Public bug reported: [ Impact ]
There is an issue where sssd-kcm sometimes fails to start and exits with status 3 if tgt_renewal = true and krb5_renew_interval are set in the config. When it fails, the logs show: "[kcm_set_options] krb5_string_to_deltat failed" "Failed setting krb5 options for renewal [12]: Cannot allocate memory" It doesn't fail every time because it depends on the heap memory state. A server might fail on every start, while another identical server starts perfectly fine. The problem is a use-after-free bug. In the code, kcm_read_options() returns renew_intv but forgets to use talloc_steal(). Because of this, the string gets freed along with tmp_ctx before krb5_string_to_deltat() can parse it. The proposed fix backports upstream commit 0100b1c3536688c12f1db2a65164f03765727f81, which just changes *_renew_intv = renew_intv; to *_renew_intv = talloc_steal(mem_ctx, renew_intv); so the memory is kept until it's actually parsed. [ Test Plan ] This is easily reproduceable easily as root on a fresh Ubuntu 26.04 system, or just run docker run --rm -it ubuntu:26.04. 1. Install the packages and create the config: apt-get update && apt-get install -y sssd-kcm valgrind printf '[kcm]\ntgt_renewal = true\nkrb5_renew_interval = 1200s\n' > /etc/sssd/conf.d/kcm.conf chown -R root:sssd /etc/sssd chmod 640 /etc/sssd/conf.d/kcm.conf chmod g+x /etc/sssd /etc/sssd/conf.d 2. Run it with MALLOC_PERTURB: MALLOC_PERTURB_=165 timeout 5 setpriv --reuid=sssd --regid=sssd --clear- groups /usr/libexec/sssd/sssd_kcm --logger=stderr -d 0x2f7f0 2>&1 | grep -E 'deltat|renew' It fails and prints the "Cannot allocate memory" errors. (Since it depends on heap state, it might not trigger on every single machine, but it usually does on a fresh container). 3. Run it with Valgrind (this will catch the bug 100% of the time regardless of heap state): timeout 120 setpriv --reuid=sssd --regid=sssd --clear-groups valgrind /usr/libexec/sssd/sssd_kcm --logger=stderr 2>&1 | grep -m1 -A14 'Invalid read' Valgrind shows a memory error: "Invalid read of size 1 ... by krb5_string_to_deltat ... Address ... is 96 bytes inside a block of size 102 free'd". [ Other Info ] Upstream commit: https://github.com/SSSD/sssd/commit/0100b1c3536688c12f1db2a65164f03765727f81 (this is already in versions 2.13.0). Right now both resolute (2.12.0-1ubuntu5.4) and stonking (2.12.0-4ubuntu3) are missing the fix. ** Affects: sssd (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2169162 Title: sssd-kcm fails to start due to use-after-free with krb5_renew_interval To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/sssd/+bug/2169162/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
