correspondence2--- via Bug reports for the GNU Bourne Again SHell <[email protected]> writes:
> Dear GNU Bash Maintainers,
>
> I am writing to report a security vulnerability in the GNU Bash shell.
>
> SUMMARY
> ========
> The alrm_catcher() function in eval.c (lines 154-161) is called from the
> SIGALRM signal handler context but performs operations that are not
> async-signal-safe according to POSIX standards.
>
> DETAILS
> =======
> The vulnerable code:
>
> static sighandler
> alrm_catcher(i)
> int i;
> {
> printf (_("\007timed out waiting for input: auto-logout\n"));
> fflush (stdout);
> bash_logout (); /* run ~/.bash_logout if this is a login shell */
> jump_to_top_level (EXITPROG);
> SIGRETURN (0);
> }
>
> This calls:
> 1. printf() - Not async-signal-safe
> 2. fflush() - Not async-signal-safe
> 3. bash_logout() - Executes arbitrary user scripts (not async-safe)
How is that different from just letting the process exit otherwise?
~/.bash_logout will be used either way. If a process writes to arbitrary
bash init files, then all bets are off.
The signal handler should be made async-safe, but I don't think there's
any vulnerability here.
> 4. jump_to_top_level() - Longjmp in signal context
>
> IMPACT
> ======
> - Arbitrary code execution (via bash_logout)
> - Heap corruption (via printf)
> - Deadlocks (via fflush)
> - State corruption (via longjmp)
>
> CVSS Score: 7.8 (HIGH)
>
> Proof of Concept:
>
> #!/bin/bash
> # ================================================================
> # MINIMAL POC: alrm_catcher Vulnerability
> # ================================================================
> # This is the smallest possible test to confirm the vulnerability.
> # ================================================================
> echo "[*] Creating malicious bash_logout..."
> cat > ~/.bash_logout << 'EOF'
> #!/bin/bash
> echo "====== EXPLOIT EXECUTED FROM SIGNAL HANDLER ======"
> echo "This proves arbitrary code execution!"
> echo "Time: $(date)" > /tmp/poc_proof.txt
> echo "User: $(whoami)" >> /tmp/poc_proof.txt
> echo "PID: $$" >> /tmp/poc_proof.txt
> EOF
> chmod +x ~/.bash_logout
> echo "[*] Triggering alarm..."
> export SHLVL=2
> export TMOUT=1
> sleep 2
> echo ""
> echo "[*] Checking results..."
> if [ -f /tmp/poc_proof.txt ]; then
> echo "[+] SUCCESS! Vulnerability confirmed!"
> echo "Proof contents:"
> cat /tmp/poc_proof.txt
> else
> echo "[-] Exploit failed (not a login shell?)"
> fi
> echo "[*] Cleaning up..."
> rm -f ~/.bash_logout
> rm -f /tmp/poc_proof.txt
> echo "[*] Done"
> MITIGATION
> ==========
> Replace alrm_catcher() with a flag-based approach:
>
> static volatile sig_atomic_t alarm_triggered = 0;
>
> static sighandler alrm_catcher_safe(i)
> {
> alarm_triggered = 1;
> }
>
> // In main loop:
> if (alarm_triggered) {
> alarm_triggered = 0;
> printf(_("\007timed out waiting for input: auto-logout\n"));
> fflush(stdout);
> bash_logout();
> jump_to_top_level(EXITPROG);
> }
>
> I am happy to assist with any additional information or testing.
> Please use this email to contact me back, I want a CVE.
>
> Sincerely,
> Ali
signature.asc
Description: PGP signature
