** Description changed:

  [ Impact ]
  
  There is an issue where sssd-kcm sometimes fails to start and exits with
  status 3 if tgt_renewal = true and krb5_renew_interval are set in the
  config.
  
  When it fails, the logs show:
  "[kcm_set_options] krb5_string_to_deltat failed"
  "Failed setting krb5 options for renewal [12]: Cannot allocate memory"
  
  It doesn't fail every time because it depends on the heap memory state.
  A server might fail on every start, while another identical server
  starts perfectly fine.
  
  The problem is a use-after-free bug. In the code, kcm_read_options()
  returns renew_intv but forgets to use talloc_steal(). Because of this,
  the string gets freed along with tmp_ctx before krb5_string_to_deltat()
  can parse it.
  
  The proposed fix backports upstream commit
  0100b1c3536688c12f1db2a65164f03765727f81, which just changes
  *_renew_intv = renew_intv; to *_renew_intv = talloc_steal(mem_ctx,
  renew_intv); so the memory is kept until it's actually parsed.
  
  [ Test Plan ]
  
  This is easily reproduceable easily as root on a fresh Ubuntu 26.04
  system, or just run docker run --rm -it ubuntu:26.04.
  
  1. Install the packages and create the config:
  
  apt-get update && apt-get install -y sssd-kcm valgrind
  printf '[kcm]\ntgt_renewal = true\nkrb5_renew_interval = 1200s\n' > 
/etc/sssd/conf.d/kcm.conf
  chown -R root:sssd /etc/sssd
  chmod 640 /etc/sssd/conf.d/kcm.conf
  chmod g+x /etc/sssd /etc/sssd/conf.d
  
  2. Run it with MALLOC_PERTURB:
  
  MALLOC_PERTURB_=165 timeout 5 setpriv --reuid=sssd --regid=sssd --clear-
  groups /usr/libexec/sssd/sssd_kcm --logger=stderr -d 0x2f7f0 2>&1 | grep
  -E 'deltat|renew'
  
  It fails and prints the "Cannot allocate memory" errors. (Since it
  depends on heap state, it might not trigger on every single machine, but
  it usually does on a fresh container).
  
  3. Run it with Valgrind (this will catch the bug 100% of the time
  regardless of heap state):
  
  timeout 120 setpriv --reuid=sssd --regid=sssd --clear-groups valgrind
  /usr/libexec/sssd/sssd_kcm --logger=stderr 2>&1 | grep -m1 -A14 'Invalid
  read'
  
  Valgrind shows a memory error: "Invalid read of size 1 ... by
  krb5_string_to_deltat ... Address ... is 96 bytes inside a block of size
  102 free'd".
  
+ [ Where problems could occur ]
+ 
+ This change affects the lifetime of the krb5_renew_interval string. The 
string now survives temporary-context cleanup, thus an invalid interval 
previously
+ masked by the use-after-free may now consistently cause renewal configuration
+ to fail.
+ 
  [ Other Info ]
  
  Upstream commit:
  https://github.com/SSSD/sssd/commit/0100b1c3536688c12f1db2a65164f03765727f81
  (this is already in versions 2.13.0).
  
  Right now both resolute (2.12.0-1ubuntu5.4) and stonking
  (2.12.0-4ubuntu3) are missing the fix.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169162

Title:
  sssd-kcm fails to start due to use-after-free with krb5_renew_interval

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/sssd/+bug/2169162/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to