Daniel P. Berrangé d61e24
From 8c2c611df31d3b37f149385e4597c47300ae1489 Mon Sep 17 00:00:00 2001
Daniel P. Berrangé d61e24
From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= <berrange@redhat.com>
Daniel P. Berrangé d61e24
Date: Tue, 30 Apr 2019 16:51:37 +0100
Daniel P. Berrangé d61e24
Subject: [PATCH 2/3] locking: restrict sockets to mode 0600
Daniel P. Berrangé d61e24
MIME-Version: 1.0
Daniel P. Berrangé d61e24
Content-Type: text/plain; charset=UTF-8
Daniel P. Berrangé d61e24
Content-Transfer-Encoding: 8bit
Daniel P. Berrangé d61e24
Daniel P. Berrangé d61e24
The virtlockd daemon's only intended client is the libvirtd daemon. As
Daniel P. Berrangé d61e24
such it should never allow clients from other user accounts to connect.
Daniel P. Berrangé d61e24
The code already enforces this and drops clients from other UIDs, but
Daniel P. Berrangé d61e24
we can get earlier (and thus stronger) protection against DoS by setting
Daniel P. Berrangé d61e24
the socket permissions to 0600
Daniel P. Berrangé d61e24
Daniel P. Berrangé d61e24
Fixes CVE-2019-10132
Daniel P. Berrangé d61e24
Daniel P. Berrangé d61e24
Reviewed-by: Ján Tomko <jtomko@redhat.com>
Daniel P. Berrangé d61e24
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
Daniel P. Berrangé d61e24
(cherry picked from commit f111e09468693909b1f067aa575efdafd9a262a1)
Daniel P. Berrangé d61e24
---
Daniel P. Berrangé d61e24
 src/locking/virtlockd-admin.socket.in | 1 +
Daniel P. Berrangé d61e24
 src/locking/virtlockd.socket.in       | 1 +
Daniel P. Berrangé d61e24
 2 files changed, 2 insertions(+)
Daniel P. Berrangé d61e24
Daniel P. Berrangé d61e24
diff --git a/src/locking/virtlockd-admin.socket.in b/src/locking/virtlockd-admin.socket.in
Daniel P. Berrangé d61e24
index 2a7500f3d0..f674c492f7 100644
Daniel P. Berrangé d61e24
--- a/src/locking/virtlockd-admin.socket.in
Daniel P. Berrangé d61e24
+++ b/src/locking/virtlockd-admin.socket.in
Daniel P. Berrangé d61e24
@@ -5,6 +5,7 @@ Before=libvirtd.service
Daniel P. Berrangé d61e24
 [Socket]
Daniel P. Berrangé d61e24
 ListenStream=@localstatedir@/run/libvirt/virtlockd-admin-sock
Daniel P. Berrangé d61e24
 Service=virtlockd.service
Daniel P. Berrangé d61e24
+SocketMode=0600
Daniel P. Berrangé d61e24
 
Daniel P. Berrangé d61e24
 [Install]
Daniel P. Berrangé d61e24
 WantedBy=sockets.target
Daniel P. Berrangé d61e24
diff --git a/src/locking/virtlockd.socket.in b/src/locking/virtlockd.socket.in
Daniel P. Berrangé d61e24
index 45e0f20235..d701b27516 100644
Daniel P. Berrangé d61e24
--- a/src/locking/virtlockd.socket.in
Daniel P. Berrangé d61e24
+++ b/src/locking/virtlockd.socket.in
Daniel P. Berrangé d61e24
@@ -4,6 +4,7 @@ Before=libvirtd.service
Daniel P. Berrangé d61e24
 
Daniel P. Berrangé d61e24
 [Socket]
Daniel P. Berrangé d61e24
 ListenStream=@localstatedir@/run/libvirt/virtlockd-sock
Daniel P. Berrangé d61e24
+SocketMode=0600
Daniel P. Berrangé d61e24
 
Daniel P. Berrangé d61e24
 [Install]
Daniel P. Berrangé d61e24
 WantedBy=sockets.target
Daniel P. Berrangé d61e24
-- 
Daniel P. Berrangé d61e24
2.21.0
Daniel P. Berrangé d61e24