Summary: | <net-misc/openssh-8.6_p1: theoretical sandbox escape in rare logging configuration | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | CC: | base-system |
Priority: | Normal | Keywords: | PullRequest |
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
See Also: | https://github.com/gentoo/gentoo/pull/23403 | ||
Whiteboard: | B? [noglsa] | ||
Package list: |
net-misc/openssh-8.6_p1-r2
|
Runtime testing required: | --- |
Description
Sam James
2021-04-22 03:19:25 UTC
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=dd069ebac8b0f15edc1dee19bb77f9611b5a812a commit dd069ebac8b0f15edc1dee19bb77f9611b5a812a Author: Patrick McLean <chutzpah@gentoo.org> AuthorDate: 2021-04-23 23:14:10 +0000 Commit: Patrick McLean <chutzpah@gentoo.org> CommitDate: 2021-04-23 23:14:16 +0000 net-misc/openssh-8.6_p1: revbump, add X509 patch Bug: https://bugs.gentoo.org/785034 Bug: https://bugs.gentoo.org/784896 Package-Manager: Portage-3.0.18, Repoman-3.0.3 Signed-off-by: Patrick McLean <chutzpah@gentoo.org> net-misc/openssh/Manifest | 1 + .../files/openssh-8.6_p1-X509-glue-13.1.patch | 72 +++++ .../files/openssh-8.6_p1-hpn-15.2-X509-glue.patch | 357 +++++++++++++++++++++ ...nssh-8.6_p1.ebuild => openssh-8.6_p1-r1.ebuild} | 4 +- 4 files changed, 432 insertions(+), 2 deletions(-) No CVE. Gentoo became "affected" when 8.5 was stabilized via bug 774090. Upstream fix is https://github.com/openssh/openssh-portable/commit/faf2b86a46c9281d237bcdec18c99e94a4eb820a. However, there is no known way to trigger this. Even when all pre requirements are met (running with LogVerbose) you still need to find a way to exploit the low-privilege process which would be an own vulnerability. We will stabilize 8.6 due to this but no GLSA until CVE/situation will change. x86 done arm64 done amd64 done arm done sparc done ppc done ppc64 done hppa done Please cleanup. Unable to check for sanity:
> no match for package: net-misc/openssh-8.6_p1-r1
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=307230a6d1ac9ebf6a354de7f4ed60a4879e2fdc commit 307230a6d1ac9ebf6a354de7f4ed60a4879e2fdc Author: John Helmert III <ajak@gentoo.org> AuthorDate: 2021-12-18 05:11:36 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2021-12-19 01:10:04 +0000 net-misc/openssh: drop 8.5_p1-r2 Bug: https://bugs.gentoo.org/784896 Acked-By: Sam James <sam@gentoo.org> Signed-off-by: John Helmert III <ajak@gentoo.org> net-misc/openssh/Manifest | 3 - net-misc/openssh/openssh-8.5_p1-r2.ebuild | 510 ------------------------------ 2 files changed, 513 deletions(-) Cleaned up. No GLSA, so all done! |