CVSROOT:        /cvs
Module name:    src
Changes by:     [email protected]   2026/10/03 11:35:09

Modified files:
        sbin/isakmpd   : Tag: OPENBSD_7_8 conf.c conf.h connection.c 
                         connection.h exchange.c exchange.h field.c 
                         field.h ike_auth.c ike_quick_mode.c ipsec.c 
                         isakmpd.8 isakmpd.c log.c log.h message.c 
                         message.h monitor.c monitor.h pf_key_v2.c 
                         policy.c sa.c sa.h timer.c timer.h transport.c 
                         transport.h udp.c udp_encap.c ui.c ui.h util.c 
                         util.h virtual.c 

Log message:
incorrect object being freed
from Franz Bettag / Bettag Systems
from deraadt@; OK markus@ hshoexer@ sthen@ mvs@

IKEv1 short-HASH heap overflow; second approach for fix
from Franz Bettag / Bettag Systems
from deraadt@; OK sthen@ mvs@

Franz Bettag sent a report & diff repairing the privsep monitor's
dangerous file behavior in /var/run, and I was shocked at what it
does.  isakmpd never had a proper diagnosis and control program like
other daemons do, and instead accepts weird commands on a fifo and
splats files dangerously.  Some path names can be manipulated.  This
2600 line diff removes all of this session debugging mechanism which
is the main cause of that unsafe design.  There are no reuseable parts
in that code (it cannot be reconstructed into a proper control program
interface).  As a result, the privsep monitor now has unveil to the
config directory, and the network speaking process is "stdio sendfd
route recvfd inet".  There is some loss of functionality, since some
users had gotten used to the decrepit debugging / logging interface to
repair sessions which would not negotiate.
This is almost completely unmaintained code from early OpenBSD days
with an incorrect privsep design, and many users have migrated to
using iked(8) which does IKEv2 protocol.  RFC9395 also provides valuable
guidance here.  Everyone is urged to avoid using this program.  If IKEv1
protocol is still a part of your life roll up sleeves and try to write a
high-quality control interface using lessons from the IKEv2 iked(8) code.
Great conversations and help from Franz Bettag finding code to delete.
from deraadt@; comments & tests from sthen@ mvs@ robert@;
also OK markus@ bluhm@ hshoexer@

The path generation must not contain '..' or '/' type patterns or it
can walk upwards and sideways.  The privsep open() is now restricted by
a single unveil() inside the config directory, but files in relative config
directories can still be reached and create potentially confusing outcomes.
This is half of a repair from Franz Bettag before I restructured the privsep
to use unveil(), the other half of the repair is not needed because it applies
to code that no longer exists.
from deraadt@; OK markus@ hshoexer@ bluhm@; testing sthen@ mvs@

this is errata/7.8/067_isakmpd.patch.sig

Reply via email to