Critical information about security vulnerabilities in LFS and BLFS (Dated 2025-06-22)

"\"Douglas R. Reno\"" ([email protected] via blfs-dev Mailing List) <[email protected]> Sun, 22 Jun 2025 17:14:08 -0500
Newsgroups gmane.linux.lfs.beyond.devel,gmane.linux.lfs.devel,gmane.linux.lfs.support,gmane.linux.lfs.beyond.support
Message-ID <[email protected]>
Good afternoon everyone,

There's been some security-related activity since the last email on 
2025-06-22 that I'm going to include here, but the most serious 
vulnerabilities are in libblockdev, udisks, and Linux-PAM. These can be 
chained together to achieve local privilege escalation, and the 
vulnerability in PAM was disclosed by the French government. Extremely 
detailed proof of concept vulnerabilities and comprehensive details are 
available, and there is some concern that these may become actively 
exploited. Users who have Linux-PAM, libblockdev, or udisks installed 
should take immediate measures to safeguard their systems (by updating 
Linux-PAM and libblockdev, and rebuilding udisks with a sed command). 
More details on these vulnerabilities can be found at 
https://seclists.org/oss-sec/2025/q2/261 and 
https://seclists.org/oss-sec/2025/q2/258 - the BLFS team has verified 
that, at minimum, the udisks and libblockdev vulnerabilities are 
exploitable on a default configuration on both SysV systems (if elogind 
is installed) and systemd systems.

Users are encouraged to continue monitoring 
https://linuxfromscratch.org/blfs/advisories/consolidated.html for new 
security advisories, as I normally only send emails when something major 
(like the PAM problem) comes up!

I've also pushed an update to the yelp/yelp-xsl security advisory. New 
versions of yelp-xsl and yelp are available which have the patch applied 
- yelp-xsl-42.4, and yelp-42.3. Users who haven't already patched them 
should use these versions instead, but if you have already patched them, 
there is no reason to update.

The following packages have had security updates since the last time I 
put out an email:

- Linux-PAM (High)

- libblockdev (High)

- Udisks (High)

- BIND DNS Server (High), client utilities not impacted.

- libarchive (High)

- Firefox (Critical)

- Thunderbird (Critical)

- ISC Kea DHCP Server (High)

- gstreamer (Medium)

- Perl (LFS) - Medium

- Coreutils (LFS) - Medium

- systemd (LFS and BLFS) - Medium

- MariaDB (Medium)

- QtWebEngine (Critical)

- Python3 (LFS and BLFS) - Critical

- cURL (Low)

- Wireshark (High)

- File::Find::Rule Perl Module (High)

- libvpx (Medium), this one requires package rebuilds if you apply it to 
a BLFS 12.3 system

- Samba (Medium), but BLFS systems are not affected by default

- Konsole (Critical), with the caveat that social engineering is required

- Requests Python Module (Medium)

- XWayland (Medium)

- Xorg-Server (Medium)

- libxml2 (High)


**Linux-PAM, udisks, and libblockdev (High)**: *All users are urged to 
update to Linux-PAM-1.7.1 and libblockdev-3.3.1 immediately, and apply 
the sed to udisks-2.10.1.* Last week, a series of emails was sent to the 
oss-security mailing list by Qualys and the French government that 
detail a chain of exploits that allow physical and remote attackers to 
obtain root access to systems by exploiting flaws in Linux-PAM, udisks, 
and libblockdev. Linux-PAM had two vulnerabilities fixed in total, one 
was the local privilege escalation problem (in pam_namespace.so) and the 
other is a unauthorized access vulnerability due to the pam_access 
module not treating rules in it's configuration file correctly (where 
rules are accidentally treated as hostnames). The privilege escalation 
issue has been demonstrated to be exploited with libblockdev and udisks 
to achieve privilege escalation. Both SysV and systemd systems are 
impacted - SysV if elogind is installed, and systemd due to 
systemd-logind. If you have Linux-PAM, libblockdev, and udisks installed 
you are urged to update to Linux-PAM-1.7.1 and libblockdev-3.3.1 
immediately, and apply a sed from the BLFS book to udisks-2.10.1 to fix 
the third stage of the exploit chain.

