From nobody Tue Aug 4 22:19:41 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) client-ip=38.145.34.151; envelope-from=devel-bounces@lists.libvirt.org; helo=lists.libvirt.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass(p=reject dis=none) header.from=lists.libvirt.org ARC-Seal: i=1; a=rsa-sha256; t=1785256742; cv=none; d=zohomail.com; s=zohoarc; b=EdLs/ZZJcIKUnPTK9TbiVOSmO4+DjU9k1BVUJRLK3KZta7wxAq+6lyWjAImtb12lfMbwQOAdsNY+/EcnFWmPXPDKvd0nJgSkfznkltdYyxxNf2YzFj5BThSiddSoo5/G52ipfoDsoBEko/80PxrxIzP+5tfYwogRcSVTDJEGUkw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785256742; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Owner:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:Reply-To:Subject:Subject:To:To:Message-Id; bh=ZmER+m4zmrUWOIxQi9MLrRUWPv46HQuJw6SLzPyhyxU=; b=FaqU0wf2wlr6KHjl4EkO9ZCBAEoSnCk6KMRCradScbAG7ny90AeEzqh5mpn92ph3v1C6nhFs9iSaH7D/X0bOaBdiO23x0KpL5eIWf3HnlbZRSzQp45aIVe31zXp63rwU0ydW9wQwx8znBQy77JkwzmAwQPvuRHL10Pfnnr1utQk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.libvirt.org (lists.libvirt.org [38.145.34.151]) by mx.zohomail.com with SMTPS id 1785256742114488.15895048239895; Tue, 28 Jul 2026 09:39:02 -0700 (PDT) Received: by lists.libvirt.org (Postfix, from userid 993) id A09CE41B06; Tue, 28 Jul 2026 12:39:00 -0400 (EDT) Received: from [172.19.199.10] (unknown [10.16.107.18]) by lists.libvirt.org (Postfix) with ESMTP id 8892841D21; Tue, 28 Jul 2026 12:38:10 -0400 (EDT) Received: by lists.libvirt.org (Postfix, from userid 993) id D5ADA3F289; Tue, 28 Jul 2026 12:38:00 -0400 (EDT) Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (3072 bits) server-digest SHA256) (No client certificate requested) by lists.libvirt.org (Postfix) with ESMTPS id A79203F862 for ; Tue, 28 Jul 2026 12:37:59 -0400 (EDT) Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-86-RTcCvA86McyQe_whcvZQjA-1; Tue, 28 Jul 2026 12:37:57 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id ADA861956089; Tue, 28 Jul 2026 16:37:56 +0000 (UTC) Received: from berrange.com (unknown [10.44.50.113]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 676BF19560AB; Tue, 28 Jul 2026 16:37:55 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on lists.libvirt.org X-Spam-Level: X-Spam-Status: No, score=0.6 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,MAILING_LIST_MULTI,RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL,RCVD_IN_SBL_CSS,SPF_HELO_PASS autolearn=no autolearn_force=no version=4.0.1 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785256679; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=ZmER+m4zmrUWOIxQi9MLrRUWPv46HQuJw6SLzPyhyxU=; b=OlM4JiGBBN0669iCebMUzgh251k6yk3cJKrmTX5qOAGmUCoGd1C854759JTp29LPSEoxML +kKMt9xEekKZBRzFjN2CF4attayjz4u9jkEGmYhbY97eQd8ms2FOzK/kidq5J6Qij6T4lX /JLVNWW5QKMdXsId13VtMkeuuWTAN7Y= X-MC-Unique: RTcCvA86McyQe_whcvZQjA-1 X-Mimecast-MFC-AGG-ID: RTcCvA86McyQe_whcvZQjA_1785256676 To: devel@lists.libvirt.org Subject: [PATCH] storage: create images with a private umask during qemu-img create/convert Date: Tue, 28 Jul 2026 17:37:53 +0100 Message-ID: <20260728163753.359068-1-berrange@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: 9yAVeDbHwtLLWzd0LNNzVwgO1bT2HkZFE7qsJKsYSqI_1785256676 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-ID-Hash: PNHVJ6QXWJG4ZYVDLQJPCBCF35NVO7FF X-Message-ID-Hash: PNHVJ6QXWJG4ZYVDLQJPCBCF35NVO7FF X-MailFrom: berrange@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.lists.libvirt.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: =?UTF-8?q?HE=20WEI=EF=BC=88=E3=82=AE=E3=82=AB=E3=82=AF=EF=BC=89?= X-Mailman-Version: 3.3.10 Precedence: list List-Id: Development discussions about the libvirt library & tools Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: From: =?utf-8?q?Daniel_P=2E_Berrang=C3=A9_via_Devel?= Reply-To: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZM-MESSAGEID: 1785256742559158500 From: HE WEI=EF=BC=88=E3=82=AE=E3=82=AB=E3=82=AF=EF=BC=89 On the local (non-NETFS) path virStorageBackendCreateExecCommand() ran qemu-img with umask 0, so the destination image was created world-readable (0644) and the full source disk was written into it before libvirt tightened the mode with a later chmod(). This is the same class as CVE-2025-13193; apply the same fix by setting a 0077 umask so qemu-img creates the file private from the start. Fixes: CVE-2026-63623 Reported-by: HE WEI=EF=BC=88=E3=82=AE=E3=82=AB=E3=82=AF=EF=BC=89 Signed-off-by: HE WEI=EF=BC=88=E3=82=AE=E3=82=AB=E3=82=AF=EF=BC=89 [DB: merged the two virCommandSetUmask to one] Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: J=C3=A1n Tomko --- src/storage/storage_util.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/src/storage/storage_util.c b/src/storage/storage_util.c index 78dc9f9f1c..9e6b266842 100644 --- a/src/storage/storage_util.c +++ b/src/storage/storage_util.c @@ -464,6 +464,7 @@ virStorageBackendCreateExecCommand(virStoragePoolObj *p= ool, bool filecreated =3D false; int ret =3D -1; =20 + virCommandSetUmask(cmd, S_IRWXUGO ^ mode); if ((def->type =3D=3D VIR_STORAGE_POOL_NETFS) && (((geteuid() =3D=3D 0) && (vol->target.perms->uid !=3D (uid_t)-1) @@ -473,7 +474,6 @@ virStorageBackendCreateExecCommand(virStoragePoolObj *p= ool, =20 virCommandSetUID(cmd, vol->target.perms->uid); virCommandSetGID(cmd, vol->target.perms->gid); - virCommandSetUmask(cmd, S_IRWXUGO ^ mode); =20 if (virCommandRun(cmd, NULL) =3D=3D 0) { /* command was successfully run, check if the file was created= */ @@ -505,7 +505,6 @@ virStorageBackendCreateExecCommand(virStoragePoolObj *p= ool, /* don't change uid/gid/mode if we retry */ virCommandSetUID(cmd, -1); virCommandSetGID(cmd, -1); - virCommandSetUmask(cmd, 0); =20 if (virCommandRun(cmd, NULL) < 0) goto cleanup; --=20 2.55.0