Re: [SECURITY] Async-signal-unsafe operations in alrm_catcher() signal handler
Sam James <[email protected]>
| Newsgroups | gmane.comp.shells.bash.bugs |
|---|---|
| Organization | Gentoo |
| Message-ID | <[email protected]> |
correspondence2--- via Bug reports for the GNU Bourne Again SHell <[email protected]> writes: > Dear GNU Bash Maintainers, > > I am writing to report a security vulnerability in the GNU Bash shell. > > SUMMARY > ======== > The alrm_catcher() function in eval.c (lines 154-161) is called from the > SIGALRM signal handler context but performs operations that are not > async-signal-safe according to POSIX standards. > > DETAILS > ======= > The vulnerable code: > > static sighandler > alrm_catcher(i) > int i; > { > printf (_("\007timed out waiting for input: auto-logout\n")); > fflush (stdout); > bash_logout (); /* run ~/.bash_logout if this is a login shell */ > jump_to_top_level (EXITPROG); > SIGRETURN (0); > } > > This calls: > 1. printf() - Not async-signal-safe > 2. fflush() - Not async-signal-safe > 3. bash_logout() - Executes arbitrary user scripts (not async-safe) How is that different from just letting the process exit otherwise? ~/.bash_logout will be used either way. If a process writes to arbitrary bash init files, then all bets are off. The signal handler should be made async-safe, but I don't think there's any vulnerability here. > 4. jump_to_top_level() - Longjmp in signal context > > IMPACT > ====== > - Arbitrary code execution (via bash_logout) > - Heap corruption (via printf) > - Deadlocks (via fflush) > - State corruption (via longjmp) > > CVSS Score: 7.8 (HIGH) > > Proof of Concept: > > #!/bin/bash > # ================================================================ > # MINIMAL POC: alrm_catcher Vulnerability > # ================================================================ > # This is the smallest possible test to confirm the vulnerability. > # ================================================================ > echo "[*] Creating malicious bash_logout..." > cat > ~/.bash_logout << 'EOF' > #!/bin/bash > echo "====== EXPLOIT EXECUTED FROM SIGNAL HANDLER ======" > echo "This proves arbitrary code execution!" > echo "Time: $(date)" > /tmp/poc_proof.txt > echo "User: $(whoami)" >> /tmp/poc_proof.txt > echo "PID: $$" >> /tmp/poc_proof.txt > EOF > chmod +x ~/.bash_logout > echo "[*] Triggering alarm..." > export SHLVL=2 > export TMOUT=1 > sleep 2 > echo "" > echo "[*] Checking results..." > if [ -f /tmp/poc_proof.txt ]; then > echo "[+] SUCCESS! Vulnerability confirmed!" > echo "Proof contents:" > cat /tmp/poc_proof.txt > else > echo "[-] Exploit failed (not a login shell?)" > fi > echo "[*] Cleaning up..." > rm -f ~/.bash_logout > rm -f /tmp/poc_proof.txt > echo "[*] Done" > MITIGATION > ========== > Replace alrm_catcher() with a flag-based approach: > > static volatile sig_atomic_t alarm_triggered = 0; > > static sighandler alrm_catcher_safe(i) > { > alarm_triggered = 1; > } > > // In main loop: > if (alarm_triggered) { > alarm_triggered = 0; > printf(_("\007timed out waiting for input: auto-logout\n")); > fflush(stdout); > bash_logout(); > jump_to_top_level(EXITPROG); > } > > I am happy to assist with any additional information or testing. > Please use this email to contact me back, I want a CVE. > > Sincerely, > Ali
signature.asc
(application/pgp-signature, 418 B)
-----BEGIN PGP SIGNATURE----- iQEBBAEWCgCpFiEEJaa7iN2bdkxrVUHCc4QJ9SDfkZAFAmqQ5ssbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMiwyXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25z Lm9wZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQyNUE2QkI4OEREOUI3NjRDNkI1NTQx QzI3Mzg0MDlGNTIwREY5MTkwDxxzYW1AZ2VudG9vLm9yZwAKCRBzhAn1IN+RkAl6 AP0aJ1ELLOiLp5y/+XSkTfA386R7ak+0M/nngCykaOET2AEAjnMEok/LclN73TnH 4NBJlA+MuOT3M//MSaFUWgy+PQw= =HCX8 -----END PGP SIGNATURE-----