**BIND DNS Server (High)**: *Users who experience assertion failures 
should update to BIND-9.20.9. *In BIND-9.20.9, a security vulnerability 
was fixed that can allow for a remotely exploitable denial of service 
(crash due to assertion failure) in the BIND DNS server. When an 
incoming DNS protocol message includes a Transaction Signature (TSIG), 
BIND will check it - and if a TSIG contains an invalid value in the 
algorithm field, BIND will immediately abort due to an assertion 
failure. Note that this does *not* affect the client utilities. If you 
are not experiencing problems, you also do not need to apply this update.

**libarchive (High)**: *Users who experience crashes related to 
libarchive should upgrade to libarchive-3.8.0.* In libarchive-3.8.0, 
five vulnerabilities were fixed that can allow for crashes and memory 
corruption when processing RAR, TAR, and WARC archives. The 
vulnerabilities are due to heap buffer overflows, signed integer 
overflows, and double frees. Users who experience crashes related to 
libarchive should update to libarchive-3.8.0, though it doesn't cause 
any harm to update this package regardless. Note that libarchive-3.8.1 
is available, but it doesn't fix any regressions related to this update.

**Firefox (Critical)**: *All users who have Firefox installed should 
update to Firefox-128.11.0esr immediately.* In Firefox-128.11.0esr, 
seven security vulnerabilities were fixed that can allow for remotely 
exploitable crashes, memory corruption, remote code execution, 
cross-origin information leakage, local code execution (through the 
"Copy as cURL" command), and for clickjacking to trick users into 
leaking saved payment card details. One of these vulnerabilities was 
rated as Critical and it's thus recommended that all users update to 
Firefox-128.11.0esr immediately.

**Thunderbird (Critical)**: *All users who have Thunderbird installed 
should update to Thunderbird-128.11.1esr immediately*. In 
Thunderbird-128.11.1esr, eight security vulnerabilities were fixed that 
could allow for credential leakage, disk space exhaustion, unsolicited 
file downloads, remotely exploitable crashes, memory corruption, remote 
code execution, cross-origin information leakage, local code execution 
(through the "Copy ad cURL" command), and for clickjacking to trick 
users into leaking saved payment card details. One of the 
vulnerabilities was rated as Critical and it's thus recommended that all 
users update to Thunderbird-128.11.1esr immediately. Most of these 
vulnerabilities are difficult to exploit in Thunderbird, but one of them 
is Thunderbird specific. That vulnerability allows for unsolicited file 
downloads, credential leakage, and disk space exhaustion when using 
crafted HTML mailbox:/// links in an email. This vulnerability was 
originally claimed to be fixed in Thunderbird-128.10.2esr. That was not 
the case, and the vulnerability was both rated as High and unfixed for 
22 days. The vulnerability is very easy to exploit, and it's recommended 
that all users with Thunderbird update to 128.11.1esr immediately as a 
result.

**ISA Kea DHCP Server (High)**: *All users who have ISC Kea DHCP Server 
installed should update to Kea-2.6.3 immediately.* In Kea-2.6.3, two 
security vulnerabilities were fixed that can allow for privilege 
escalation and for unprivileged users to overwrite files that Kea has 
access too, and silently modify Kea's configuration. This is caused by 
the Kea API points not being properly secured. An additional 
vulnerability occurs because of insecure file permissions in common Kea 
configurations, which allows for confidential information leakage. The 
BLFS team recommends that users with Kea installed update to Kea-2.6.3 
and modify their configuration so that lease files and logs are stored 
in directories that are not world readable.

**gstreamer (Medium)**: *Users who have the gstreamer stack installed 
should update the stack to 1.26.2**. *In 
gst-plugins-base/gst-plugins-good-1.26.2, five security vulnerabilities 
were fixed that can allow for remotely exploitable denial of service 
(application crashes) or information disclosure. The problems occur when 
processing SubRip or TMPlayer formatted subtitles, as well as when 
reading crafted MOV and MP4 files. The issues are caused by stack buffer 
overflows and NULL pointer dereferences, and have been known to be 
exploitable via contexts such as web browsers. Users who have the 
gstreamer stack installed should update to 1.26.2 to fix these 
vulnerabilities.

