Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #65355

Bug#940848: nfs-utils:CVE-2019-3689: root-owned files stored in insecure /var/lib/nfs

Path csiph.com!news.mixmin.net!aioe.org!bofh.it!news.nic.it!robomod
From Sylvain Beucler <beuc@beuc.net>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#940848: nfs-utils:CVE-2019-3689: root-owned files stored in insecure /var/lib/nfs
Date Wed, 09 Oct 2019 16:40:03 +0200
Message-ID <yPlib-855-31@gated-at.bofh.it> (permalink)
References <yIxo5-7BN-1@gated-at.bofh.it> <yLYrM-2b4-7@gated-at.bofh.it> <yIxo5-7BN-1@gated-at.bofh.it> <yLYrM-2b4-7@gated-at.bofh.it>
X-Original-To 940848@bugs.debian.org
X-Mailbox-Line From debian-bugs-dist-request@lists.debian.org Wed Oct 9 14:36:09 2019
Old-Return-Path <debbugs@buxtehude.debian.org>
X-Spam-Flag NO
X-Spam-Score -3.951
Reply-To Sylvain Beucler <beuc@beuc.net>, 940848@bugs.debian.org
Resent-To debian-bugs-dist@lists.debian.org
Resent-Cc Debian kernel team <debian-kernel@lists.debian.org>
X-Debian-Pr-Message followup 940848
X-Debian-Pr-Package src:nfs-utils
X-Debian-Pr-Keywords security upstream
X-Debian-Pr-Source nfs-utils
X-Spam-Bayes score:0.0000 Tokens: new, 23; hammy, 150; neutral, 131; spammy, 0. spammytokens: hammytokens:0.000-+--HOpenpgp:signencrypt, 0.000-+--HOpenpgp:preference, 0.000-+--HAutocrypt:keydata, 0.000-+--HAutocrypt:addr, 0.000-+--H*u:60.0
Openpgp preference=signencrypt
Autocrypt addr=beuc@beuc.net; prefer-encrypt=mutual; keydata= mQENBFIV4mMBCAC2rlmQ5UKtQB3WQq4Z8YIzttPQXBJIT1Zlg825nSIClNRx/ZfGiZysIyHY aqde79+DbZoLmNBReGP8ZEJMOdlmgmT895HDt6KsODznrOw7iyjOGHodRBy3jQwAHrYWQWAl a6rTcDZHBc9HdOZkKi76+vL3PC6prU6P8Bel+IF6okk9FqMfu/4RXCCupzvhubK578i7ZSsf h6F7mIM78LSkjQNQsQEXK6aXgQUF+kJATGHPOY9cPfDJbClgHVUJivy7y3i6Rs/6XLy8QQVj /J+9DUYw5cXAcAK0IMAO6U6wNyKDqhSUCc8n2NWBr5HSh7HxeGwydVkETgIz1H1CRBh7ABEB AAG0H1N5bHZhaW4gQmV1Y2xlciA8YmV1Y0BiZXVjLm5ldD6JAVUEEwECAD8CGwMGCwkIBwMC BhUIAgkKCwQWAgMBAh4BAheAFiEEQic8GuN/xDR88HkSj/HLbo2JBZ8FAlqhjfoFCQxOEpcA CgkQj/HLbo2JBZ/TiQf9FXHeRlbsh+H34ky2Kg4UH7nM/jBlfEyhor4r26KaDz5NrtxfsaMH N2NxRMPJwHeI/yAKJEI6Ipb8ebIo4ZWCiC3g+wI2eWp757VGvZ3uUQ1Tgty4cWAbftrtdIZb YpvW9owfcz+U/7SH7M6U2TT/jHIzlyqP4pyUqUSfTzrwSVJCXLmoT2sC0yTFFndWYtrZIQJS SCOk4FWtAtiOSzQouaf2LJuvv5WXQDRXt2OsOWal6sVDTcb3sHcmwUCErQ3BATCvmxWiDzIz j+jB5faLK0IAZn+ZN/JW/ocG+aHDMddTWMkpMpk5kCqFOl2PxeFDdqjlLpXss1aDrsHQ3KpO trkBDQRSFeJjAQgAtVe8zYdpeh1q+6XR+pa06OOKgaNHE8a251Nw0klF5WxNEL2IHJ/be6zp 0oIaZXet4woL5x2gpsGBIJPyQ4GwA3f696kEcEZcz3EVzwhrtrJXpxfTyUkLU2A6om0xFPU8 KQQzDqB0A1pyMUqv+qSA/c2t3UppYHzWZOowUO58so7V2eOT4qU8w83SyGeIG5m+p4vEycsY 5dBB7n7Ot7rcbohvTTgwMiBqNek7Gf1PfsODB6dDDjwHhcRUPXA8v4TGJXEZCWvh8u40hs/r sunJMmRdxMolhdwDeF/7McmhFZ/VcY8o6QQIVshTfkvnO/3HpzhGOMcgdLFSeyAS+w4vtQAR AQABiQE8BBgBAgAmAhsMFiEEQic8GuN/xDR88HkSj/HLbo2JBZ8FAlqhjL0FCQxOEVoACgkQ j/HLbo2JBZ/MCggAk4x5HiiOtFc1rzo53ovkWScrrr8RZT6x9f00j+4Vtbwt5gei2lF3+SQU Ziki0xVC5w4eJYsUdNnVK8zL/5hE+BrPXZ0ioKxtkRPTHj33epk05C/L3rr0EEqHA0T5iOT+ dnF1Q1Ax3ShUdmAWAjVBa9DBWGkjEtgXabc/1hS34qRyM9uhpiVsgVnYn6+1f0OsKzklQs9O FK14P8QDv6yND6wPzfbA8kuUtaBORnHW64b5RWeJGCWz0lqzFu6DqiMtppDsLnMC3ihwbcq5 hDCmIp8+x/fifD2mBibYNNba4DKrUur+/HxpUskr2BqHInmY8vnn3ZbmuUd6TK51Vrhpcw==
User-Agent Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version 1.0
Content-Type text/plain; charset=utf-8
Content-Transfer-Encoding 8bit
Content-Language en-US
X-Debian-Message from BTS
X-Mailing-List <debian-bugs-dist@lists.debian.org> archive/latest/1562996
List-ID <debian-bugs-dist.lists.debian.org>
List-URL <https://lists.debian.org/debian-bugs-dist/>
Approved robomod@news.nic.it
Lines 44
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Wed, 9 Oct 2019 16:32:14 +0200
X-Original-Message-ID <d3d64908-3a4b-36bc-f7e5-17bb3947c952@beuc.net>
X-Original-References <156900987685.28528.4626244954931953936.reportbug@eldamar.local> <ed3ae0fe-0d48-e52e-c5fb-7558de3d5214@beuc.net> <156900987685.28528.4626244954931953936.reportbug@eldamar.local> <ed3ae0fe-0d48-e52e-c5fb-7558de3d5214@beuc.net>
Xref csiph.com linux.debian.bugs.dist:978552 linux.debian.kernel:65355

