!73 [sync] PR-71: FIX CVE-2024-2314
From: @openeuler-sync-bot Reviewed-by: @bitcoffee Signed-off-by: @bitcoffee
This commit is contained in:
commit
49d00b5e10
65
backport-CVE-2024-2314-clang-check-header-owners.patch
Normal file
65
backport-CVE-2024-2314-clang-check-header-owners.patch
Normal file
@ -0,0 +1,65 @@
|
|||||||
|
From 008ea09e891194c072f2a9305a3c872a241dc342 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Brendan Gregg <brendan@intel.com>
|
||||||
|
Date: Thu, 7 Mar 2024 05:27:14 +1100
|
||||||
|
Subject: [PATCH] clang: check header ownership (#4928)
|
||||||
|
|
||||||
|
Example testing with a brendan-owned /tmp/kheaders file (note the "ERROR:" message):
|
||||||
|
|
||||||
|
~/bcc/build$ sudo /usr/share/bcc/tools/biosnoop
|
||||||
|
ERROR: header file ownership unexpected: /tmp/kheaders-5.15.47-internal
|
||||||
|
<built-in>:1:10: fatal error: './include/linux/kconfig.h' file not found
|
||||||
|
#include "./include/linux/kconfig.h"
|
||||||
|
^~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||||
|
1 error generated.
|
||||||
|
Traceback (most recent call last):
|
||||||
|
File "/usr/share/bcc/tools/biosnoop", line 335, in <module>
|
||||||
|
b = BPF(text=bpf_text)
|
||||||
|
File "/usr/lib/python3/dist-packages/bcc-0.1.5+6cd27218-py3.10.egg/bcc/__init__.py", line 479, in __init__
|
||||||
|
Exception: Failed to compile BPF module <text>
|
||||||
|
~/bcc/build$ ls -lhd /tmp/kheaders-5.15.47-internal
|
||||||
|
drwxrwxr-x 2 brendan dev 4.0K Mar 6 02:50 /tmp/kheaders-5.15.47-internal
|
||||||
|
|
||||||
|
No error when chown'd back to root.
|
||||||
|
---
|
||||||
|
src/cc/frontends/clang/kbuild_helper.cc | 15 +++++++++++----
|
||||||
|
1 file changed, 11 insertions(+), 4 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/src/cc/frontends/clang/kbuild_helper.cc b/src/cc/frontends/clang/kbuild_helper.cc
|
||||||
|
index 50e2da9a7bc..d4b9d3e61c7 100644
|
||||||
|
--- a/src/cc/frontends/clang/kbuild_helper.cc
|
||||||
|
+++ b/src/cc/frontends/clang/kbuild_helper.cc
|
||||||
|
@@ -140,15 +140,22 @@ int KBuildHelper::get_flags(const char *uname_machine, vector<string> *cflags) {
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
-static inline int file_exists(const char *f)
|
||||||
|
+static inline int file_exists_and_ownedby(const char *f, uid_t uid)
|
||||||
|
{
|
||||||
|
struct stat buffer;
|
||||||
|
- return (stat(f, &buffer) == 0);
|
||||||
|
+ int ret;
|
||||||
|
+ if ((ret = stat(f, &buffer)) == 0) {
|
||||||
|
+ if (buffer.st_uid != uid) {
|
||||||
|
+ std::cout << "ERROR: header file ownership unexpected: " << std::string(f) << "\n";
|
||||||
|
+ return -1;
|
||||||
|
+ }
|
||||||
|
+ }
|
||||||
|
+ return ret;
|
||||||
|
}
|
||||||
|
|
||||||
|
static inline int proc_kheaders_exists(void)
|
||||||
|
{
|
||||||
|
- return file_exists(PROC_KHEADERS_PATH);
|
||||||
|
+ return file_exists_and_ownedby(PROC_KHEADERS_PATH, 0);
|
||||||
|
}
|
||||||
|
|
||||||
|
static inline const char *get_tmp_dir() {
|
||||||
|
@@ -224,7 +231,7 @@ int get_proc_kheaders(std::string &dirpath)
|
||||||
|
uname_data.release);
|
||||||
|
dirpath = std::string(dirpath_tmp);
|
||||||
|
|
||||||
|
- if (file_exists(dirpath_tmp))
|
||||||
|
+ if (file_exists_and_ownedby(dirpath_tmp, 0))
|
||||||
|
return 0;
|
||||||
|
|
||||||
|
// First time so extract it
|
||||||
6
bcc.spec
6
bcc.spec
@ -2,7 +2,7 @@
|
|||||||
|
|
||||||
Name: bcc
|
Name: bcc
|
||||||
Version: 0.29.1
|
Version: 0.29.1
|
||||||
Release: 2
|
Release: 3
|
||||||
Summary: BPF Compiler Collection (BCC)
|
Summary: BPF Compiler Collection (BCC)
|
||||||
License: ASL 2.0
|
License: ASL 2.0
|
||||||
URL: https://github.com/iovisor/bcc
|
URL: https://github.com/iovisor/bcc
|
||||||
@ -10,6 +10,7 @@ URL: https://github.com/iovisor/bcc
|
|||||||
Source0: %{url}/releases/download/v%{version}/%{name}-src-with-submodule.tar.gz
|
Source0: %{url}/releases/download/v%{version}/%{name}-src-with-submodule.tar.gz
|
||||||
|
|
||||||
Patch0001: backport-Fix-ttysnoop.py-with-newer-kernels-4888.patch
|
Patch0001: backport-Fix-ttysnoop.py-with-newer-kernels-4888.patch
|
||||||
|
Patch0002: backport-CVE-2024-2314-clang-check-header-owners.patch
|
||||||
|
|
||||||
# Arches will be included as upstream support is added and dependencies are
|
# Arches will be included as upstream support is added and dependencies are
|
||||||
# satisfied in the respective arches
|
# satisfied in the respective arches
|
||||||
@ -164,6 +165,9 @@ rm -rf %{buildroot}%{_datadir}/%{name}/tools/old/
|
|||||||
|
|
||||||
|
|
||||||
%changelog
|
%changelog
|
||||||
|
* Tue Dec 03 2024 zhangmingyi <zhangmingyi5@huawei.com> - 0.29.1-3
|
||||||
|
- Fix CVE-2024-2314
|
||||||
|
|
||||||
* Thu May 09 2024 jinzhiguang <jinzhiguang@kylinos.cn> - 0.29.1-2
|
* Thu May 09 2024 jinzhiguang <jinzhiguang@kylinos.cn> - 0.29.1-2
|
||||||
- backport patch from upstream
|
- backport patch from upstream
|
||||||
backport-Fix-ttysnoop.py-with-newer-kernels-4888.patch
|
backport-Fix-ttysnoop.py-with-newer-kernels-4888.patch
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user