Fedora Account System
Red Hat Associate
Red Hat Customer
AI_ONLY_REPORT package: sssd-2.12.0-1.el10 ------ Summary: Local DoS in autofs responder via packet length underflow in `autofs_read_setautomntent_input`: crafted local `SSS_AUTOFS_SETAUTOMNTENT` requests with a declared packet length below the 16-byte header can underflow `blen` and trigger invalid reads that crash or destabilize the autofs responder. Requirements to exploit: A local attacker must be able to connect to the autofs responder UNIX socket and send a malformed `SSS_AUTOFS_SETAUTOMNTENT` request whose declared packet length is smaller than `SSS_NSS_HEADER_SIZE`. Deployments where the autofs responder is disabled or its socket is not reachable to the attacker are not exposed through this path. Component affected: `sssd-2.12.0-1.el10`, autofs responder request parsing in `src/responder/autofs/autofssrv_cmd.c` (`autofs_read_setautomntent_input()`), with related packet length handling in `src/responder/common/responder_packet.c` Version affected: `sssd-2.12.0-1.el10` when the autofs responder is enabled and reachable through its local UNIX socket Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - 6.1 (MEDIUM) AV:L - Exploitation is local through the autofs responder UNIX socket. AC:L - The trigger is a single malformed request with a declared length smaller than the 16-byte header. PR:N - No privileges within the vulnerable component are required beyond being able to open the local responder socket. UI:N - No user interaction is needed. S:U - The impact is limited to the same responder process and security scope. C:N - No confidentiality impact is established. I:N - No integrity impact is established. A:H - Crafted input can terminate or destabilize the autofs responder, causing loss of that service. Impact: Moderate. The available evidence supports a locally reachable denial of service against the autofs responder, but not privilege escalation, confidentiality loss, or integrity compromise. Because the issue is local and exposure depends on the autofs responder being enabled and reachable, this fits Red Hat's Moderate rating more closely than Important. Embargo: no Reason: This is a local, service-scoped denial of service with no demonstrated confidentiality or integrity impact, and there is straightforward mitigation by disabling or restricting the affected responder until a fix is available. Acknowledgement: Aisle Research Vulnerability Details: In `autofs_read_setautomntent_input()`, the request body is used without first ensuring that the computed body length is non-zero and derived from a valid packet length: ```c sss_packet_get_body(pctx->creq->in, &body, &blen); /* if not terminated fail */ if (body[blen - 1] != '\0') { return EINVAL; } /* If the body isn't valid UTF-8, fail */ if (!sss_utf8_check(body, blen - 1)) { return EINVAL; } ``` Here, `blen` is derived as the declared packet length minus `SSS_NSS_HEADER_SIZE`, and the receive path does not reject declared lengths smaller than `SSS_NSS_HEADER_SIZE` before dispatch. If an attacker supplies a packet whose declared length is less than `16` bytes, `blen` wraps to a very large `size_t`. Subsequent use of `body[blen - 1]` and `sss_utf8_check(body, blen - 1)` can then read outside the actual packet buffer and may crash or destabilize the responder. A declared length of exactly `16` produces `blen == 0`; that case still underflows the UTF-8 length argument, but the clearer crash-prone case is a declared length below `16`. Steps to reproduce: 1. Ensure the autofs responder is enabled and its socket is present, typically `/var/lib/sss/pipes/autofs`. 2. Send a crafted 16-byte header whose declared packet length field is `15` and whose command is `0x00D1` (`SSS_AUTOFS_SETAUTOMNTENT`). 3. Run: ```bash python3 - <<'PY' import socket, struct sock = "/var/lib/sss/pipes/autofs" len=15 (<16), cmd=0x00D1, status=0, reserved=0 pkt = struct.pack("<IIII", 15, 0x00D1, 0, 0) s = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM) s.connect(sock) s.sendall(pkt) print("sent") PY ``` 4. Observe responder instability or crash, or an invalid read when tested with ASan/UBSan. The exact manifestation may vary by build and runtime environment. Mitigation: If autofs integration is not required, disable the autofs responder. Otherwise, restrict access to the autofs responder UNIX socket to trusted local users until a fixed package is available. Proposed Fix: Reject undersized packets in the common receive path and reject zero-length autofs request bodies before subtracting `1` from `blen`. ```diff diff --git a/src/responder/common/responder_packet.c b/src/responder/common/responder_packet.c — a/src/responder/common/responder_packet.c +++ b/src/responder/common/responder_packet.c @@ -217,6 +217,10 @@ int sss_packet_recv(struct sss_packet *packet, int fd) new_len = sss_packet_get_len(packet); + if (new_len < SSS_NSS_HEADER_SIZE) { + return EINVAL; + } + if (new_len > packet->memsize) { enum sss_cli_command cmd = sss_packet_get_cmd(packet); size_t max_recv_size; diff --git a/src/responder/autofs/autofssrv_cmd.c b/src/responder/autofs/autofssrv_cmd.c — a/src/responder/autofs/autofssrv_cmd.c +++ b/src/responder/autofs/autofssrv_cmd.c @@ -386,7 +386,7 @@ autofs_read_setautomntent_input(struct cli_ctx *cli_ctx, sss_packet_get_body(pctx->creq->in, &body, &blen); /* if not terminated fail */ if (body[blen - 1] != '\0') { + if (blen == 0 || body[blen - 1] != '\0') { return EINVAL; } ``` ------ This report was generated using AI technology. Always review AI-generated content prior to use