**Perl (LFS) - Medium**: *Users who have Perl installed should rebuild 
Perl-5.40.2 with the patch in the development LFS book. *In Perl-5.40.2, 
a security vulnerability was discovered that can allow for a race 
condition where file operations may target unintended paths. This race 
condition can lead to unintended operations, including loading code and 
accessing files from unexpected locations. A proof of concept exploit 
for this vulnerability is available publicly, and it triggers arbitrary 
code execution. Users who have Perl installed should thus update to 
Perl-5.40.2 with the patch.

**Coreutils (LFS) - Medium**: *Users who have Coreutils installed should 
update to Coreutils-9.7 with the patch in the development LFS book if 
they experience issues with the 'sort' utility.* In Coreutils-9.6 and 
9.7, a security vulnerability was discovered that can allow for denial 
of service (application crash) or potentially leakage of sensitive data 
when using the 'sort' utility. Note that this vulnerability is not 
exploitable remotely, and users who are impacted on most systems will 
just experience a crash. Users on 32-bit systems or other architectures 
which do not have proper protections may have information leakage as a 
result of a successful exploitation of this vulnerability, but note that 
it is only available locally and the attacker must already have access 
to your system to run the crafted sort command. The problem is due to a 
heap buffer under-read.

**systemd (LFS and BLFS) - Medium**: *Users who have systemd installed 
should update to systemd-257.6 or later, or 256.16 if they are on older 
systems (which has also been tested by the BLFS team). *In 
systemd-257.6, a security vulnerability was fixed that can allow for an 
attacker to force SUID programs to crash, and afterwards replace the 
program with a non-SUID binary to access the original privileged 
process's coredump. This allows the attacker to read extremely sensitive 
data from the system. A proof of concept exploit is available from 
Qualys that allows for unprivileged users to read the memory contents of 
the 'sshd' process on some distributions. All users who have systemd 
installed are encouraged to update to systemd-257.6 or 256.16 
immediately. If you are on an older system, you will also want to update 
your kernel to at least 6.12.31 or later because the fix for the 
vulnerability depends on changes made within the kernel. For those 
interested, more details can be found at 
https://seclists.org/oss-sec/2025/q2/183

**MariaDB (Medium)**: *Users who have MariaDB installed and are running 
it's server should update to MariaDB-11.4.7. Users who are just using 
the client libraries may skip this update.* In MariaDB-11.4.7, five 
security vulnerabilities were fixed which can allow for unauthorized 
access to data stored within a MySQL database, as well as for remotely 
exploitable crashes. As mentioned earlier, the client libraries and 
functionality are not impacted, so you only need to update if you are 
running the MariaDB server.

**QtWebEngine (Critical)**: *All users who have QtWebEngine installed 
should update to QtWebEngine-6.9.1. *In QtWebEngine-6.9.1, nineteen 
security vulnerabilities were fixed that can allow for remote code 
execution, information retrieval about devices on the system, malicious 
extension installation, file restriction bypasses, same origin policy 
bypasses, remotely exploitable privilege escalation, remotely 
exploitable sandbox escapes, cross origin information leakage, and for 
access control bypasses. The vulnerabilities are in a variety of 
different components within the bundled copy of Chromium, including... 
Media, Media Stream, PDFium, Profiles, DevTools, Inspector, V8, libxslt, 
Navigations, Extensions, Mojo, Codecs, HTML, SQLite, and Loader. The 
patch from QtWebEngine-6.9.0 to fix 3D Acceleration problems is also no 
longer required.

