From: "Yoann Congal" <yoann.congal@smile.fr>
To: <vanusuri@mvista.com>, <openembedded-core@lists.openembedded.org>
Subject: Re: [OE-core][wrynose][patch] kbd: Fix CVE-2026-72693
Date: Tue, 08 Sep 2026 16:18:59 +0200 [thread overview]
Message-ID: <DLA00SM0KMT2.1CWHEJAO2J870@smile.fr> (raw)
In-Reply-To: <20260826081324.65559-1-vanusuri@mvista.com>
On Wed Aug 26, 2026 at 10:13 AM CEST, Vijay Anusuri via lists.openembedded.org wrote:
> Pick patch according to [1]
>
> [1] https://security-tracker.debian.org/tracker/CVE-2026-72693
> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-72693
> [3] https://access.redhat.com/security/cve/cve-2026-72693
>
> Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> ---
> .../recipes-core/kbd/kbd/CVE-2026-72693.patch | 155 ++++++++++++++++++
> meta/recipes-core/kbd/kbd_2.9.0.bb | 1 +
> 2 files changed, 156 insertions(+)
> create mode 100644 meta/recipes-core/kbd/kbd/CVE-2026-72693.patch
>
> diff --git a/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch b/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch
> new file mode 100644
> index 0000000000..06b8c195a5
> --- /dev/null
> +++ b/meta/recipes-core/kbd/kbd/CVE-2026-72693.patch
> @@ -0,0 +1,155 @@
> +From 78d5ae119742e87baa7dbe0f5c4107e7533fd698 Mon Sep 17 00:00:00 2001
> +From: Alexey Gladkov <legion@kernel.org>
> +Date: Tue, 12 May 2026 10:20:50 +0200
> +Subject: [PATCH] openvt: make -u process matching more conservative
> +
> +The -u mode relies on the current VT owner to decide which user should
> +be used for the new login session. Make that check stricter by requiring
> +a matching process owner and controlling terminal instead of relying on
> +the ownership of an inherited file descriptor.
> +
> +Also reject root as a pre-authenticated target and document the tighter
> +behavior in the man page.
> +
> +Signed-off-by: Alexey Gladkov <legion@kernel.org>
> +
> +Upstream-Status: Backport [https://github.com/legionus/kbd/commit/78d5ae119742e87baa7dbe0f5c4107e7533fd698]
> +CVE: CVE-2026-72693
> +Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> +---
> + docs/man/man1/openvt.1 | 10 +++++++
> + src/openvt.c | 64 +++++++++++++++++++++++++++++++++++++-----
> + 2 files changed, 67 insertions(+), 7 deletions(-)
> +
> +diff --git a/docs/man/man1/openvt.1 b/docs/man/man1/openvt.1
> +index 8f1244f..404e4a0 100644
> +--- a/docs/man/man1/openvt.1
> ++++ b/docs/man/man1/openvt.1
> +@@ -36,6 +36,8 @@ will be made the new current VT.
> + \fB\-u\fR, \fB\-\-user\fR
> + Figure out the owner of the current VT, and run login as that user.
> + Suitable to be called by init. Shouldn't be used with \fI\-c\fR or \fI\-l\fR.
> ++This option refuses to pre-authenticate root and requires a process owned by
> ++the VT owner whose controlling terminal is the current VT.
> + .TP
> + \fB\-l\fR, \fB\-\-login\fR
> + Make the command a login shell. A \- is prepended to the name of the command
> +@@ -64,6 +66,14 @@ If
> + is compiled with a getopt_long() and you wish to set
> + options to the command to be run, then you must supply
> + the end of options \-\- flag before the command.
> ++.PP
> ++The
> ++.B \-u
> ++option uses
> ++.BR "login -f"
> ++and therefore bypasses normal password authentication for the detected user.
> ++It is intended only for controlled init or keyboard-request configurations.
> ++Use a normal authenticated login command when authentication is required.
> + .SH EXAMPLES
> + .B openvt
> + can be used to start a shell on the next free VT, by using the command:
> +diff --git a/src/openvt.c b/src/openvt.c
> +index a94392b..ddd9239 100644
> +--- a/src/openvt.c
> ++++ b/src/openvt.c
> +@@ -57,6 +57,51 @@ usage(int rc, const struct kbd_help *options)
> + exit(rc);
> + }
> +
> ++static int
> ++proc_pid_stat(const char *pid, uid_t *uid, dev_t *tty)
> ++{
> ++ char filename[NAME_MAX + 12];
> ++ char line[BUFSIZ];
> ++ char *lp, *rp;
> ++ FILE *fp;
> ++ struct stat st;
> ++ long tty_nr;
> ++
> ++ snprintf(filename, sizeof(filename), "/proc/%s/stat", pid);
> ++ fp = fopen(filename, "r");
> ++ if (!fp)
> ++ return -1;
> ++
> ++ if (fstat(fileno(fp), &st)) {
> ++ fclose(fp);
> ++ return -1;
> ++ }
> ++
> ++ if (!fgets(line, sizeof(line), fp)) {
> ++ fclose(fp);
> ++ return -1;
> ++ }
> ++ fclose(fp);
> ++
> ++ rp = strrchr(line, ')');
> ++ if (!rp)
> ++ return -1;
> ++
> ++ /*
> ++ * /proc/<pid>/stat fields after comm are:
> ++ * state ppid pgrp session tty_nr ...
> ++ */
> ++ if (!rp || sscanf(rp + 1, " %*c %*d %*d %*d %ld", &tty_nr) != 1)
> ++ return -1;
> ++
> ++ if (tty_nr <= 0)
> ++ return -1;
> ++
> ++ *uid = st.st_uid;
> ++ *tty = (dev_t) tty_nr;
> ++ return 0;
> ++}
> ++
> + /*
> + * Support for Spawn_Console: openvt running from init
> + * added by Joshua Spoerri, Thu Jul 18 21:13:16 EDT 1996
> +@@ -88,8 +133,7 @@ authenticate_user(int curvt)
> + DIR *dp;
> + struct dirent *dentp;
> + struct stat buf;
> +- dev_t console_dev;
> +- ino_t console_ino;
> ++ dev_t console_rdev;
> + uid_t console_uid;
> + char filename[NAME_MAX + 12];
> + struct passwd *pwnam;
> +@@ -109,10 +153,12 @@ authenticate_user(int curvt)
> + kbd_error(EXIT_FAILURE, errsv, "%s", filename);
> + }
> + }
> +- console_dev = buf.st_dev;
> +- console_ino = buf.st_ino;
> ++ console_rdev = buf.st_rdev;
> + console_uid = buf.st_uid;
> +
> ++ if (console_uid == 0)
> ++ kbd_error(EXIT_FAILURE, 0, _("Refusing to pre-authenticate root on current tty."));
Hello,
Isn't this a change in befavior that might break some use-case?
I don't know how legitimate and/or unsafe it is though...
Do you know?
I'll hold this in the meantime.
Regards,
--
Yoann Congal
Smile ECS
next prev parent reply other threads:[~2026-09-08 14:19 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-26 8:13 [OE-core][wrynose][patch] kbd: Fix CVE-2026-72693 Vijay Anusuri
2026-09-08 14:18 ` Yoann Congal [this message]
2026-09-10 6:29 ` Vijay Anusuri
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DLA00SM0KMT2.1CWHEJAO2J870@smile.fr \
--to=yoann.congal@smile.fr \
--cc=openembedded-core@lists.openembedded.org \
--cc=vanusuri@mvista.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.