From nobody Wed Aug 5 23:37:20 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) client-ip=38.145.34.151; envelope-from=devel-bounces@lists.libvirt.org; helo=lists.libvirt.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass(p=reject dis=none) header.from=lists.libvirt.org ARC-Seal: i=1; a=rsa-sha256; t=1785258045; cv=none; d=zohomail.com; s=zohoarc; b=hUikx/S7hRMZnR8pBNv8MdxaqyU12kd0/Zp/Maf4p4e9SMptH4mOGoq7eI6SbQFsvilYALOSxTtwF42a8oITQzg6qKSzpI4yJqh7HZ26p1LQhESDjwqF2Gm/073K0d9R1dWA9bOysPMScTWzalJjT1bARNHB/i0E9u/Pc+kKn7k= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785258045; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Owner:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:Reply-To:Subject:Subject:To:To:Message-Id; bh=qs1oJLL+VXrImTJRMPCVZy0KDbISo6FuJaogCzYU+6E=; b=BcX44IO2bN1icQR4oEA91xWTf9En+7uAjUVGkCUNiIyTFr/IfqhEMzSagsyQWv+dr7ntKqQJ82V51lnHdqlAdHvFORstXaQ/lL4BT89bpC4cGlF3dAXjvKCzdH5ai+aq0lxMYv+mO5lBMk5HyfMEttB0TGgDw44WRSvWJv8KfEk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.libvirt.org (lists.libvirt.org [38.145.34.151]) by mx.zohomail.com with SMTPS id 1785258045258717.4074616308203; Tue, 28 Jul 2026 10:00:45 -0700 (PDT) Received: by lists.libvirt.org (Postfix, from userid 993) id C316B418F7; Tue, 28 Jul 2026 13:00:43 -0400 (EDT) Received: from [172.19.199.10] (unknown [10.16.107.18]) by lists.libvirt.org (Postfix) with ESMTP id 3A23D41D38; Tue, 28 Jul 2026 12:59:51 -0400 (EDT) Received: by lists.libvirt.org (Postfix, from userid 993) id 497E64187F; Tue, 28 Jul 2026 12:59:43 -0400 (EDT) Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (3072 bits) server-digest SHA256) (No client certificate requested) by lists.libvirt.org (Postfix) with ESMTPS id 4E3264187F for ; Tue, 28 Jul 2026 12:59:42 -0400 (EDT) Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-690-RJdAfBtoOfu3uUVYK3SwNw-1; Tue, 28 Jul 2026 12:59:40 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 5DEE21956089; Tue, 28 Jul 2026 16:59:39 +0000 (UTC) Received: from berrange.com (unknown [10.44.50.113]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 1EF6C404; Tue, 28 Jul 2026 16:59:37 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on lists.libvirt.org X-Spam-Level: X-Spam-Status: No, score=0.6 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,MAILING_LIST_MULTI,RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL,RCVD_IN_SBL_CSS,SPF_HELO_PASS autolearn=no autolearn_force=no version=4.0.1 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785257981; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=qs1oJLL+VXrImTJRMPCVZy0KDbISo6FuJaogCzYU+6E=; b=PIAGsKrX4Nwg0US/j/ZOw49H4Iov1RKIQzeaqXIHWPbCnx5PQrSo4JFdMPYQJrsiQFL7uj YUKfXj/gzX5OVdhd0VXcaBqRMee1sY4Yx3z8FAdKMW85EhuOiOE7b3hjwoZGzT27VyzlNh Xk/Ph5DHcVTIUrH1JiGtEDbU5FOesww= X-MC-Unique: RJdAfBtoOfu3uUVYK3SwNw-1 X-Mimecast-MFC-AGG-ID: RJdAfBtoOfu3uUVYK3SwNw_1785257979 To: devel@lists.libvirt.org Subject: [PATCH] util: virFileChownFiles: do not follow symlinks Date: Tue, 28 Jul 2026 17:59:36 +0100 Message-ID: <20260728165936.398636-1-berrange@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: _B_adoMRwvS3iTSl3e3XKnBA2ZkdvtoHVnEKZfeD5zU_1785257979 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-ID-Hash: Q4BWNTSCD6725G3NVPQQA4KFOEFAVKZ5 X-Message-ID-Hash: Q4BWNTSCD6725G3NVPQQA4KFOEFAVKZ5 X-MailFrom: berrange@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.lists.libvirt.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: =?UTF-8?q?HE=20WEI=EF=BC=88=E3=82=AE=E3=82=AB=E3=82=AF=EF=BC=89?= X-Mailman-Version: 3.3.10 Precedence: list List-Id: Development discussions about the libvirt library & tools Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: From: =?utf-8?q?Daniel_P=2E_Berrang=C3=A9_via_Devel?= Reply-To: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZM-MESSAGEID: 1785258048247158500 From: HE WEI=EF=BC=88=E3=82=AE=E3=82=AB=E3=82=AF=EF=BC=89 virFileChownFiles() selected entries with virFileIsRegular() (stat(), follo= ws symlinks) and changed ownership with chown() (follows symlinks). A component that owns the target directory at a lower privilege (e.g. the swtpm/tss sta= te directory) can plant a symlink to an arbitrary regular file and have the ro= ot caller chown that file. Use lstat() to skip non-regular entries and fchownat(..., AT_SYMLINK_NOFOLLOW) so a symlink final component is never followed. Fixes: CVE-2026-63622 Signed-off-by: HE WEI=EF=BC=88=E3=82=AE=E3=82=AB=E3=82=AF=EF=BC=89 [DB: use g_lstat instead of stat; use lchown instead of fchownat for portability; added comment] Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: J=C3=A1n Tomko --- src/util/virfile.c | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/src/util/virfile.c b/src/util/virfile.c index a0c6cb8048..c9d838eeeb 100644 --- a/src/util/virfile.c +++ b/src/util/virfile.c @@ -3306,6 +3306,12 @@ int virDirIsEmpty(const char *path, * * Change ownership of all regular files in a directory. * + * This will NOT follow any symlinks, to avoid security risks. + * It is assumed the process using content under @name will + * be unprivileged, thus less trusted than libvirt. If it is + * compromised it might attempt to create symlinks in @name to + * escalate privileges on a subsequent call to virFileChownFiles. + * * Returns -1 on error, with error already reported, 0 on success. */ #ifndef WIN32 @@ -3322,13 +3328,19 @@ int virFileChownFiles(const char *name, =20 while ((direrr =3D virDirRead(dir, &ent, name)) > 0) { g_autofree char *path =3D NULL; + struct stat sb; =20 path =3D g_build_filename(name, ent->d_name, NULL); =20 - if (!virFileIsRegular(path)) + if (g_lstat(path, &sb) < 0) { + virReportSystemError(errno, _("cannot stat '%1$s'"), path); + return -1; + } + + if (!S_ISREG(sb.st_mode)) continue; =20 - if (chown(path, uid, gid) < 0) { + if (lchown(path, uid, gid) < 0) { virReportSystemError(errno, _("cannot chown '%1$s' to (%2$u, %3$u)"), ent->d_name, (unsigned int) uid, --=20 2.55.0