Cross-posted to 2 groups.

Show key headers only | View raw


Hi,

I submitted the following patch to address this issue:
https://salsa.debian.org/debian/nfs-utils/merge_requests/3/diffs

The source part of the fix was also submitted at:
https://bugzilla.linux-nfs.org/show_bug.cgi?id=338

I intend to push it to LTS/ELTS, I can also prepare an upload for
stable/oldstable if security-team wishes so.
What do you think?

To test:

pp/post_install_checknfs.sh:

#!/bin/sh -ex
if [ -e /var/lib/nfs ]; then
    ls -ld /var/lib/nfs
    if [ "$(dpkg -l | grep ' nfs-common ' | awk '{print $3}')" !=
'1:1.3.4-2.6' ]; then
        exit 0
    fi
    if [ "$(stat -c '%U:%G' /var/lib/nfs)" != 'root:root' ]; then
        exit 1
    fi
fi

sudo piuparts -d bullseye nfs-utils_1.3.4-2.6_amd64.changes
--scriptsdir=$(pwd)/pp
sudo piuparts -d bullseye nfs-utils_1.3.4-2.6_amd64.changes
--scriptsdir=$(pwd)/pp --install-remove-install


Mount NFS with v3 mode to force statd:
$ sudo service rpcinfo stop
$ sudo service rpcinfo start
$ sudo mount -t nfs -o vers=3 127.0.0.1:/media/nfs /mnt/t
$ ps aux | grep statd
Ensure rpc.statd runs as 'statd' (not 'root').

Cheers!
Sylvain Beucler
Debian LTS Team

Back to linux.debian.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#940848: nfs-utils:CVE-2019-3689: root-owned files stored in insecure /var/lib/nfs Salvatore Bonaccorso <carnil@debian.org> - 2019-09-20 22:10 +0200
  Bug#940848: nfs-utils:CVE-2019-3689: root-owned files stored in insecure /var/lib/nfs Sylvain Beucler <beuc@beuc.net> - 2019-09-30 09:40 +0200
    Bug#940848: nfs-utils:CVE-2019-3689: root-owned files stored in insecure /var/lib/nfs Sylvain Beucler <beuc@beuc.net> - 2019-10-09 16:40 +0200
      Bug#940848: nfs-utils:CVE-2019-3689: root-owned files stored in insecure /var/lib/nfs Sylvain Beucler <beuc@beuc.net> - 2019-10-14 10:10 +0200
  Bug#940848: nfs-utils:CVE-2019-3689: root-owned files stored in insecure /var/lib/nfs Salvatore Bonaccorso <carnil@debian.org> - 2020-03-10 11:10 +0100
  Bug#940848: marked as done (nfs-utils: CVE-2019-3689: root-owned  files stored in insecure /var/lib/nfs) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2020-03-13 15:00 +0100
  Bug#940848: marked as done (nfs-utils: CVE-2019-3689: root-owned  files stored in insecure /var/lib/nfs) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2020-07-03 21:10 +0200
  Bug#940848: marked as done (nfs-utils: CVE-2019-3689: root-owned  files stored in insecure /var/lib/nfs) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2020-07-09 21:40 +0200

csiph-web