**Python (LFS and BLFS) - Critical**: *Users who have Python installed 
and use the tarfile module to extract tarballs should update to 
Python-3.13.5 or 3.12.11 immediately. Users should also upgrade if they 
are experiencing crashes when processing long IPv6 addresses.* In 
Python-3.13.4 and 3.12.11, five security vulnerabilities were fixed that 
can allow for a denial of service (crash of the Python interpreter) when 
processing long IPv6 addresses, and for the tarfile module's extraction 
filters to be bypassed using crafted symlinks and hard links. This set 
of vulnerabilities allow attackers to write arbitrary files into a 
user's filesystem when decompressing a TAR file, which could be leverage 
to exploit future vulnerabilities in indexers, or even overwrite 
programs, libraries, and configuration files already on the system.

**cURL (Low)**: *Users who experience crashes or hangs when using 
WebSocket connections should upgrade to cURL-8.14.1.* In cURL-8.14.1, a 
security vulnerability was fixed that allows for an infinite loop to 
occur when processing a maliciously crafted WebSocket packet. Upstream 
has stated that there's no way to properly exit affected programs other 
than killing the process. If you begin experiencing problems using 
WebSocket connections, you should definitely upgrade to cURL-8.14.1 
before reporting any issues with it to upstream.

**Wireshark (High)**: *Users who experience crashes when running 
Wireshark to capture packets or dissect packet traces should update to 
Wireshark-4.4.7.* In Wireshark-4.4.7, a security vulnerability was fixed 
that can allow for a denial of service (application crash) due to a 
buffer overflow when processing crafted packets. The problem affects the 
built-in Columns module, which is common to all dissectors.

**File::Find::Rule Perl Module (High)**: *All users who have the 
File::Find::Rule Perl Module installed should update to 
File::Find::Rule-0.35*. In File::Find::Rule-0.35, a security 
vulnerability was fixed that can allow for arbitrary code execution when 
'grep()' encounters a maliciously crafted file name. A file handle gets 
opened with the 2 argument form of 'open()', which can allow attackers 
to provide the MODE parameter to open() via said crafted file name. This 
feeds the MODE parameter to open(), turning the filename into a command 
to be executed. A proof of concept exploit has been published 
demonstrating how the vulnerability can be exploited, so users who have 
this module installed should update as soon as possible.

**libvpx (Medium)**: *Users who have libvpx installed should update to 
libvpx-1.15.2, but there are caveats.* In libvpx-1.15.2 a security 
vulnerability was fixed that can allow for arbitrary code execution when 
processing VP8 and VP9 files, or for a denial of service (application 
crash). The vulnerability was discovered being used in attacks against 
Google Chrome, but can be exploited in a variety of contexts including 
media players and web browsers. The problem is caused by a use after 
free. Applying this update to a BLFS 12.3 system can be challenging due 
to the fact that libvpx-1.15.2 is not ABI compatible with libvpx-1.15.0, 
as shipped with BLFS 12.3. In order to properly fix this vulnerability, 
several applications will need to be rebuilt afterwards. We are 
currently aware of the following packages needing to be rebuilt: ffmpeg 
VLC, gst-plugins-good, xine-lib, Thunderbird, and Firefox. This method 
has been tested and is confirmed to work.

**Samba (Medium)**: *Users who have Samba installed and are 
participating in an Active Directory network or using Kerberos 
authentication should update to Samba-4.22.2. Note that the standard 
BLFS configuration is NOT affected.* In Samba-4.22.2, a security 
vulnerability was fixed that can allow for file shares to be exposed to 
clients until a computer disconnects from an SMB server and reconnects 
again. The problem occurs because smbd didn't pick up group membership 
changes when it resets an expired SMB sessions. This issue only affects 
Kerberos authentication though and Active Directory support with the SMB 
file server in BLFS, which is not part of the standard BLFS book. In 
addition, users are *not* impacted if they are using the client side 
components. If you are impacted though, you should update to Samba-4.22.2.

