From nobody Sat Jul 25 15:51:07 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) client-ip=38.145.34.151; envelope-from=devel-bounces@lists.libvirt.org; helo=lists.libvirt.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass(p=reject dis=none) header.from=lists.libvirt.org ARC-Seal: i=1; a=rsa-sha256; t=1784206287; cv=none; d=zohomail.com; s=zohoarc; b=NMrOpR8wqe30zZTaZv1Fuyf587SuCfG819ERKPDAfPt5BxWUYPiGcLmcM/yfAG3CgNc4SmvorR1xfcuve4h3ThQ9+KoEfPwvm6mjG6Kkcdnrxl9YO7Sxm9qOps6E7xvzT+ghDZMIIkxqNffg9pXBE19UikHYc6jeGJlGnqhqF9M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784206287; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Owner:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:Reply-To:Subject:Subject:To:To:Message-Id; bh=X1GY+1TAN+zwGeyniBXnhp83gj8lFz78+qxlMDmyGQ8=; b=hcKAINtZNhau2V3mCnM/UNMT3LBXavdOLec7xpr6CmPcSxewXdVy6obBDHTsTWApU3Tsr6eGZrk1Kxup77yNpIg6Xx+idbFIgR3xx0+LFOtjKXj83DuuxkHfN7Nqnc67bJ7u0iIWJw+ctJ4GYFePo9996haI/12Eimdm9BjdmKQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.libvirt.org (lists.libvirt.org [38.145.34.151]) by mx.zohomail.com with SMTPS id 178420628725341.930121016009366; Thu, 16 Jul 2026 05:51:27 -0700 (PDT) Received: by lists.libvirt.org (Postfix, from userid 993) id CC3CF41BA5; Thu, 16 Jul 2026 08:51:25 -0400 (EDT) Received: from [172.19.199.10] (unknown [10.16.107.18]) by lists.libvirt.org (Postfix) with ESMTP id CB49F41E13; Thu, 16 Jul 2026 08:50:22 -0400 (EDT) Received: by lists.libvirt.org (Postfix, from userid 993) id EC95341AEE; Thu, 16 Jul 2026 08:50:14 -0400 (EDT) Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (3072 bits) server-digest SHA256) (No client certificate requested) by lists.libvirt.org (Postfix) with ESMTPS id C12A641AF6 for ; Thu, 16 Jul 2026 08:50:13 -0400 (EDT) Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-70-JNhDydx6MoC2A70aXZmoXw-1; Thu, 16 Jul 2026 08:50:12 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 0598B1954231; Thu, 16 Jul 2026 12:50:11 +0000 (UTC) Received: from berrange.com (unknown [10.44.34.221]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id B1D1C1955F78; Thu, 16 Jul 2026 12:50:09 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on lists.libvirt.org X-Spam-Level: X-Spam-Status: No, score=0.6 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,MAILING_LIST_MULTI,RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL,RCVD_IN_SBL_CSS,SPF_HELO_PASS autolearn=no autolearn_force=no version=4.0.1 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784206213; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=X1GY+1TAN+zwGeyniBXnhp83gj8lFz78+qxlMDmyGQ8=; b=APwXVZDoUn72v9/u8zzzA1efGi5WXuLTjdcLc15dw1QNl6TLNOWTEEGEXW+GwR4YniZX6F lCynXq9QM/dzTuRbADM54Kgye0+o2DYo2gLX6Z7tzIrX/JpQLtdpbLNaZ4QwdPZ3ZIDteH YLk4CNXFDvIvJ1J4L8wAkUtFW2dWmGY= X-MC-Unique: JNhDydx6MoC2A70aXZmoXw-1 X-Mimecast-MFC-AGG-ID: JNhDydx6MoC2A70aXZmoXw_1784206211 To: devel@lists.libvirt.org Subject: [PATCH] remote: block use of URI transport in scheme & query parameters Date: Thu, 16 Jul 2026 13:50:07 +0100 Message-ID: <20260716125007.1627140-1-berrange@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: HgiMzoONWBU3gxFmAdZOuIgWw5CFZB46nhNw0su64BY_1784206211 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-ID-Hash: FPF7LESHXI736NQTE6XYJVBOXICFXYST X-Message-ID-Hash: FPF7LESHXI736NQTE6XYJVBOXICFXYST X-MailFrom: berrange@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.lists.libvirt.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: redteam@telekom.de X-Mailman-Version: 3.3.10 Precedence: list List-Id: Development discussions about the libvirt library & tools Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: From: =?utf-8?q?Daniel_P=2E_Berrang=C3=A9_via_Devel?= Reply-To: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZM-MESSAGEID: 1784206288960158500 From: Daniel P. Berrang=C3=A9 The remote driver client supports specifying a transport in the URI scheme component such as +ext, +unix, +tls, etc. This determines how it should connect to the daemons. It strips this transport from the scheme to create a plain driver name that it forwards on to the remote server. It also, however, supports a "name" URI parameter which can be used to override the stripped URI that gets sent to the remote server. Unfortunately there is no validation of the URI by the remote server, so the URI override could include the transport in the scheme component. When the remote server sees a transport in the URI scheme, the connection gets diverted into the remote driver which then opens another client connection. When the "ext" transport is combined with the "command" URI parameter, this allows the client to trick the server into running an arbitrary command with the same privileges as the server. This can be abused with a read-only connection to a privileged server in order to elevate local privileges. There is no a valid reason to accept a transport component in the URI scheme received by the server, so validate this condition and reject any connection that violates it. This patch is derived from a proposal made by the reporter along with their disclosure, but generalized to block all schemes, not merely +ext and apply unconditionally to all connections not merely read-only ones. Reported-by: Deutsche Telekom Red Team Fixes: CVE-2026-15268 Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Peter Krempa --- src/remote/remote_daemon_dispatch.c | 29 +++++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) diff --git a/src/remote/remote_daemon_dispatch.c b/src/remote/remote_daemon= _dispatch.c index 329853b6da..95ab173b7c 100644 --- a/src/remote/remote_daemon_dispatch.c +++ b/src/remote/remote_daemon_dispatch.c @@ -2135,6 +2135,31 @@ remoteDispatchProbeURI(bool readonly, } #endif /* VIRTPROXYD */ =20 +static int +remoteCheckPermittedConnURI(const char *uristr) +{ + g_autoptr(virURI) uri =3D NULL; + + if (!(uri =3D virURIParse(uristr))) + return -1; + + /* + * Use of a transport (eg "+ext") in the scheme can be used to + * trick the daemon into using the remote driver to connect to + * an arbitrary socket under the caller's control. The valid + * URIs from the remote driver client will never include a + * transport component, so always reject that attempt. + */ + if (uri->scheme && + strchr(uri->scheme, '+')) { + virReportError(VIR_ERR_OPERATION_DENIED, + _("Remote URI '%1$s' is not permitted to include a = transport"), + uristr); + return -1; + } + + return 0; +} =20 static int remoteDispatchConnectOpen(virNetServer *server G_GNUC_UNUSED, @@ -2164,6 +2189,10 @@ remoteDispatchConnectOpen(virNetServer *server G_GNU= C_UNUSED, =20 name =3D args->name ? *args->name : NULL; =20 + if (name && STRNEQ(name, "") && + remoteCheckPermittedConnURI(name) < 0) + goto cleanup; + /* If this connection arrived on a readonly socket, force * the connection to be readonly. */ --=20 2.55.0