Fedora Account System
Red Hat Associate
Red Hat Customer
AI_ONLY_REPORT package: cockpit-356-1.el10 ------ Summary: Integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ILP32 builds: a specially provisioned authenticated user can wrap the computed offset and cause cross-user reads and writes in legacy `lastlog` records during login accounting. Requirements to exploit: An authenticated account that can log in through Cockpit, a sufficiently large assigned UID to overflow `uid * sizeof(struct lastlog)` on an ILP32 build, and a deployment where the `cockpit-session` path updates legacy `/var/log/lastlog`. Component affected: `cockpit-356-1.el10`, `src/session/session-utils.c`, `do_lastlog()` in the `cockpit-session` login-accounting path Version affected: `cockpit-356-1.el10`; reachability is limited to ILP32 deployments where `cockpit-session` updates legacy `/var/log/lastlog` entries Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N - 3.6 (LOW) AV:L - Exploitation requires control of a locally provisioned account on the target system that is permitted to authenticate through Cockpit. AC:H - Exploitation additionally depends on uncommon but valid preconditions: an ILP32 build, legacy `/var/log/lastlog` handling being active, and a sufficiently large UID that causes wraparound. PR:L - The attacker needs a valid low-privilege account. UI:N - No separate victim interaction is required after the attacker authenticates. S:U - The impact remains within the same system scope that performs login accounting. C:L - A wrapped read can disclose another account's `lastlog` entry. I:L - A wrapped write can alter another account's `lastlog` entry, including the demonstrated UID 0 slot. A:N - The available evidence shows misaddressed login-accounting data, not direct service disruption. Impact: Low. Based on Red Hat severity guidance, this issue fits Low impact because exploitation depends on unlikely but technically valid circumstances and the demonstrated consequences are limited to confidentiality and integrity of legacy `lastlog` metadata. The available evidence does not show code execution, privilege escalation, or broader system compromise. Embargo: no Reason: The supported impact is low and configuration-dependent, and the issue is limited to `lastlog` record disclosure and tampering rather than system compromise. Acknowledgement: Aisle Research Vulnerability Details: In `do_lastlog()`, the file offset used for both `pread()` and `pwrite()` is computed as `uid * sizeof entry` without an overflow check or a guaranteed widened intermediate type. On ILP32 builds, that multiplication can wrap before being passed as an `off_t`, redirecting access to a different user's slot in `/var/log/lastlog`. ```c r = pread (fd, &entry, sizeof entry, uid * sizeof entry); ... r = pwrite (fd, &entry, sizeof entry, uid * sizeof entry); ``` For example, when `sizeof(struct lastlog) = 292`, `uid = 1073741824` wraps the product to `0`, which targets UID 0's record. The available evidence indicates this path is reached from `utmp_log()` during authenticated `cockpit-session` login handling, so a successful login by a specially provisioned high-UID account can cause cross-user `lastlog` reads and writes in privileged session-accounting code. Steps to reproduce: 1. Use an ILP32 environment, such as a 32-bit userspace/build, where the `uid * sizeof entry` multiplication is evaluated in 32-bit width. 2. Ensure Cockpit uses the `cockpit-session` login path and that `/var/log/lastlog` exists. 3. Create or identify an account with a UID that causes wraparound, such as `1073741824` when `sizeof(struct lastlog) = 292`. 4. Record the current UID 0 entry with `lastlog -u 0`. 5. Log in through Cockpit as the high-UID account. 6. Re-run `lastlog -u 0` and observe that the UID 0 entry changed. 7. Optionally trace `pread()` and `pwrite()` in `do_lastlog()` and confirm the wrapped offset, `0` in this example. Mitigation: If `cockpit-356-1.el10` is deployed in an affected ILP32 configuration, avoid assigning unusually large UIDs to accounts that can authenticate through Cockpit, and restrict such accounts from the `cockpit-session` login path until a fix is available. Proposed Fix: Compute the `lastlog` offset once in checked `off_t` space, reject overflow before I/O, and use the verified `offset` for both operations. ```diff diff --git a/src/session/session-utils.c b/src/session/session-utils.c index XXXXXXX..YYYYYYY 100644 — a/src/session/session-utils.c +++ b/src/session/session-utils.c @@ -6,6 +6,7 @@ #include "session-utils.h" #include "common/cockpitframe.h" +#include <limits.h> #include "common/cockpitjsonprint.h" #include "common/cockpitmemory.h" @@ -194,6 +195,18 @@ do_lastlog (uid_t uid, bool result = false; int fd = -1; ssize_t r; + off_t offset; + + if ((uintmax_t) uid > ((uintmax_t) OFF_MAX / (uintmax_t) sizeof entry)) + { + warnx ("uid %u causes lastlog offset overflow", (unsigned) uid); + goto out; + } + + offset = (off_t) uid * (off_t) sizeof entry; + if (offset < 0) + goto out; @@ -207,7 +220,7 @@ do_lastlog (uid_t uid, r = pread (fd, &entry, sizeof entry, uid * sizeof entry); + r = pread (fd, &entry, sizeof entry, offset); @@ -277,7 +290,7 @@ do_lastlog (uid_t uid, r = pwrite (fd, &entry, sizeof entry, uid * sizeof entry); + r = pwrite (fd, &entry, sizeof entry, offset); ``` ------ This report was generated using AI technology. Always review AI-generated content prior to use