CVE-2015-0245: denial of service in dbus >= 1.4 systemd activation
Simon McVittie <simon.mcvittie-ZGY8ohtN/[email protected]>
| Newsgroups | gmane.comp.freedesktop.dbus,gmane.comp.security.oss.general |
|---|---|
| Organization | Collabora Ltd. |
| Message-ID | <[email protected]> |
Bug tracked as: CVE-2015-0245
Bug tracked as: https://bugs.freedesktop.org/show_bug.cgi?id=88811
Versions affected: dbus >= 1.4.0
Versions fixed: >= 1.9.10, 1.8.x >= 1.8.16, 1.6.x >= 1.6.30
Type of vulnerability: CWE-285 Improper Authorization
Exploitable by: local users
Impact: denial of service
Reporter: Simon McVittie, Collabora Ltd.
D-Bus <http://www.freedesktop.org/wiki/Software/dbus/> is an
asynchronous inter-process communication system, commonly used
for system services or within a desktop session on Linux and other
operating systems.
dbus-daemon can "activate" (auto-start) D-Bus services on-demand when it
receives a message addressed to them. In versions >= 1.4.0 of dbus, it
can do this by using a D-Bus signal to ask systemd to carry out the
actual service start.
systemd sends back an ActivationFailure D-Bus signal if the activation
fails. However, when it receives these signals, dbus-daemon does not
verify that the signal actually came from systemd. A malicious local
user could send repeated ActivationFailure signals in the hope that it
would "win the race" with the genuine signal, causing D-Bus to send back
an error to the client that requested activation.
Mitigation: the system service is not actually prevented from starting
or claiming its well-known bus name, and after it has done so,
subsequent clients can communicate with it as usual.
The recommended fix for stable distributions is to alter system.conf
similar to the attached patch (commit link below), or upgrade to version
1.8.16 or 1.6.30. This restricts the attack to uid 0, making it a
non-issue in practice.
http://cgit.freedesktop.org/dbus/dbus/commit/?id=6dbd09fedc396c53b25ea73c6c8a278beca349c7
The full solution involves additional code changes and has only been
made in the 1.9 development branch so far, but is easy to backport to
1.8 if required (e.g. for environments where uid 0 is not all-powerful
due to use of LSMs). It requires two additional commits:
http://cgit.freedesktop.org/dbus/dbus/commit/?id=aaea59916398d1c590490edb0471a01bcf20e6d7
http://cgit.freedesktop.org/dbus/dbus/commit/?id=03c5e161752fe1ff4925955800ca9c78d09a6e0c
Regards,
S
--
Simon McVittie, Collabora Ltd.
on behalf of the D-Bus maintainers
_______________________________________________
dbus mailing list
[email protected]
http://lists.freedesktop.org/mailman/listinfo/dbus
0001-CVE-2015-0245-prevent-forged-ActivationFailure-from-.patch
(text/x-patch, 1.5 KB)
From b07a95b457a5e72bae525c4f3e707544cd8a99b3 Mon Sep 17 00:00:00 2001 From: Simon McVittie <simon.mcvittie-ZGY8ohtN/[email protected]> Date: Mon, 26 Jan 2015 20:09:56 +0000 Subject: [PATCH] CVE-2015-0245: prevent forged ActivationFailure from non-root processes Without either this rule or better checking in dbus-daemon, non-systemd processes can make dbus-daemon think systemd failed to activate a system service, resulting in an error reply back to the requester. This is redundant with the fix in the C code (which I consider to be the real solution), but is likely to be easier to backport. Bug: https://bugs.freedesktop.org/show_bug.cgi?id=88811 Reviewed-by: Alban Crequy Reviewed-by: David King Reviewed-by: Philip Withnall --- bus/system.conf.in | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/bus/system.conf.in b/bus/system.conf.in index 92f4cc4..851b9e6 100644 --- a/bus/system.conf.in +++ b/bus/system.conf.in @@ -68,6 +68,14 @@ <deny send_destination="org.freedesktop.DBus" send_interface="org.freedesktop.DBus" send_member="UpdateActivationEnvironment"/> + <deny send_destination="org.freedesktop.DBus" + send_interface="org.freedesktop.systemd1.Activator"/> + </policy> + + <!-- Only systemd, which runs as root, may report activation failures. --> + <policy user="root"> + <allow send_destination="org.freedesktop.DBus" + send_interface="org.freedesktop.systemd1.Activator"/> </policy> <!-- Config files are placed here that among other things, punch -- 2.1.4
signature.asc
(application/pgp-signature, 793 B)
-----BEGIN PGP SIGNATURE----- iQIVAwUBVNjQo03o/ypjx8yQAQgmIQ/7BWezPxEAmrjF75WDqPf6bf8ek8FEMbAL mzmyEbaipNASAOgbbBfBeN8Xk5WU23VzkpzGEuuhgXnLkXbN1n1EG0ijFselOagt HZJh20YYerPpU6dgrLdEQtykiHfXYlcIN0JgTY6O6WNhdW/Muty3fRj5NnOxFIxu dw7KszVUx40h+7KyZkAP4exYnym10PWM7FmQOByvu4ObN4JjfNf1LwdvqL5UiQ/X jwt1l7ypOteHaWQDRAFh2S6PUTxXace6uLPEn+2ZwR6DpFb6mo/UsAkqkmFh0aQR TvPX4oq0c11+zDMbL/G19aaPLgST9NmaDa7gE7zZc/XKR6hvqzxXxIra/1r0gW+g Y2m+ZRRWtyMV2yUJFABFTYkNTZpMwyuZknBCUwUWrJqqB3IFxLZDn3h1PMyK/NDN Dxe6V9zNk2osgOEexzKWR5zbn1xwuGysITl4YPKyNFC9aYtfedLQuXx2r6qzWN/E 3/C2Tvy90FeyRvZcInI/Nfj9T8sF6RSfW1xyAxuxoGgL4baCywj9wnGw0p1ajmKU k4He6WT5gl12uWS4tTiB2mM1wbRQ9mPjfL/7S01YFAzyy0jK2stWKKPZDYOqLxTb jul44PStDN+yfyhNm0GO6KxRy4OOwv8TmdNgzGt+avSboN2/ZJJRNSXngInQone3 Kw1um4U+tEM= =YUDV -----END PGP SIGNATURE-----