From 92cda295403d9f4e03608bc6e828c68e9cb57911 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= Date: Mon, 11 Mar 2024 10:33:46 +0100 Subject: [PATCH] Ensure group access correction reaches also updated configs If the user has already modified configuration file unbound.conf, our change of defaults would not affect them. Let's move the change to extra file, which will be applied even when main config file were not modified. Correct new config snippet typo in CVE id ; Resolves: CVE-2024-1488 Resolves: RHEL-25500 --- remote-control.conf | 9 +++++++++ unbound.conf | 2 +- unbound.spec | 7 ++++++- 3 files changed, 16 insertions(+), 2 deletions(-) create mode 100644 remote-control.conf diff --git a/remote-control.conf b/remote-control.conf new file mode 100644 index 0000000..90072d3 --- /dev/null +++ b/remote-control.conf @@ -0,0 +1,9 @@ +# Remote control config section update. +# Previous defaults allowed any process to change settings, CVE-2024-1488 +remote-control: + # set to an absolute path to use a unix local name pipe, certificates + # are not used for that, so key and cert files need not be present. + control-interface: "/run/unbound/control" + + # For local sockets this option is ignored, and TLS is not used. + control-use-cert: "yes" diff --git a/unbound.conf b/unbound.conf index 0f83196..18fad43 100644 --- a/unbound.conf +++ b/unbound.conf @@ -998,7 +998,7 @@ remote-control: # are not used for that, so key and cert files need not be present. # control-interface: 127.0.0.1 # control-interface: ::1 - control-interface: "/run/unbound/control" + # moved to /etc/unbound/conf.d/remote-control.conf # port number for remote control operations. # control-port: 8953 diff --git a/unbound.spec b/unbound.spec index 1d13efd..600d25a 100644 --- a/unbound.spec +++ b/unbound.spec @@ -34,7 +34,7 @@ Summary: Validating, recursive, and caching DNS(SEC) resolver Name: unbound Version: 1.16.2 -Release: 5.3%{?extra_version:.%{extra_version}}%{?dist} +Release: 5.6%{?extra_version:.%{extra_version}}%{?dist} License: BSD Url: https://www.unbound.net/ Source: https://www.unbound.net/downloads/%{name}-%{version}%{?extra_version}.tar.gz @@ -55,6 +55,7 @@ Source15: unbound-anchor.timer Source16: unbound-munin.README Source17: unbound-anchor.service Source18: https://nlnetlabs.nl/downloads/%{name}/%{name}-%{version}%{?extra_version}.tar.gz.asc +Source21: remote-control.conf # Reverts ABI change done in version 1.8.0 (bz#2027735) # Makes possible backward binary compatibility with a new features @@ -286,6 +287,7 @@ mkdir -p %{buildroot}%{_sysconfdir}/unbound/{keys.d,conf.d,local.d} install -p %{SOURCE9} %{buildroot}%{_sysconfdir}/unbound/keys.d/ install -p %{SOURCE10} %{buildroot}%{_sysconfdir}/unbound/conf.d/ install -p %{SOURCE11} %{buildroot}%{_sysconfdir}/unbound/local.d/ +install -p -m 0644 %{SOURCE21} %{buildroot}%{_sysconfdir}/unbound/conf.d/ # Link unbound-control-setup.8 manpage to unbound-control.8 echo ".so man8/unbound-control.8" > %{buildroot}/%{_mandir}/man8/unbound-control-setup.8 @@ -433,6 +435,9 @@ popd %verify(not md5 size mtime) %{_sharedstatedir}/%{name}/root.key %changelog +* Mon Mar 11 2024 Petr Menšík - 1.16.2-5.6 +- Ensure group access correction reaches also updated configs (CVE-2024-1488) + * Wed Feb 28 2024 Petr Menšík - 1.16.2-5.3 - Ensure only unbound group can change configuration (CVE-2024-1488)