Compare commits

...

1 Commits
c10 ... c8s

Author SHA1 Message Date
RHEL Packaging Agent
8a5699ed82 Fix CVE-2026-72694: symlink-following chown of pid file in daemon mode
Backport upstream commit 30e19216bf to fix CVE-2026-72694
(CWE-59), a symlink-following chown vulnerability in MRTG's
PID file handling during daemon mode startup.

The fix ensures create_pid() refuses symlinks, creates the
PID file atomically with O_WRONLY|O_CREAT|O_EXCL, and uses
fchown on the open filehandle instead of path-based chown,
preventing a local attacker from redirecting ownership
changes to arbitrary files via a pre-placed symlink.

CVE: CVE-2026-72694
Upstream patches:
 - 30e19216bf.patch
Resolves: RHEL-236037

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-08-11 09:16:14 +00:00
2 changed files with 122 additions and 1 deletions

View File

@ -0,0 +1,113 @@
From d165b744f0ef0fa713e4b1cf4635422fffae9c73 Mon Sep 17 00:00:00 2001
From: Tobias Oetiker <tobi@oetiker.ch>
Date: Tue, 30 Jun 2026 23:34:40 +0200
Subject: [PATCH] Fix symlink-following chown of pid file in daemon mode
(CWE-59) (#123)
When mrtg is started as root in daemon mode (--daemon --user), it
created the pid file and chown'ed it to the target user *before*
dropping privileges. Both create_pid()'s `-e`/`open(">...")` and the
subsequent `chown` follow symlinks, so a local attacker who can
pre-place a symlink at the pid path (e.g. a pid file in a writable
directory) could make root chown an arbitrary existing file to the
daemon user, or create a root-owned file at an attacker-chosen path.
Rather than reorder the privilege drop (which would break the common
case of a root-owned pid directory, where the unprivileged daemon
cannot create the file itself), keep creating the file while
privileged but do it safely:
- create_pid() refuses symlinks and creates the file with
O_WRONLY|O_CREAT|O_EXCL, closing the symlink-follow / TOCTOU window.
- It chowns the open filehandle (fchown) instead of the path, so the
ownership change cannot be redirected through a swapped-in symlink.
The caller no longer does a separate path-based chown.
- demonize_me()'s later pid write refuses symlinks too.
Reported by Aisle Research via Vitezslav Crhonek.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
---
bin/mrtg | 8 +++++---
lib/mrtg2/MRTG_lib.pm | 32 ++++++++++++++++++++++++++------
2 files changed, 31 insertions(+), 9 deletions(-)
diff --git a/bin/mrtg b/bin/mrtg
index c332665..fc6cdcb 100755
--- a/bin/mrtg
+++ b/bin/mrtg
@@ -222,9 +222,11 @@ sub main {
# Run as a daemon, specified on command line (required for FHS compliant daemon)
if (defined $opts{"daemon"}) {
- # Create a pidfile, then chown it so we can use it once we change user
- &create_pid($pidfile);
- chown $uid, $gid, $pidfile;
+ # Create the pidfile securely and, while still privileged, hand it to
+ # the user we are about to become so the daemon can update it later.
+ # create_pid refuses symlinks and chowns the open handle (not the path),
+ # so a hostile pid path cannot be used to chown an arbitrary file.
+ &create_pid($pidfile, $uid, $gid);
}
($(,$)) = ($gid,$gid) ;
diff --git a/lib/mrtg2/MRTG_lib.pm b/lib/mrtg2/MRTG_lib.pm
index ff3d7e1..140f0b0 100644
--- a/lib/mrtg2/MRTG_lib.pm
+++ b/lib/mrtg2/MRTG_lib.pm
@@ -16,6 +16,7 @@ package MRTG_lib;
require 5.005;
use strict;
+use Fcntl qw(O_WRONLY O_CREAT O_EXCL);
use vars qw($OS $SL $PS @EXPORT @ISA $VERSION %timestrpospattern);
@@ -1208,14 +1209,31 @@ sub expistr ($) {
return "$wday, $mday $month ".($year+1900)." $hour:$min:$sec GMT";
}
-sub create_pid ($) {
- my $pidfile = shift;
+sub create_pid ($;$$) {
+ my ($pidfile, $uid, $gid) = @_;
return if ($OS eq 'NT' );
+
+ # Security: refuse to operate on a symlink. When mrtg is started as root
+ # in daemon mode with a writable pid path, an attacker who pre-places a
+ # symlink here could otherwise make us create or chown an arbitrary file
+ # (CWE-59). A plain stat/-e on the path would follow the link, so check
+ # the link itself first.
+ if (-l $pidfile) {
+ warn "refusing to use pid file $pidfile: it is a symbolic link\n";
+ return;
+ }
return if -e $pidfile;
- if ( open(PIDFILE,">$pidfile")) {
- close PIDFILE;
+
+ # O_CREAT|O_EXCL creates the file atomically and fails if anything
+ # (including a symlink that was raced in after the check above) already
+ # exists at the path, closing the symlink-follow / TOCTOU window.
+ if ( sysopen(my $fh, $pidfile, O_WRONLY|O_CREAT|O_EXCL, 0644) ) {
+ # chown the open handle (fchown) rather than the path, so the
+ # ownership change cannot be redirected through a swapped-in symlink.
+ chown $uid, $gid, $fh if defined $uid and defined $gid;
+ close $fh;
} else {
- warn "cannot write to $pidfile: $!\n";
+ warn "cannot create pid file $pidfile: $!\n";
}
}
@@ -1261,7 +1279,9 @@ sub demonize_me ($) {
} else {
if (defined $pidfile){
$main::Cleanfile3 = $pidfile;
- if (open(PIDFILE,">$pidfile")) {
+ if (-l $pidfile) {
+ warn "refusing to write pid file $pidfile: it is a symbolic link\n";
+ } elsif (open(PIDFILE,">$pidfile")) {
print PIDFILE "$$\n";
close PIDFILE;
} else {

