Re: [SECURITY] Async-signal-unsafe operations in alrm_catcher() signal handler

Sam James <[email protected]>
Newsgroups gmane.comp.shells.bash.bugs
Organization Gentoo
Message-ID <[email protected]>
correspondence2--- via Bug reports for the GNU Bourne Again SHell <[email protected]> writes:

> Dear GNU Bash Maintainers,
>
> I am writing to report a security vulnerability in the GNU Bash shell.
>
> SUMMARY
> ========
> The alrm_catcher() function in eval.c (lines 154-161) is called from the
> SIGALRM signal handler context but performs operations that are not
> async-signal-safe according to POSIX standards.
>
> DETAILS
> =======
> The vulnerable code:
>
> static sighandler
> alrm_catcher(i)
>      int i;
> {
>   printf (_("\007timed out waiting for input: auto-logout\n"));
>   fflush (stdout);
>   bash_logout ();       /* run ~/.bash_logout if this is a login shell */
>   jump_to_top_level (EXITPROG);
>   SIGRETURN (0);
> }
>
> This calls:
> 1. printf() - Not async-signal-safe
> 2. fflush() - Not async-signal-safe
> 3. bash_logout() - Executes arbitrary user scripts (not async-safe)

How is that different from just letting the process exit otherwise?
~/.bash_logout will be used either way. If a process writes to arbitrary
bash init files, then all bets are off.

The signal handler should be made async-safe, but I don't think there's
any vulnerability here.

> 4. jump_to_top_level() - Longjmp in signal context
>
> IMPACT
> ======
> - Arbitrary code execution (via bash_logout)
> - Heap corruption (via printf)
> - Deadlocks (via fflush)
> - State corruption (via longjmp)
>
> CVSS Score: 7.8 (HIGH)
>
> Proof of Concept:
>
>    #!/bin/bash
>    # ================================================================
>    # MINIMAL POC: alrm_catcher Vulnerability
>    # ================================================================
>    # This is the smallest possible test to confirm the vulnerability.
>    # ================================================================
>    echo "[*] Creating malicious bash_logout..."
>    cat > ~/.bash_logout << 'EOF'
>    #!/bin/bash
>    echo "====== EXPLOIT EXECUTED FROM SIGNAL HANDLER ======"
>    echo "This proves arbitrary code execution!"
>    echo "Time: $(date)" > /tmp/poc_proof.txt
>    echo "User: $(whoami)" >> /tmp/poc_proof.txt
>    echo "PID: $$" >> /tmp/poc_proof.txt
>    EOF
>    chmod +x ~/.bash_logout
>    echo "[*] Triggering alarm..."
>    export SHLVL=2
>    export TMOUT=1
>    sleep 2
>    echo ""
>    echo "[*] Checking results..."
>    if [ -f /tmp/poc_proof.txt ]; then
>        echo "[+] SUCCESS! Vulnerability confirmed!"
>        echo "Proof contents:"
>        cat /tmp/poc_proof.txt
>    else
>        echo "[-] Exploit failed (not a login shell?)"
>    fi
>    echo "[*] Cleaning up..."
>    rm -f ~/.bash_logout
>    rm -f /tmp/poc_proof.txt
>    echo "[*] Done"
> MITIGATION
> ==========
> Replace alrm_catcher() with a flag-based approach:
>
> static volatile sig_atomic_t alarm_triggered = 0;
>
> static sighandler alrm_catcher_safe(i)
> {
>     alarm_triggered = 1;
> }
>
> // In main loop:
> if (alarm_triggered) {
>     alarm_triggered = 0;
>     printf(_("\007timed out waiting for input: auto-logout\n"));
>     fflush(stdout);
>     bash_logout();
>     jump_to_top_level(EXITPROG);
> }
>
> I am happy to assist with any additional information or testing.
> Please use this email to contact me back, I want a CVE.
>
> Sincerely,
> Ali
signature.asc (application/pgp-signature, 418 B)
-----BEGIN PGP SIGNATURE-----

iQEBBAEWCgCpFiEEJaa7iN2bdkxrVUHCc4QJ9SDfkZAFAmqQ5ssbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25z
Lm9wZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQyNUE2QkI4OEREOUI3NjRDNkI1NTQx
QzI3Mzg0MDlGNTIwREY5MTkwDxxzYW1AZ2VudG9vLm9yZwAKCRBzhAn1IN+RkAl6
AP0aJ1ELLOiLp5y/+XSkTfA386R7ak+0M/nngCykaOET2AEAjnMEok/LclN73TnH
4NBJlA+MuOT3M//MSaFUWgy+PQw=
=HCX8
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.