Bug 1695963 (CVE-2019-12439) - CVE-2019-12439 bubblewrap: temporary directory misuse as mount point
Summary: CVE-2019-12439 bubblewrap: temporary directory misuse as mount point
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2019-12439
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1695964 1695965 1697974 1712029 1724905
Blocks: 1695966
TreeView+ depends on / blocked
 
Reported: 2019-04-04 00:11 UTC by Pedro Sampaio
Modified: 2021-02-16 22:09 UTC (History)
21 users (show)

Fixed In Version: bubblewrap 0.3.3
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-07-24 19:18:18 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2019:1833 0 None None None 2019-07-24 13:38:51 UTC

Description Pedro Sampaio 2019-04-04 00:11:27 UTC
Is /run/user/<UID>/.bubblewrap/ doesn't exist and couldn't be created 
(as was the case on my system), bubblewrap falls back to 
/tmp/.bubblewrap-<UID>/. Local attacker could exploit this to prevent 
other users from running bubblewrap, for example:

  getent passwd | cut -d: -f3 | xargs printf '/tmp/.bubblewrap-%d\n' | xargs touch

But it gets worse, because bubblewrap is happy to use existing 
/tmp/.bubblewrap-<UID>/, even when the directory is owned by some else. 
In the worst case, this could be exploited by a local user to execute 
arbitrary code in the container. (Though I couldn't find any way to 
exploit this without disabling protected_symlinks.)

Upstream issue:

https://github.com/projectatomic/bubblewrap/issues/304

Comment 1 Pedro Sampaio 2019-04-04 00:12:20 UTC
Created bubblewrap tracking bugs for this issue:

Affects: epel-7 [bug 1695965]
Affects: fedora-all [bug 1695964]

Comment 3 Elijah DeLee 2019-05-01 13:49:57 UTC
Github release https://github.com/projectatomic/bubblewrap/releases/tag/v0.3.3 just went out with the bugfix for https://github.com/projectatomic/bubblewrap/issues/304

RPM build is pending on bohdi now: https://bodhi.fedoraproject.org/updates/bubblewrap-0.3.3-2.el7

Comment 6 Bill Nottingham 2019-05-02 15:02:53 UTC
(In reply to Borja Tarraso from comment #5)
> Statement:
> 
> Tower is not affected since systemd-logind is used by default and the UID
> under /run/user/ is pre-created before bubblewrap service starts.

This is incorrect; the system user using bubblewrap is not using a login session.

That being said, it would require local system access to try to exploit, which the vast majority of users should not have.

Comment 8 Riccardo Schirone 2019-05-20 14:57:14 UTC
Setting Attack Complexity(AC) to High(H) as for an attack to be successful fs.protected_symlinks sysctl should be 0, which is not the case by default on Red Hat Enterprise Linux.

Comment 10 Riccardo Schirone 2019-05-21 13:21:47 UTC
The attack also requires the path /run/user/<uid>/.bubblewrap to not exist, to be inaccessible or the program to fail when trying to create it. Normally, this directory either already exists or it is under the user control and it can be safely created by bubblewrap.

Comment 13 Doran Moppert 2019-06-28 04:17:40 UTC
Statement:

This flaw requires a local user account to exploit. Since local users without root privileges are not supported on Red Had CloudForms, or on Red Hat Ansible Tower, this vulnerability is rated Low severity on these products.  Future updates may address this vulnerability.

Comment 14 Doran Moppert 2019-06-28 04:17:43 UTC
Mitigation:

The default setting of `fs.protected_symlinks = 1` prevents any Confidentiality or Integrity impact from exploiting this vulnerability, reducing its rating to Low severity (4.7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).

Comment 16 errata-xmlrpc 2019-07-24 13:38:49 UTC
This issue has been addressed in the following products:

  CloudForms Management Engine 5.10

Via RHSA-2019:1833 https://access.redhat.com/errata/RHSA-2019:1833

Comment 17 Product Security DevOps Team 2019-07-24 19:18:18 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-12439


Note You need to log in before you can comment on or make changes to this bug.