View File

@ -6,7 +6,7 @@
Summary: Multi Router Traffic Grapher
Name: mrtg
Version: 2.17.7
Release: 1%{?dist}
Release: 1%{?dist}.1
URL: http://oss.oetiker.ch/mrtg/
Source0: http://oss.oetiker.ch/mrtg/pub/mrtg-%{version}.tar.gz
Source1: http://oss.oetiker.ch/mrtg/pub/mrtg-%{version}.tar.gz.md5
@ -28,6 +28,9 @@ Patch0: mrtg-2.15.0-lib64.patch
Patch1: mrtg-2.17.2-socket6-fix.patch
# Patch2: some devices return 2**32-2 on ifSpeed (e. g. IBM FibreChannel switches)
Patch2: mrtg-2.17.4-cfgmaker-ifhighspeed.patch
# https://issues.redhat.com/browse/RHEL-236037
# https://github.com/oetiker/mrtg/commit/30e19216bfadc0148f347cb0a42fd5e2016e6269
Patch3: mrtg-2.17.7-CVE-2026-72694.patch
License: GPLv2+
Group: Applications/Internet
Requires(post): systemd-units
@ -52,6 +55,7 @@ images which provide a LIVE visual representation of this traffic.
%patch0 -p1 -b .lib64
%patch1 -p1 -b .socket6
%patch2 -p1 -b .ifhighspeed
%patch3 -p1 -b .CVE-2026-72694
for i in doc/mrtg-forum.1 doc/mrtg-squid.1 CHANGES; do
iconv -f iso-8859-1 -t utf-8 < "$i" > "${i}_"
@ -138,6 +142,10 @@ fi
%{_unitdir}/mrtg.timer
%changelog
* Tue Aug 11 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 2.17.7-1.1
- Fix CVE-2026-72694: symlink-following chown in PID file handling
Resolves: RHEL-236037
* Mon Aug 13 2018 Vitezslav Crhonek <vcrhonek@redhat.com> - 2.17.7-1
- Use %%license
- Update to mrtg-2.17.7