Bug#1144392: kdb: CVE-2026-72693
Moritz Mühlenhoff <[email protected]>
| Newsgroups | gmane.linux.debian.devel.bugs.rc |
|---|---|
| Message-ID | <[email protected]> |
Source: kdb X-Debbugs-CC: [email protected] Severity: grave Tags: security Hi, The following vulnerability was published for kdb. CVE-2026-72693[0]: | `openvt -u` is intended to identify the owner of the current VT and | then execute `login` as that user from a privileged context. In the | documented `kbrequest`/init usage, the ownership test in | `authenticate_user()` relies on `stat("/proc/<pid>/fd/0")`. `stat()` | on `/proc/<pid>/fd/0` follows the symlink to the underlying TTY | device node. As a result, `buf.st_uid` reflects the owner of the TTY | node rather than the owner of the process holding the file | descriptor. If the TTY owner returns to `root` or the getty owner | after logout while an unprivileged process still has `fd 0` attached | to that TTY, the check can incorrectly treat that process as | belonging to the privileged console owner. Once that check succeeds, | the `-u` path executes a passwordless login as the selected user. In | the documented `kbrequest`/init deployment using `openvt -us`, this | can result in passwordless `login -f root` on the spawned VT. This | report establishes that privilege escalation path for that | documented deployment; it does not claim equivalent reachability for | deployments that do not use `openvt -u` from a privileged | `kbrequest`/init path. https://bugzilla.redhat.com/show_bug.cgi?id=2462115 Fixed by: https://github.com/legionus/kbd/commit/78d5ae119742e87baa7dbe0f5c4107e7533fd698 (v2.10.0) If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-72693 https://www.cve.org/CVERecord?id=CVE-2026-72693 Please adjust the affected versions in the BTS as needed.