Bug 1716284 (CVE-2019-11460)

Summary: CVE-2019-11460 gnome-desktop: thumbnailer security bypass
Product: [Other] Security Response Reporter: Dhananjay Arunesh <darunesh>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: caillon+fedoraproject, fmuellner, gnome-sig, john.j5live, mclasen, philip.wyett, rhughes, rstrode, tiagomatos, yselkowi
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: gnome-desktop 3.30.2.2, gnome-deskop 3.32.1.1 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-27 03:29:02 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1716290, 1716291, 1716292, 1718719, 1718720    
Bug Blocks: 1716288    

Description Dhananjay Arunesh 2019-06-03 07:16:19 UTC
An issue was discovered in GNOME gnome-desktop 3.26, 3.28, and 3.30 prior to 3.30.2.2, and 3.32 prior to 3.32.1.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.

Reference:
https://gitlab.gnome.org/GNOME/gnome-desktop/issues/112

Comment 1 Dhananjay Arunesh 2019-06-03 07:24:28 UTC
Created gnome-desktop tracking bugs for this issue:

Affects: fedora-all [bug 1716290]


Created gnome-desktop3 tracking bugs for this issue:

Affects: fedora-all [bug 1716291]

Comment 2 Dhananjay Arunesh 2019-06-03 07:24:48 UTC
Created gnome-desktop tracking bugs for this issue:

Affects: epel-7 [bug 1716292]

Comment 4 Huzaifa S. Sidhpurwala 2019-06-10 04:20:07 UTC
Upstream patch: https://gitlab.gnome.org/GNOME/nautilus/commit/2ddba428ef2b13d0620bd599c3635b9c11044659