correspondence2--- via Bug reports for the GNU Bourne Again SHell 
<[email protected]> writes:

> Dear GNU Bash Maintainers,
>
> I am writing to report a security vulnerability in the GNU Bash shell.
>
> SUMMARY
> ========
> The alrm_catcher() function in eval.c (lines 154-161) is called from the
> SIGALRM signal handler context but performs operations that are not
> async-signal-safe according to POSIX standards.
>
> DETAILS
> =======
> The vulnerable code:
>
> static sighandler
> alrm_catcher(i)
>      int i;
> {
>   printf (_("\007timed out waiting for input: auto-logout\n"));
>   fflush (stdout);
>   bash_logout ();       /* run ~/.bash_logout if this is a login shell */
>   jump_to_top_level (EXITPROG);
>   SIGRETURN (0);
> }
>
> This calls:
> 1. printf() - Not async-signal-safe
> 2. fflush() - Not async-signal-safe
> 3. bash_logout() - Executes arbitrary user scripts (not async-safe)

How is that different from just letting the process exit otherwise?
~/.bash_logout will be used either way. If a process writes to arbitrary
bash init files, then all bets are off.

The signal handler should be made async-safe, but I don't think there's
any vulnerability here.

> 4. jump_to_top_level() - Longjmp in signal context
>
> IMPACT
> ======
> - Arbitrary code execution (via bash_logout)
> - Heap corruption (via printf)
> - Deadlocks (via fflush)
> - State corruption (via longjmp)
>
> CVSS Score: 7.8 (HIGH)
>
> Proof of Concept:
>
>    #!/bin/bash
>    # ================================================================
>    # MINIMAL POC: alrm_catcher Vulnerability
>    # ================================================================
>    # This is the smallest possible test to confirm the vulnerability.
>    # ================================================================
>    echo "[*] Creating malicious bash_logout..."
>    cat > ~/.bash_logout << 'EOF'
>    #!/bin/bash
>    echo "====== EXPLOIT EXECUTED FROM SIGNAL HANDLER ======"
>    echo "This proves arbitrary code execution!"
>    echo "Time: $(date)" > /tmp/poc_proof.txt
>    echo "User: $(whoami)" >> /tmp/poc_proof.txt
>    echo "PID: $$" >> /tmp/poc_proof.txt
>    EOF
>    chmod +x ~/.bash_logout
>    echo "[*] Triggering alarm..."
>    export SHLVL=2
>    export TMOUT=1
>    sleep 2
>    echo ""
>    echo "[*] Checking results..."
>    if [ -f /tmp/poc_proof.txt ]; then
>        echo "[+] SUCCESS! Vulnerability confirmed!"
>        echo "Proof contents:"
>        cat /tmp/poc_proof.txt
>    else
>        echo "[-] Exploit failed (not a login shell?)"
>    fi
>    echo "[*] Cleaning up..."
>    rm -f ~/.bash_logout
>    rm -f /tmp/poc_proof.txt
>    echo "[*] Done"
> MITIGATION
> ==========
> Replace alrm_catcher() with a flag-based approach:
>
> static volatile sig_atomic_t alarm_triggered = 0;
>
> static sighandler alrm_catcher_safe(i)
> {
>     alarm_triggered = 1;
> }
>
> // In main loop:
> if (alarm_triggered) {
>     alarm_triggered = 0;
>     printf(_("\007timed out waiting for input: auto-logout\n"));
>     fflush(stdout);
>     bash_logout();
>     jump_to_top_level(EXITPROG);
> }
>
> I am happy to assist with any additional information or testing.
> Please use this email to contact me back, I want a CVE.
>
> Sincerely,
> Ali

Attachment: signature.asc
Description: PGP signature

  • [SECURIT... correspondence2--- via Bug reports for the GNU Bourne Again SHell

Reply via email to