Blame SOURCES/CVE-2022-0492.patch

2a2517
From d6dc1581c25221b17e1447f5eea0ee156a69e986 Mon Sep 17 00:00:00 2001
2a2517
From: Joe Lawrence <joe.lawrence@redhat.com>
2a2517
Date: Fri, 25 Mar 2022 14:49:39 -0400
2a2517
Subject: [KPATCH CVE-2022-0492] cgroup-v1: kpatch fixes for CVE-2022-0492
2a2517
Content-type: text/plain
2a2517
2a2517
Kernels:
2a2517
3.10.0-1160.24.1.el7
2a2517
3.10.0-1160.25.1.el7
2a2517
3.10.0-1160.31.1.el7
2a2517
3.10.0-1160.36.2.el7
2a2517
3.10.0-1160.41.1.el7
2a2517
3.10.0-1160.42.2.el7
2a2517
3.10.0-1160.45.1.el7
2a2517
3.10.0-1160.49.1.el7
2a2517
3.10.0-1160.53.1.el7
2a2517
3.10.0-1160.59.1.el7
2a2517
2a2517
Changes since last build:
2a2517
arches: x86_64 ppc64le
2a2517
cgroup.o: changed function: cgroup_release_agent_write
2a2517
cgroup.o: changed function: parse_cgroupfs_options
2a2517
---------------------------
2a2517
2a2517
Kpatch-MR: https://gitlab.com/redhat/prdsc/rhel/src/kpatch/rhel-7/-/merge_requests/36
2a2517
Approved-by: Yannick Cote (@ycote1)
2a2517
Modifications: none
2a2517
2a2517
commit a1d7f90e939b5ca2fddb1e295c6cf8bfb97a69f0
2a2517
Author: Waiman Long <longman@redhat.com>
2a2517
Date:   Wed Feb 9 09:23:49 2022 -0500
2a2517
2a2517
    cgroup-v1: Require capabilities to set release_agent
2a2517
2a2517
    Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=2052162
2a2517
    CVE: CVE-2022-0492
2a2517
    Conflicts:
2a2517
     1) For RHEL7, the right file to be modified is kernel/cgroup.c.
2a2517
     2) The cgroup filesystem files in RHEL7 are created via direct
2a2517
        manipulation of dentries and inode and credential at the time of
2a2517
        creation are not stored. So the init_user_ns comparison check in
2a2517
        the upstream commit isn't applicable. It is also less important
2a2517
        and so the checks are dropped.
2a2517
     3) The cgroup mount parameter parsing is done in
2a2517
        parse_cgroupfs_options() instead.
2a2517
2a2517
    commit 24f6008564183aa120d07c03d9289519c2fe02af
2a2517
    Author: Eric W. Biederman <ebiederm@xmission.com>
2a2517
    Date:   Thu, 20 Jan 2022 11:04:01 -0600
2a2517
2a2517
        cgroup-v1: Require capabilities to set release_agent
2a2517
2a2517
        The cgroup release_agent is called with call_usermodehelper.  The function
2a2517
        call_usermodehelper starts the release_agent with a full set fo capabilities.
2a2517
        Therefore require capabilities when setting the release_agaent.
2a2517
2a2517
        Reported-by: Tabitha Sable <tabitha.c.sable@gmail.com>
2a2517
        Tested-by: Tabitha Sable <tabitha.c.sable@gmail.com>
2a2517
        Fixes: 81a6a5cdd2c5 ("Task Control Groups: automatic userspace notification of idle cgroups")
2a2517
        Cc: stable@vger.kernel.org # v2.6.24+
2a2517
        Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
2a2517
        Signed-off-by: Tejun Heo <tj@kernel.org>
2a2517
2a2517
    Signed-off-by: Waiman Long <longman@redhat.com>
2a2517
2a2517
Signed-off-by: Joe Lawrence <joe.lawrence@redhat.com>
2a2517
---
2a2517
 kernel/cgroup.c | 15 +++++++++++++++
2a2517
 1 file changed, 15 insertions(+)
2a2517
2a2517
diff --git a/kernel/cgroup.c b/kernel/cgroup.c
2a2517
index 4777d5bc3142..e4138e5a7879 100644
2a2517
--- a/kernel/cgroup.c
2a2517
+++ b/kernel/cgroup.c
2a2517
@@ -1149,6 +1149,13 @@ static int parse_cgroupfs_options(char *data, struct cgroup_sb_opts *opts)
2a2517
 			/* Specifying two release agents is forbidden */
2a2517
 			if (opts->release_agent)
2a2517
 				return -EINVAL;
2a2517
+			/*
2a2517
+			 * Release agent gets called with all capabilities,
2a2517
+			 * require capabilities to set release agent.
2a2517
+			 */
2a2517
+			if (!capable(CAP_SYS_ADMIN))
2a2517
+				return -EPERM;
2a2517
+
2a2517
 			opts->release_agent =
2a2517
 				kstrndup(token + 14, PATH_MAX - 1, GFP_KERNEL);
2a2517
 			if (!opts->release_agent)
2a2517
@@ -2196,6 +2203,14 @@ static int cgroup_release_agent_write(struct cgroup *cgrp, struct cftype *cft,
2a2517
 	BUILD_BUG_ON(sizeof(cgrp->root->release_agent_path) < PATH_MAX);
2a2517
 	if (strlen(buffer) >= PATH_MAX)
2a2517
 		return -EINVAL;
2a2517
+
2a2517
+	/*
2a2517
+	 * Release agent gets called with all capabilities,
2a2517
+	 * require capabilities to set release agent.
2a2517
+	 */
2a2517
+	if (!capable(CAP_SYS_ADMIN))
2a2517
+		return -EPERM;
2a2517
+
2a2517
 	if (!cgroup_lock_live_group(cgrp))
2a2517
 		return -ENODEV;
2a2517
 	mutex_lock(&cgroup_root_mutex);
2a2517
-- 
2a2517
2.26.3
2a2517
2a2517