Public bug reported:

[ Impact ]

There is an issue where sssd-kcm sometimes fails to start and exits with
status 3 if tgt_renewal = true and krb5_renew_interval are set in the
config.

When it fails, the logs show:
"[kcm_set_options] krb5_string_to_deltat failed"
"Failed setting krb5 options for renewal [12]: Cannot allocate memory"

It doesn't fail every time because it depends on the heap memory state.
A server might fail on every start, while another identical server
starts perfectly fine.

The problem is a use-after-free bug. In the code, kcm_read_options()
returns renew_intv but forgets to use talloc_steal(). Because of this,
the string gets freed along with tmp_ctx before krb5_string_to_deltat()
can parse it.

The proposed fix backports upstream commit
0100b1c3536688c12f1db2a65164f03765727f81, which just changes
*_renew_intv = renew_intv; to *_renew_intv = talloc_steal(mem_ctx,
renew_intv); so the memory is kept until it's actually parsed.

[ Test Plan ]

This is easily reproduceable easily as root on a fresh Ubuntu 26.04
system, or just run docker run --rm -it ubuntu:26.04.

1. Install the packages and create the config:

apt-get update && apt-get install -y sssd-kcm valgrind
printf '[kcm]\ntgt_renewal = true\nkrb5_renew_interval = 1200s\n' > 
/etc/sssd/conf.d/kcm.conf
chown -R root:sssd /etc/sssd
chmod 640 /etc/sssd/conf.d/kcm.conf
chmod g+x /etc/sssd /etc/sssd/conf.d

2. Run it with MALLOC_PERTURB:

MALLOC_PERTURB_=165 timeout 5 setpriv --reuid=sssd --regid=sssd --clear-
groups /usr/libexec/sssd/sssd_kcm --logger=stderr -d 0x2f7f0 2>&1 | grep
-E 'deltat|renew'

It fails and prints the "Cannot allocate memory" errors. (Since it
depends on heap state, it might not trigger on every single machine, but
it usually does on a fresh container).

3. Run it with Valgrind (this will catch the bug 100% of the time
regardless of heap state):

timeout 120 setpriv --reuid=sssd --regid=sssd --clear-groups valgrind
/usr/libexec/sssd/sssd_kcm --logger=stderr 2>&1 | grep -m1 -A14 'Invalid
read'

Valgrind shows a memory error: "Invalid read of size 1 ... by
krb5_string_to_deltat ... Address ... is 96 bytes inside a block of size
102 free'd".

[ Other Info ]

Upstream commit:
https://github.com/SSSD/sssd/commit/0100b1c3536688c12f1db2a65164f03765727f81
(this is already in versions 2.13.0).

Right now both resolute (2.12.0-1ubuntu5.4) and stonking
(2.12.0-4ubuntu3) are missing the fix.

** Affects: sssd (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169162

Title:
  sssd-kcm fails to start due to use-after-free with krb5_renew_interval

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/sssd/+bug/2169162/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to