Bug 2537074

Summary: CVE-2026-92745 cockpit-machines: cockpit-machines: Information Disclosure of RHSM Offline Token via Process Arguments [fedora-all]
Product: [Fedora] Fedora Reporter: Marco Benatto <mbenatto>
Component: cockpit-machinesAssignee: Katerina Koukiou <kkoukiou>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: rawhideCC: jvanderwaa, kkoukiou, martin, mmarusak, tmatus
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["cfc5f4bd-8050-4fc2-8bdd-324f35cb7543"]}
Fixed In Version: cockpit-machines-357-1.fc45 cockpit-machines-357-1.fc44 cockpit-machines-357-1.fc43 Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-10-03 00:21:42 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2476266    

Description Marco Benatto 2026-09-18 19:19:14 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

AI_ONLY_REPORT
package: cockpit-machines-348-1.el10
------
Summary: RHSM Offline Token Exposure via Process Arguments in  
`getAccessToken()` (CWE-214): the package passes the RHSM offline token to  
a helper via argv, allowing local disclosure through process metadata while  
token validation is running.
Requirements to exploit: An attacker needs local access to the host running  
Cockpit Machines, the ability to inspect another user's process metadata  
while the RHSM token-validation flow is active, and a deployment without  
`/proc` visibility restrictions that would otherwise block command-line  
inspection.
Component affected: `cockpit-machines`; `src/libvirtApi/rhel-images.ts`  
`getAccessToken()`; `src/scripts/rhsm/get_access_token.py`
Version affected: `cockpit-machines-348-1.el10`
Patch available: no released package fix established; proposed patch  
included below
Version fixed: unknown
Upstream coordination: Not notified.
CVSS: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N - 4.7 (MEDIUM)
AV:L - Exploitation requires local access to the host where Cockpit  
Machines is running.
AC:L - On systems without restrictive `/proc` settings, observing helper  
command lines is straightforward once the process starts.
PR:L - A low-privileged local account is sufficient to inspect process  
metadata in affected configurations.
UI:R - A user must trigger the RHSM offline-token validation flow so the  
helper process is spawned with the secret in argv.
S:U - The impact stays within the same security scope.
C:H - The exposed value is a sensitive RHSM offline token that can be  
used to request access tokens.
I:N - This issue does not directly alter data or system state.
A:N - This issue does not directly reduce service availability.
Impact: Moderate. This issue can expose a high-value credential and  
therefore compromise confidentiality, but exploitation is local,  
timing-sensitive, and dependent on process-visibility configuration. Under  
Red Hat's severity guidance, that fits a confidentiality compromise that is  
real but less easily exploited than an Important issue.
Embargo: no
Reason: This is a local information disclosure issue with  
configuration-dependent exploitability and a straightforward remediation  
path. It does not present the kind of remotely exploitable or rapidly  
weaponizable condition that typically warrants embargo.
Acknowledgement: Aisle Research
Vulnerability Details: The RHSM offline token is serialized into JSON and  
passed to a Python helper as a command-line argument. The helper then reads  
the secret from `sys.argv[1]` and uses it as the `refresh_token` parameter  
when requesting an access token:
```ts
export function getAccessToken(offlineToken: string): cockpit.Spawn<string>  
{
logDebug(`Get access token`);
const arg = JSON.stringify({ offlineToken });
return python.spawn(getAccessTokenScript, [arg], { err: "message",  
environ: ['LC_ALL=C.UTF-8'] });
}
```
```py
args = json.loads(sys.argv[1], strict=False)
data = {
"grant_type": "refresh_token",
"client_id": "rhsm-api",
"refresh_token": args["offlineToken"]
}
```
Because the secret is present in argv, it can be exposed through process  
metadata such as `ps`, `pgrep -af`, or `/proc/<pid>/cmdline` while the  
helper is running. Reachability from the UI is direct through the Create VM  
RHEL download/token-validation flow. This is a local disclosure issue  
rather than a remote compromise; its practical exploitability depends on  
whether another local user can inspect that process metadata on the host.
Steps to reproduce:
1. Start Cockpit Machines and open the Create VM flow.
2. Select `Download an OS` and choose a RHEL entry that requires an RHSM  
offline token.
3. Paste a valid or invalid offline token so the validation flow calls  
`getAccessToken()`.
4. From a second local shell on the same host, monitor the helper command  
line:
```bash
while true; do pgrep -af get_access_token.py; sleep 0.1; done
```
5. Observe that the helper process command line contains JSON with the  
`offlineToken` value.
If the host enforces restrictive `/proc` visibility settings such as  
`hidepid`, cross-user observation may be blocked. That limits  
exploitability, but it does not change the underlying secret-on-argv  
behavior.
Mitigation: Until a fixed build is available, avoid validating RHSM offline  
tokens through this flow on shared systems where untrusted local users can  
inspect process metadata. Restrict `/proc` visibility so unprivileged users  
cannot view other users' command lines.
Proposed Fix: Do not pass the offline token in argv. Spawn the helper  
without secret-bearing arguments and send the JSON payload over stdin  
instead.
```diff
diff --git a/src/libvirtApi/rhel-images.ts b/src/libvirtApi/rhel-images.ts
@@
export function getAccessToken(offlineToken: string):  
cockpit.Spawn<string> {
logDebug(`Get access token`);
   const arg = JSON.stringify({ offlineToken });

   return python.spawn(getAccessTokenScript, [arg], { err: "message",  
environ: ['LC_ALL=C.UTF-8'] });
+    const proc = python.spawn(getAccessTokenScript, [], { err: "message",  
environ: ['LC_ALL=C.UTF-8'] });
+    proc.input(JSON.stringify({ offlineToken }));
+    return proc;
  }
diff --git a/src/scripts/rhsm/get_access_token.py  
b/src/scripts/rhsm/get_access_token.py
@@
-args = json.loads(sys.argv[1], strict=False)
+args = json.loads(sys.stdin.read(), strict=False)
```


------
This report was generated using AI technology. Always review AI-generated  
content prior to use

Comment 1 Fedora Update System 2026-09-24 08:34:24 UTC
FEDORA-2026-2afda0f514 (cockpit-machines-357-1.fc45) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-2afda0f514

Comment 2 Fedora Update System 2026-09-24 08:35:12 UTC
FEDORA-2026-57e39fc2fa (cockpit-machines-357-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-57e39fc2fa

Comment 3 Fedora Update System 2026-09-24 08:35:42 UTC
FEDORA-2026-4923296720 (cockpit-machines-357-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-4923296720

Comment 4 Fedora Update System 2026-10-03 00:21:42 UTC
FEDORA-2026-2afda0f514 (cockpit-machines-357-1.fc45) has been pushed to the Fedora 45 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 5 Fedora Update System 2026-10-03 01:11:03 UTC
FEDORA-2026-57e39fc2fa (cockpit-machines-357-1.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 6 Fedora Update System 2026-10-03 01:34:55 UTC
FEDORA-2026-4923296720 (cockpit-machines-357-1.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.