Bug 2479459 (CVE-2026-91142)

Summary: CVE-2026-91142 cockpit: Integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ILP32 builds
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: rhel-process-autobot, sdawley, security-response-team, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileged authenticated user with a specially provisioned large User ID (UID) can cause the computed offset to wrap around. This allows the user to perform unauthorized reads and writes to other users' `lastlog` records, potentially disclosing or altering sensitive login accounting information.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-05-18 04:06:34 UTC
AI_ONLY_REPORT
package: cockpit-356-1.el10
------
Summary: Integer overflow in `do_lastlog()` offset calculation can  
misaddress `lastlog` entries on ILP32 builds: a specially provisioned  
authenticated user can wrap the computed offset and cause cross-user reads  
and writes in legacy `lastlog` records during login accounting.
Requirements to exploit: An authenticated account that can log in through  
Cockpit, a sufficiently large assigned UID to overflow `uid * sizeof(struct  
lastlog)` on an ILP32 build, and a deployment where the `cockpit-session`  
path updates legacy `/var/log/lastlog`.
Component affected: `cockpit-356-1.el10`, `src/session/session-utils.c`,  
`do_lastlog()` in the `cockpit-session` login-accounting path
Version affected: `cockpit-356-1.el10`; reachability is limited to ILP32  
deployments where `cockpit-session` updates legacy `/var/log/lastlog`  
entries
Patch available: no released package fix established; proposed patch  
included below
Version fixed: unknown
Upstream coordination: Not notified.
CVSS: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N - 3.6 (LOW)
AV:L - Exploitation requires control of a locally provisioned account on  
the target system that is permitted to authenticate through Cockpit.
AC:H - Exploitation additionally depends on uncommon but valid  
preconditions: an ILP32 build, legacy `/var/log/lastlog` handling being  
active, and a sufficiently large UID that causes wraparound.
PR:L - The attacker needs a valid low-privilege account.
UI:N - No separate victim interaction is required after the attacker  
authenticates.
S:U - The impact remains within the same system scope that performs  
login accounting.
C:L - A wrapped read can disclose another account's `lastlog` entry.
I:L - A wrapped write can alter another account's `lastlog` entry,  
including the demonstrated UID 0 slot.
A:N - The available evidence shows misaddressed login-accounting data,  
not direct service disruption.
Impact: Low. Based on Red Hat severity guidance, this issue fits Low impact  
because exploitation depends on unlikely but technically valid  
circumstances and the demonstrated consequences are limited to  
confidentiality and integrity of legacy `lastlog` metadata. The available  
evidence does not show code execution, privilege escalation, or broader  
system compromise.
Embargo: no
Reason: The supported impact is low and configuration-dependent, and  
the issue is limited to `lastlog` record disclosure and tampering rather  
than system compromise.
Acknowledgement: Aisle Research
Vulnerability Details: In `do_lastlog()`, the file offset used for both  
`pread()` and `pwrite()` is computed as `uid * sizeof entry` without an  
overflow check or a guaranteed widened intermediate type. On ILP32 builds,  
that multiplication can wrap before being passed as an `off_t`, redirecting  
access to a different user's slot in `/var/log/lastlog`.
```c
r = pread (fd, &entry, sizeof entry, uid * sizeof entry);
...
r = pwrite (fd, &entry, sizeof entry, uid * sizeof entry);
```
For example, when `sizeof(struct lastlog) = 292`, `uid = 1073741824` wraps  
the product to `0`, which targets UID 0's record. The available evidence  
indicates this path is reached from `utmp_log()` during authenticated  
`cockpit-session` login handling, so a successful login by a specially  
provisioned high-UID account can cause cross-user `lastlog` reads and  
writes in privileged session-accounting code.
Steps to reproduce:
1. Use an ILP32 environment, such as a 32-bit userspace/build, where the  
`uid * sizeof entry` multiplication is evaluated in 32-bit width.
2. Ensure Cockpit uses the `cockpit-session` login path and that  
`/var/log/lastlog` exists.
3. Create or identify an account with a UID that causes wraparound, such as  
`1073741824` when `sizeof(struct lastlog) = 292`.
4. Record the current UID 0 entry with `lastlog -u 0`.
5. Log in through Cockpit as the high-UID account.
6. Re-run `lastlog -u 0` and observe that the UID 0 entry changed.
7. Optionally trace `pread()` and `pwrite()` in `do_lastlog()` and confirm  
the wrapped offset, `0` in this example.
Mitigation: If `cockpit-356-1.el10` is deployed in an affected ILP32  
configuration, avoid assigning unusually large UIDs to accounts that can  
authenticate through Cockpit, and restrict such accounts from the  
`cockpit-session` login path until a fix is available.
Proposed Fix: Compute the `lastlog` offset once in checked `off_t` space,  
reject overflow before I/O, and use the verified `offset` for both  
operations.
```diff
diff --git a/src/session/session-utils.c b/src/session/session-utils.c
index XXXXXXX..YYYYYYY 100644
— a/src/session/session-utils.c
+++ b/src/session/session-utils.c
@@ -6,6 +6,7 @@
#include "session-utils.h"
#include "common/cockpitframe.h"
+#include <limits.h>
#include "common/cockpitjsonprint.h"
#include "common/cockpitmemory.h"
@@ -194,6 +195,18 @@ do_lastlog (uid_t                 uid,
bool result = false;
int fd = -1;
ssize_t r;
+  off_t offset;
+
+  if ((uintmax_t) uid > ((uintmax_t) OFF_MAX / (uintmax_t) sizeof entry))
+    {
+      warnx ("uid %u causes lastlog offset overflow", (unsigned) uid);
+      goto out;
+    }
+
+  offset = (off_t) uid * (off_t) sizeof entry;
+  if (offset < 0)
+    goto out;
@@ -207,7 +220,7 @@ do_lastlog (uid_t                 uid,
 r = pread (fd, &entry, sizeof entry, uid * sizeof entry);
+  r = pread (fd, &entry, sizeof entry, offset);
@@ -277,7 +290,7 @@ do_lastlog (uid_t                 uid,

 r = pwrite (fd, &entry, sizeof entry, uid * sizeof entry);
+  r = pwrite (fd, &entry, sizeof entry, offset);
```


------
This report was generated using AI technology. Always review AI-generated  
content prior to use