**Konsole (Critical)**: *Users who have Konsole installed should upgrade 
to Konsole-25.04.2, or apply the workaround described in this advisory. 
This update may not be necessary for all users though and users should 
make a decision based on the information listed here. *In 
Konsole-25.04.2, a security vulnerability was fixed which can allow for 
attackers to trick users into executing arbitrary code with a malicious 
link. Note that the attack requires significant social engineering to be 
successful. The issue occurs because Konsole allows loading URLs from 
various scheme handlers (such as telnet://) - but it does not check to 
verify that the program used to handle the scheme exists first. If it 
isn't present, Konsole falls back to using Bash instead, which allows 
for arbitrary code execution. I personally developed a proof of concept 
that BLFS systems are succeptible to in order to test whether we are 
vulnerable to the problem or not. For a BLFS system to be affected, a 
user must download a file (or be hit by another vulnerability allowing 
for arbitrary file extractions or downloads), and then willingly right 
click the URL in a context menu to click "Open Link". Still though, BLFS 
systems are impacted if a user clicks "Open Link" on a rlogin:// URL. 
Users who do not have OpenSSH installed can also be hit by a ssh:// URL. 
There are three ways to fix this problem - don't use the functionality 
in Konsole as it must be manually clicked by a user to exploit this 
vulnerability, or update to Konsole-25.04.2, or remove 
$KF6_PREFIX/share/applications/ktelnetservice6.desktop from the system 
(and relaunch Konsole). Both methods requiring changes have been tested 
on a BLFS 12.3 system and are confirmed to work.

**Requests Python Module (Medium)**: *Users who have Requests installed 
and use a ~/.netrc file should update to Requests-2.32.4 immediately. 
Users who do not use a ~/.netrc file are not impacted.* In 
Requests-2.32.4, a security vulnerability was fixed that can allow for a 
crafted URL and a trusted environment to retrieve credentials from the 
wrong hostname in a ~/.netrc file. Users who do not have a ~/.netrc file 
are not affected, and there is no need to upgrade in this case. If you 
do have one though, update to Requests-2.32.4 immediately as the 
workaround requires modifying every requests session to include 
"trust_env=False", and this Python Module can get called by others in BLFS.

**Xorg-Server (Medium)**: *Users who have Xorg-Server installed should 
update to Xorg-Server-21.1.18, and also rebuild TigerVNC against the new 
version if it is installed.* In Xorg-Server-21.1.18, six security 
vulnerabilities were fixed that can allow for remote code execution, 
privilege escalation, information disclosure, client hangs, and crashes. 
Several vulnerabilities are very old, dating all the way back to X11R6. 
Upstream has rated all of these vulnerabilities as Medium, but if you 
are using TigerVNC or SSH X Forwarding these should be treated as 
*Critical*.

**Xwayland (Medium)**: *Users who have Xwayland installed should update 
to Xwayland-24.1.8. *In Xwayland-24.1.8, six security vulnerabilities 
were fixed that can allow for remote code execution, privilege 
escalation, information disclosure, client hangs, and crashes. Several 
vulnerabilities are very old, dating all the way back to X11R6. As with 
Xorg-Server, all of the vulnerabilities are rated as Medium.

**libxml2 (High)**: *Users who have libxml2 and WINE or PHP installed 
should update to libxml2-2.14.4, or rebuild libxml2-2.13.x with the 
patch (recommended if using BLFS 12.3 or prior).* In libxml2-2.14.4, a 
security vulnerability was fixed that can allow for a denial of service 
(application crash) or memory corruption when a program uses the 
xmlBuildQName() function. In BLFS, only PHP is known to use it. If you 
use Zeckma's GLFS book, WINE is also impacted. Only those two packages 
are known to be affected. Users who have either PHP or WINE installed 
should update to libxml2-2.14.4 - but, if you are on BLFS 12.3 or prior, 
you should use the patch that I created and uploaded to 
https://linuxfromscratch.org/patches/downloads/libxml2/libxml2-2.13.8-security_fixes-1.patch 
to fix the vulnerability instead (applying the patch and rebuilding 
libxml2-2.13.8).


On that note, the most severe of these vulnerabilities still remains 
Linux-PAM, shadow, and libblockdev. If you have any questions, please 
feel free to ask! As always, please continue to monitor 
https://linuxfromscratch.org/blfs/advisories/consolidated.html for updates!

- Douglas Reno
Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-dev
Unsubscribe: See the above information page