mirror of
git://sourceware.org/git/glibc.git
synced 2026-09-08 23:58:31 +08:00
For AT_SECURE programs the loader honors $ORIGIN in DT_RPATH only when the expansion is rooted in a trusted directory, but it validated the lexically normalized path while opening the raw expansion. As "a/b/../c" only names "a/c" when "b" is not a symlink, an attacker who controls a component of $ORIGIN -- e.g. by hard-linking the setuid binary into an attacker-owned directory -- can make the opened path escape the trusted directory even though the check passed, loading an attacker-controlled object. Normalize the expansion in place and open that, so the path that is opened is exactly the path that was validated. _dl_normalize_path rewrites the string in place without ever advancing its write cursor past its read cursor or appending, so it stays within the original storage. Add elf/tst-origin-secure as a regression test. Reviewed-by: Florian Weimer <fweimer@redhat.com>
29 lines
1.1 KiB
C
29 lines
1.1 KiB
C
/* Module for tst-origin-secure (the attacker-controlled copy).
|
|
Copyright (C) 2026 Free Software Foundation, Inc.
|
|
This file is part of the GNU C Library.
|
|
|
|
The GNU C Library is free software; you can redistribute it and/or
|
|
modify it under the terms of the GNU Lesser General Public
|
|
License as published by the Free Software Foundation; either
|
|
version 2.1 of the License, or (at your option) any later version.
|
|
|
|
The GNU C Library is distributed in the hope that it will be useful,
|
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
Lesser General Public License for more details.
|
|
|
|
You should have received a copy of the GNU Lesser General Public
|
|
License along with the GNU C Library; if not, see
|
|
<https://www.gnu.org/licenses/>. */
|
|
|
|
#include "tst-origin-secure.h"
|
|
|
|
/* If the victim reports this copy, the loader opened the un-normalized rpath
|
|
and resolved it through the attacker's symlink -- i.e. the trusted-path
|
|
check was bypassed (bug 34360). */
|
|
int
|
|
origin_secure_id (void)
|
|
{
|
|
return ORIGIN_SECURE_ID_ATTACKER;
|
|
}
|