On Wed Aug 26, 2026 at 10:13 AM CEST, Vijay Anusuri via lists.openembedded.org wrote: > Pick patch according to [1] > > [1] https://security-tracker.debian.org/tracker/CVE-2026-72693 > [2] https://nvd.nist.gov/vuln/detail/CVE-2026-72693 > [3] https://access.redhat.com/security/cve/cve-2026-72693 > > Signed-off-by: Vijay Anusuri <[email protected]> > --- > .../recipes-core/kbd/kbd/CVE-2026-72693.patch | 155 ++++++++++++++++++ > meta/recipes-core/kbd/kbd_2.9.0.bb | 1 + > 2 files changed, 156 insertions(+) > create mode 100644 meta/recipes-core/kbd/kbd/CVE-2026-72693.patch > > diff --git a/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch > b/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch > new file mode 100644 > index 0000000000..06b8c195a5 > --- /dev/null > +++ b/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch > @@ -0,0 +1,155 @@ > +From 78d5ae119742e87baa7dbe0f5c4107e7533fd698 Mon Sep 17 00:00:00 2001 > +From: Alexey Gladkov <[email protected]> > +Date: Tue, 12 May 2026 10:20:50 +0200 > +Subject: [PATCH] openvt: make -u process matching more conservative > + > +The -u mode relies on the current VT owner to decide which user should > +be used for the new login session. Make that check stricter by requiring > +a matching process owner and controlling terminal instead of relying on > +the ownership of an inherited file descriptor. > + > +Also reject root as a pre-authenticated target and document the tighter > +behavior in the man page. > + > +Signed-off-by: Alexey Gladkov <[email protected]> > + > +Upstream-Status: Backport > [https://github.com/legionus/kbd/commit/78d5ae119742e87baa7dbe0f5c4107e7533fd698] > +CVE: CVE-2026-72693 > +Signed-off-by: Vijay Anusuri <[email protected]> > +--- > + docs/man/man1/openvt.1 | 10 +++++++ > + src/openvt.c | 64 +++++++++++++++++++++++++++++++++++++----- > + 2 files changed, 67 insertions(+), 7 deletions(-) > + > +diff --git a/docs/man/man1/openvt.1 b/docs/man/man1/openvt.1 > +index 8f1244f..404e4a0 100644 > +--- a/docs/man/man1/openvt.1 > ++++ b/docs/man/man1/openvt.1 > +@@ -36,6 +36,8 @@ will be made the new current VT. > + \fB\-u\fR, \fB\-\-user\fR > + Figure out the owner of the current VT, and run login as that user. > + Suitable to be called by init. Shouldn't be used with \fI\-c\fR or > \fI\-l\fR. > ++This option refuses to pre-authenticate root and requires a process owned by > ++the VT owner whose controlling terminal is the current VT. > + .TP > + \fB\-l\fR, \fB\-\-login\fR > + Make the command a login shell. A \- is prepended to the name of the command > +@@ -64,6 +66,14 @@ If > + is compiled with a getopt_long() and you wish to set > + options to the command to be run, then you must supply > + the end of options \-\- flag before the command. > ++.PP > ++The > ++.B \-u > ++option uses > ++.BR "login -f" > ++and therefore bypasses normal password authentication for the detected user. > ++It is intended only for controlled init or keyboard-request configurations. > ++Use a normal authenticated login command when authentication is required. > + .SH EXAMPLES > + .B openvt > + can be used to start a shell on the next free VT, by using the command: > +diff --git a/src/openvt.c b/src/openvt.c > +index a94392b..ddd9239 100644 > +--- a/src/openvt.c > ++++ b/src/openvt.c > +@@ -57,6 +57,51 @@ usage(int rc, const struct kbd_help *options) > + exit(rc); > + } > + > ++static int > ++proc_pid_stat(const char *pid, uid_t *uid, dev_t *tty) > ++{ > ++ char filename[NAME_MAX + 12]; > ++ char line[BUFSIZ]; > ++ char *lp, *rp; > ++ FILE *fp; > ++ struct stat st; > ++ long tty_nr; > ++ > ++ snprintf(filename, sizeof(filename), "/proc/%s/stat", pid); > ++ fp = fopen(filename, "r"); > ++ if (!fp) > ++ return -1; > ++ > ++ if (fstat(fileno(fp), &st)) { > ++ fclose(fp); > ++ return -1; > ++ } > ++ > ++ if (!fgets(line, sizeof(line), fp)) { > ++ fclose(fp); > ++ return -1; > ++ } > ++ fclose(fp); > ++ > ++ rp = strrchr(line, ')'); > ++ if (!rp) > ++ return -1; > ++ > ++ /* > ++ * /proc/<pid>/stat fields after comm are: > ++ * state ppid pgrp session tty_nr ... > ++ */ > ++ if (!rp || sscanf(rp + 1, " %*c %*d %*d %*d %ld", &tty_nr) != 1) > ++ return -1; > ++ > ++ if (tty_nr <= 0) > ++ return -1; > ++ > ++ *uid = st.st_uid; > ++ *tty = (dev_t) tty_nr; > ++ return 0; > ++} > ++ > + /* > + * Support for Spawn_Console: openvt running from init > + * added by Joshua Spoerri, Thu Jul 18 21:13:16 EDT 1996 > +@@ -88,8 +133,7 @@ authenticate_user(int curvt) > + DIR *dp; > + struct dirent *dentp; > + struct stat buf; > +- dev_t console_dev; > +- ino_t console_ino; > ++ dev_t console_rdev; > + uid_t console_uid; > + char filename[NAME_MAX + 12]; > + struct passwd *pwnam; > +@@ -109,10 +153,12 @@ authenticate_user(int curvt) > + kbd_error(EXIT_FAILURE, errsv, "%s", filename); > + } > + } > +- console_dev = buf.st_dev; > +- console_ino = buf.st_ino; > ++ console_rdev = buf.st_rdev; > + console_uid = buf.st_uid; > + > ++ if (console_uid == 0) > ++ kbd_error(EXIT_FAILURE, 0, _("Refusing to pre-authenticate root > on current tty."));
Hello, Isn't this a change in befavior that might break some use-case? I don't know how legitimate and/or unsafe it is though... Do you know? I'll hold this in the meantime. Regards, -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#245366): https://lists.openembedded.org/g/openembedded-core/message/245366 Mute This Topic: https://lists.openembedded.org/mt/120933890/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
