkov <legion@kernel.org>
|
|
Date: Tue, 12 May 2026 10:20:50 +0200
|
|
Subject: [PATCH] openvt: make -u process matching more conservative
|
|
|
|
The -u mode relies on the current VT owner to decide which user should
|
|
be used for the new login session. Make that check stricter by requiring
|
|
a matching process owner and controlling terminal instead of relying on
|
|
the ownership of an inherited file descriptor.
|
|
|
|
Also reject root as a pre-authenticated target and document the tighter
|
|
behavior in the man page.
|
|
|
|
Signed-off-by: Alexey Gladkov <legion@kernel.org>
|
|
---
|
|
docs/man/man1/openvt.1 | 12 +++++++-
|
|
src/openvt.c | 64 +++++++++++++++++++++++++++++++++++++-----
|
|
2 files changed, 68 insertions(+), 8 deletions(-)
|
|
|
|
diff --git a/docs/man/man1/openvt.1 b/docs/man/man1/openvt.1
|
|
index 4712547..9b7ecd3 100644
|
|
--- a/docs/man/man1/openvt.1
|
|
+++ b/docs/man/man1/openvt.1
|
|
@@ -35,7 +35,9 @@ will be made the new current VT;
|
|
.TP
|
|
.I "\-u, \-\-user"
|
|
Figure out the owner of the current VT, and run login as that user.
|
|
-Suitable to be called by init. Shouldn't be used with \-c or \-l;
|
|
+Suitable to be called by init. Shouldn't be used with \-c or \-l.
|
|
+This option refuses to pre-authenticate root and requires a process owned by
|
|
+the VT owner whose controlling terminal is the current VT;
|
|
.TP
|
|
.I "\-l, \-\-login"
|
|
Make the command a login shell. A \- is prepended to the name of the command
|
|
@@ -64,6 +66,14 @@ If
|
|
is compiled with a getopt_long() and you wish to set
|
|
options to the command to be run, then you must supply
|
|
the end of options \-\- flag before the command.
|
|
+.PP
|
|
+The
|
|
+.B \-u
|
|
+option uses
|
|
+.BR "login -f"
|
|
+and therefore bypasses normal password authentication for the detected user.
|
|
+It is intended only for controlled init or keyboard-request configurations.
|
|
+Use a normal authenticated login command when authentication is required.
|
|
.BR
|
|
.SH EXAMPLES
|
|
.B openvt
|
|
diff --git a/src/openvt.c b/src/openvt.c
|
|
index 1dcf2f4..fbd85fe 100644
|
|
--- a/src/openvt.c
|
|
+++ b/src/openvt.c
|
|
@@ -66,6 +66,51 @@ static void
|
|
exit(ret);
|
|
}
|
|
|
|
+static int
|
|
+proc_pid_stat(const char *pid, uid_t *uid, dev_t *tty)
|
|
+{
|
|
+ char filename[NAME_MAX + 12];
|
|
+ char line[BUFSIZ];
|
|
+ char *lp, *rp;
|
|
+ FILE *fp;
|
|
+ struct stat st;
|
|
+ long tty_nr;
|
|
+
|
|
+ snprintf(filename, sizeof(filename), "/proc/%s/stat", pid);
|
|
+ fp = fopen(filename, "r");
|
|
+ if (!fp)
|
|
+ return -1;
|
|
+
|
|
+ if (fstat(fileno(fp), &st)) {
|
|
+ fclose(fp);
|
|
+ return -1;
|
|
+ }
|
|
+
|
|
+ if (!fgets(line, sizeof(line), fp)) {
|
|
+ fclose(fp);
|
|
+ return -1;
|
|
+ }
|
|
+ fclose(fp);
|
|
+
|
|
+ rp = strrchr(line, ')');
|
|
+ if (!rp)
|
|
+ return -1;
|
|
+
|
|
+ /*
|
|
+ * /proc/<pid>/stat fields after comm are:
|
|
+ * state ppid pgrp session tty_nr ...
|
|
+ */
|
|
+ if (!rp || sscanf(rp + 1, " %*c %*d %*d %*d %ld", &tty_nr) != 1)
|
|
+ return -1;
|
|
+
|
|
+ if (tty_nr <= 0)
|
|
+ return -1;
|
|
+
|
|
+ *uid = st.st_uid;
|
|
+ *tty = (dev_t) tty_nr;
|
|
+ return 0;
|
|
+}
|
|
+
|
|
/*
|
|
* Support for Spawn_Console: openvt running from init
|
|
* added by Joshua Spoerri, Thu Jul 18 21:13:16 EDT 1996
|
|
@@ -97,8 +142,7 @@ authenticate_user(int curvt)
|
|
DIR *dp;
|
|
struct dirent *dentp;
|
|
struct stat buf;
|
|
- dev_t console_dev;
|
|
- ino_t console_ino;
|
|
+ dev_t console_rdev;
|
|
uid_t console_uid;
|
|
char filename[NAME_MAX + 12];
|
|
struct passwd *pwnam;
|
|
@@ -118,10 +162,12 @@ authenticate_user(int curvt)
|
|
kbd_error(EXIT_FAILURE, errsv, "%s", filename);
|
|
}
|
|
}
|
|
- console_dev = buf.st_dev;
|
|
- console_ino = buf.st_ino;
|
|
+ console_rdev = buf.st_rdev;
|
|
console_uid = buf.st_uid;
|
|
|
|
+ if (console_uid == 0)
|
|
+ kbd_error(EXIT_FAILURE, 0, _("Refusing to pre-authenticate root on current tty."));
|
|
+
|
|
/* get the owner of current tty */
|
|
if (!(pwnam = getpwuid(console_uid)))
|
|
kbd_error(EXIT_FAILURE, errno, "getpwuid");
|
|
@@ -129,12 +175,16 @@ authenticate_user(int curvt)
|
|
/* check to make sure that user has a process on that tty */
|
|
/* this will fail for example when X is running on the tty */
|
|
while ((dentp = readdir(dp))) {
|
|
- sprintf(filename, "/proc/%s/fd/0", dentp->d_name);
|
|
+ uid_t proc_uid;
|
|
+ dev_t proc_tty;
|
|
+
|
|
+ if (dentp->d_name[0] < '0' || dentp->d_name[0] > '9')
|
|
+ continue;
|
|
|
|
- if (stat(filename, &buf))
|
|
+ if (proc_pid_stat(dentp->d_name, &proc_uid, &proc_tty) < 0)
|
|
continue;
|
|
|
|
- if (buf.st_dev == console_dev && buf.st_ino == console_ino && buf.st_uid == console_uid)
|
|
+ if (proc_uid == console_uid && proc_tty == console_rdev)
|
|
goto got_a_process;
|
|
}
|
|
|