Bug 2173520

Summary: Please backport the fix for the double-free crash bug you backported :)
Product: [Fedora] Fedora Reporter: Robin Powell <rlpowell>
Component: opensshAssignee: Dmitry Belyavskiy <dbelyavs>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 37CC: crypto-team, dbelyavs, dwalsh, jjelen, lkundrak, mattias.ellert, tm
Target Milestone: ---Keywords: Security, Triaged
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: openssh-8.8p1-10.fc37 openssh-9.0p1-15.fc38 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-04-14 11:46:35 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Comment 3 Robin Powell 2023-02-27 15:12:57 UTC
I got a mail that you converted it to private and I was like "that's weird", but then I realized there's a CVE attached, which I hadn't put together.

... Severity 8.9??  Nuh-uh.  Yes, it causes a crash, but the crash is to the *per-client* sshd instance.  It has no effect whatsoever on the overall system.  Unless someone has found an *exploit* based on this, it feels pretty low severity to me.

Neither here nor there, just commenting.

Comment 4 Robin Powell 2023-02-27 15:14:28 UTC
Side comment: for my first attempt at a fix I tried to use the 9.0p1 SRPM plus the 9.2p1 upstream source to make a package.

I now have *deep* respect for the Fedora maintainers of the openssh package.  OMG *so many* patches.  ;_;  Wish you could upstream them, but amazing that you deal with all that!

Comment 5 Fedora Update System 2023-04-14 11:14:35 UTC
FEDORA-2023-123647648e has been submitted as an update to Fedora 38. https://bodhi.fedoraproject.org/updates/FEDORA-2023-123647648e

Comment 6 Fedora Update System 2023-04-14 11:42:08 UTC
FEDORA-2023-1176c8b10c has been submitted as an update to Fedora 37. https://bodhi.fedoraproject.org/updates/FEDORA-2023-1176c8b10c

Comment 7 Dmitry Belyavskiy 2023-04-14 11:46:35 UTC
Fix pushed to f37+

Comment 8 Dmitry Belyavskiy 2023-04-14 11:46:57 UTC
Many thanks for drawing my attention!

Comment 9 Fedora Update System 2023-04-15 01:50:52 UTC
FEDORA-2023-123647648e has been pushed to the Fedora 38 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2023-123647648e`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2023-123647648e

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 10 Fedora Update System 2023-04-15 03:00:14 UTC
FEDORA-2023-1176c8b10c has been pushed to the Fedora 37 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2023-1176c8b10c`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2023-1176c8b10c

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 11 Robin Powell 2023-04-16 18:42:03 UTC
Perhaps you could un-confidential the original report now?  I rather liked it and would like to be able to share it.

Comment 12 Robin Powell 2023-04-16 18:49:27 UTC
Oh, also, the fix totally appears to work, thank you!

Comment 13 Fedora Update System 2023-04-18 01:30:26 UTC
FEDORA-2023-1176c8b10c has been pushed to the Fedora 37 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 14 Fedora Update System 2023-04-19 01:39:14 UTC
FEDORA-2023-123647648e has been pushed to the Fedora 38 stable repository.
If problem still persists, please make note of it in this bug report.