[meta-virtualization][scarthgap][PATCH] libvirt: fix for CVE-2026-63622
Hitendra Prajapati <[email protected]>
| Newsgroups | org.yoctoproject.lists.meta-virtualization |
|---|---|
| Message-ID | <[email protected]> |
Pick patch from [1] also mentioned at Debian report in [2] [1] https://gitlab.com/libvirt/libvirt/-/commit/801160fd414ca2cc402bc01ead09b7ed4c3b8f5b [2] https://security-tracker.debian.org/tracker/CVE-2026-63622 [3] https://nvd.nist.gov/vuln/detail/CVE-2026-63622 Signed-off-by: Hitendra Prajapati <[email protected]> --- .../libvirt/libvirt/CVE-2026-63622.patch | 73 +++++++++++++++++++ recipes-extended/libvirt/libvirt_10.0.0.bb | 1 + 2 files changed, 74 insertions(+) create mode 100644 recipes-extended/libvirt/libvirt/CVE-2026-63622.patch diff --git a/recipes-extended/libvirt/libvirt/CVE-2026-63622.patch b/recipes-extended/libvirt/libvirt/CVE-2026-63622.patch new file mode 100644 index 00000000..093cd1c6 --- /dev/null +++ b/recipes-extended/libvirt/libvirt/CVE-2026-63622.patch @@ -0,0 +1,73 @@ +From 801160fd414ca2cc402bc01ead09b7ed4c3b8f5b Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?HE=20WEI=EF=BC=88=E3=82=AE=E3=82=AB=E3=82=AF=EF=BC=89?= + <[email protected]> +Date: Tue, 28 Jul 2026 17:49:02 +0100 +Subject: [PATCH] util: virFileChownFiles: do not follow symlinks +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +virFileChownFiles() selected entries with virFileIsRegular() (stat(), follows +symlinks) and changed ownership with chown() (follows symlinks). A component +that owns the target directory at a lower privilege (e.g. the swtpm/tss state +directory) can plant a symlink to an arbitrary regular file and have the root +caller chown that file. Use lstat() to skip non-regular entries and +fchownat(..., AT_SYMLINK_NOFOLLOW) so a symlink final component is never +followed. + +Fixes: CVE-2026-63622 +Signed-off-by: HE WEI(ギカク) <[email protected]> +[DB: use g_lstat instead of stat; use lchown instead of + fchownat for portability; added comment] +Reviewed-by: Ján Tomko <[email protected]> +Signed-off-by: Daniel P. Berrangé <[email protected]> + +CVE: CVE-2026-63622 +Upstream-Status: Backport [https://gitlab.com/libvirt/libvirt/-/commit/801160fd414ca2cc402bc01ead09b7ed4c3b8f5b] +Signed-off-by: Hitendra Prajapati <[email protected]> +--- + src/util/virfile.c | 16 ++++++++++++++-- + 1 file changed, 14 insertions(+), 2 deletions(-) + +diff --git a/src/util/virfile.c b/src/util/virfile.c +index f3108e9..baeb842 100644 +--- a/src/util/virfile.c ++++ b/src/util/virfile.c +@@ -3172,6 +3172,12 @@ int virDirIsEmpty(const char *path, + * + * Change ownership of all regular files in a directory. + * ++ * This will NOT follow any symlinks, to avoid security risks. ++ * It is assumed the process using content under @name will ++ * be unprivileged, thus less trusted than libvirt. If it is ++ * compromised it might attempt to create symlinks in @name to ++ * escalate privileges on a subsequent call to virFileChownFiles. ++ * + * Returns -1 on error, with error already reported, 0 on success. + */ + #ifndef WIN32 +@@ -3188,13 +3194,19 @@ int virFileChownFiles(const char *name, + + while ((direrr = virDirRead(dir, &ent, name)) > 0) { + g_autofree char *path = NULL; ++ struct stat sb; + + path = g_build_filename(name, ent->d_name, NULL); + +- if (!virFileIsRegular(path)) ++ if (g_lstat(path, &sb) < 0) { ++ virReportSystemError(errno, _("cannot stat '%1$s'"), path); ++ return -1; ++ } ++ ++ if (!S_ISREG(sb.st_mode)) + continue; + +- if (chown(path, uid, gid) < 0) { ++ if (lchown(path, uid, gid) < 0) { + virReportSystemError(errno, + _("cannot chown '%1$s' to (%2$u, %3$u)"), + ent->d_name, (unsigned int) uid, +-- +2.50.1 + diff --git a/recipes-extended/libvirt/libvirt_10.0.0.bb b/recipes-extended/libvirt/libvirt_10.0.0.bb index c6e6069c..4076a0cf 100644 --- a/recipes-extended/libvirt/libvirt_10.0.0.bb +++ b/recipes-extended/libvirt/libvirt_10.0.0.bb @@ -38,6 +38,7 @@ SRC_URI = "http://libvirt.org/sources/libvirt-${PV}.tar.xz;name=libvirt \ file://CVE-2024-2494.patch \ file://CVE-2024-4418.patch \ file://CVE-2025-13193.patch \ + file://CVE-2026-63622.patch \ " SRC_URI[libvirt.sha256sum] = "8ba2e72ec8bdd2418554a1474c42c35704c30174b7611eaf9a16544b71bcf00a" -- 2.50.1