On Wed Aug 26, 2026 at 10:13 AM CEST, Vijay Anusuri via lists.openembedded.org 
wrote:
> Pick patch according to [1]
>
> [1] https://security-tracker.debian.org/tracker/CVE-2026-72693
> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-72693
> [3] https://access.redhat.com/security/cve/cve-2026-72693
>
> Signed-off-by: Vijay Anusuri <[email protected]>
> ---
>  .../recipes-core/kbd/kbd/CVE-2026-72693.patch | 155 ++++++++++++++++++
>  meta/recipes-core/kbd/kbd_2.9.0.bb            |   1 +
>  2 files changed, 156 insertions(+)
>  create mode 100644 meta/recipes-core/kbd/kbd/CVE-2026-72693.patch
>
> diff --git a/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch 
> b/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch
> new file mode 100644
> index 0000000000..06b8c195a5
> --- /dev/null
> +++ b/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch
> @@ -0,0 +1,155 @@
> +From 78d5ae119742e87baa7dbe0f5c4107e7533fd698 Mon Sep 17 00:00:00 2001
> +From: Alexey Gladkov <[email protected]>
> +Date: Tue, 12 May 2026 10:20:50 +0200
> +Subject: [PATCH] openvt: make -u process matching more conservative
> +
> +The -u mode relies on the current VT owner to decide which user should
> +be used for the new login session. Make that check stricter by requiring
> +a matching process owner and controlling terminal instead of relying on
> +the ownership of an inherited file descriptor.
> +
> +Also reject root as a pre-authenticated target and document the tighter
> +behavior in the man page.
> +
> +Signed-off-by: Alexey Gladkov <[email protected]>
> +
> +Upstream-Status: Backport 
> [https://github.com/legionus/kbd/commit/78d5ae119742e87baa7dbe0f5c4107e7533fd698]
> +CVE: CVE-2026-72693
> +Signed-off-by: Vijay Anusuri <[email protected]>
> +---
> + docs/man/man1/openvt.1 | 10 +++++++
> + src/openvt.c           | 64 +++++++++++++++++++++++++++++++++++++-----
> + 2 files changed, 67 insertions(+), 7 deletions(-)
> +
> +diff --git a/docs/man/man1/openvt.1 b/docs/man/man1/openvt.1
> +index 8f1244f..404e4a0 100644
> +--- a/docs/man/man1/openvt.1
> ++++ b/docs/man/man1/openvt.1
> +@@ -36,6 +36,8 @@ will be made the new current VT.
> + \fB\-u\fR, \fB\-\-user\fR
> + Figure out the owner of the current VT, and run login as that user.
> + Suitable to be called by init. Shouldn't be used with \fI\-c\fR or 
> \fI\-l\fR.
> ++This option refuses to pre-authenticate root and requires a process owned by
> ++the VT owner whose controlling terminal is the current VT.
> + .TP
> + \fB\-l\fR, \fB\-\-login\fR
> + Make the command a login shell. A \- is prepended to the name of the command
> +@@ -64,6 +66,14 @@ If
> + is compiled with a getopt_long() and you wish to set
> + options to the command to be run, then you must supply
> + the end of options \-\- flag before the command.
> ++.PP
> ++The
> ++.B \-u
> ++option uses
> ++.BR "login -f"
> ++and therefore bypasses normal password authentication for the detected user.
> ++It is intended only for controlled init or keyboard-request configurations.
> ++Use a normal authenticated login command when authentication is required.
> + .SH EXAMPLES
> + .B openvt
> + can be used to start a shell on the next free VT, by using the command:
> +diff --git a/src/openvt.c b/src/openvt.c
> +index a94392b..ddd9239 100644
> +--- a/src/openvt.c
> ++++ b/src/openvt.c
> +@@ -57,6 +57,51 @@ usage(int rc, const struct kbd_help *options)
> +     exit(rc);
> + }
> + 
> ++static int
> ++proc_pid_stat(const char *pid, uid_t *uid, dev_t *tty)
> ++{
> ++    char filename[NAME_MAX + 12];
> ++    char line[BUFSIZ];
> ++    char *lp, *rp;
> ++    FILE *fp;
> ++    struct stat st;
> ++    long tty_nr;
> ++
> ++    snprintf(filename, sizeof(filename), "/proc/%s/stat", pid);
> ++    fp = fopen(filename, "r");
> ++    if (!fp)
> ++            return -1;
> ++
> ++    if (fstat(fileno(fp), &st)) {
> ++            fclose(fp);
> ++            return -1;
> ++    }
> ++
> ++    if (!fgets(line, sizeof(line), fp)) {
> ++            fclose(fp);
> ++            return -1;
> ++    }
> ++    fclose(fp);
> ++
> ++    rp = strrchr(line, ')');
> ++    if (!rp)
> ++            return -1;
> ++
> ++    /*
> ++     * /proc/<pid>/stat fields after comm are:
> ++     * state ppid pgrp session tty_nr ...
> ++     */
> ++    if (!rp || sscanf(rp + 1, " %*c %*d %*d %*d %ld", &tty_nr) != 1)
> ++            return -1;
> ++
> ++    if (tty_nr <= 0)
> ++            return -1;
> ++
> ++    *uid = st.st_uid;
> ++    *tty = (dev_t) tty_nr;
> ++    return 0;
> ++}
> ++
> + /*
> +  * Support for Spawn_Console: openvt running from init
> +  * added by Joshua Spoerri, Thu Jul 18 21:13:16 EDT 1996
> +@@ -88,8 +133,7 @@ authenticate_user(int curvt)
> +     DIR *dp;
> +     struct dirent *dentp;
> +     struct stat buf;
> +-    dev_t console_dev;
> +-    ino_t console_ino;
> ++    dev_t console_rdev;
> +     uid_t console_uid;
> +     char filename[NAME_MAX + 12];
> +     struct passwd *pwnam;
> +@@ -109,10 +153,12 @@ authenticate_user(int curvt)
> +                     kbd_error(EXIT_FAILURE, errsv, "%s", filename);
> +             }
> +     }
> +-    console_dev = buf.st_dev;
> +-    console_ino = buf.st_ino;
> ++    console_rdev = buf.st_rdev;
> +     console_uid = buf.st_uid;
> + 
> ++    if (console_uid == 0)
> ++            kbd_error(EXIT_FAILURE, 0, _("Refusing to pre-authenticate root 
> on current tty."));

Hello,

Isn't this a change in befavior that might break some use-case?
I don't know how legitimate and/or unsafe it is though...
Do you know?

I'll hold this in the meantime.

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245366): 
https://lists.openembedded.org/g/openembedded-core/message/245366
Mute This Topic: https://lists.openembedded.org/mt/120933890/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to