From 30e38505e4bc6f8313509bdee2418024693088fa Mon Sep 17 00:00:00 2001 From: Raphael Pavlidis Date: Thu, 29 Jan 2026 17:10:04 +0100 Subject: [PATCH] package/linux-pam: security bump to version 1.7.2 Fixes (in 1.7.1): CVE-2025-6020 - pam_namespace: potential privilege escalation https://github.com/linux-pam/linux-pam/security/advisories/GHSA-f9p8-gjr4-j9gx The build system was changed from autotools to meson in 1.7.0. Changelog: https://github.com/linux-pam/linux-pam/releases/tag/v1.7.0 https://github.com/linux-pam/linux-pam/releases/tag/v1.7.1 https://github.com/linux-pam/linux-pam/releases/tag/v1.7.2 Signed-off-by: Raphael Pavlidis [Marcus: add note about the CVE fixed in this bump] Signed-off-by: Marcus Hoffmann --- ...-consistently-include-config.h-first.patch | 180 -------------- ...work-resolving-of-tokens-as-hostname.patch | 229 ------------------ package/linux-pam/linux-pam.hash | 6 +- package/linux-pam/linux-pam.mk | 34 ++- 4 files changed, 17 insertions(+), 432 deletions(-) delete mode 100644 package/linux-pam/0001-build-consistently-include-config.h-first.patch delete mode 100644 package/linux-pam/0002-pam_access-rework-resolving-of-tokens-as-hostname.patch diff --git a/package/linux-pam/0001-build-consistently-include-config.h-first.patch b/package/linux-pam/0001-build-consistently-include-config.h-first.patch deleted file mode 100644 index e9f36b8a60..0000000000 --- a/package/linux-pam/0001-build-consistently-include-config.h-first.patch +++ /dev/null @@ -1,180 +0,0 @@ -From cdba2c8cdba9b3500595624fb375c0dda266631b Mon Sep 17 00:00:00 2001 -From: "Dmitry V. Levin" -Date: Fri, 30 Aug 2024 08:00:00 +0000 -Subject: [PATCH] build: consistently include config.h first - -Make sure that config.h is included before any system header. - -Upstream: https://github.com/linux-pam/linux-pam/commit/5d7eefb1883c557c7a027f68e966e2fae294a9b6 -Signed-off-by: Thomas Petazzoni ---- - libpam/pam_prelude.c | 8 ++++---- - modules/pam_namespace/argv_parse.c | 2 ++ - modules/pam_setquota/pam_setquota.c | 3 ++- - modules/pam_timestamp/sha1.c | 2 +- - modules/pam_unix/audit.c | 3 +-- - modules/pam_unix/bigcrypt_main.c | 2 ++ - modules/pam_unix/md5.c | 4 ++-- - modules/pam_unix/md5_crypt.c | 2 +- - modules/pam_unix/yppasswd.h | 2 ++ - 9 files changed, 17 insertions(+), 11 deletions(-) - -diff --git a/libpam/pam_prelude.c b/libpam/pam_prelude.c -index 6c73bf5d..c62e2f2c 100644 ---- a/libpam/pam_prelude.c -+++ b/libpam/pam_prelude.c -@@ -5,17 +5,17 @@ - * (C) Sebastien Tricaud 2005 - */ - --#include --#include -- - #ifdef PRELUDE - -+#include "pam_private.h" -+ -+#include -+#include - #include - #include - #include - - #include "pam_prelude.h" --#include "pam_private.h" - - - #define ANALYZER_CLASS "pam" -diff --git a/modules/pam_namespace/argv_parse.c b/modules/pam_namespace/argv_parse.c -index ac7c9ae0..cbae7831 100644 ---- a/modules/pam_namespace/argv_parse.c -+++ b/modules/pam_namespace/argv_parse.c -@@ -28,6 +28,8 @@ - * Version 1.1, modified 2/27/1999 - */ - -+#include "config.h" -+ - #include - #include - #include -diff --git a/modules/pam_setquota/pam_setquota.c b/modules/pam_setquota/pam_setquota.c -index c15fc669..73445e29 100644 ---- a/modules/pam_setquota/pam_setquota.c -+++ b/modules/pam_setquota/pam_setquota.c -@@ -8,6 +8,8 @@ - Copyright © 2016 Keller Fuchs - */ - -+#include "pam_inline.h" -+ - #include - #include - #include -@@ -22,7 +24,6 @@ - #include - #include - #include --#include "pam_inline.h" - - #ifndef PATH_LOGIN_DEFS - # define PATH_LOGIN_DEFS "/etc/login.defs" -diff --git a/modules/pam_timestamp/sha1.c b/modules/pam_timestamp/sha1.c -index dff454cf..f21b2870 100644 ---- a/modules/pam_timestamp/sha1.c -+++ b/modules/pam_timestamp/sha1.c -@@ -37,6 +37,7 @@ - */ - /* See http://www.itl.nist.gov/fipspubs/fip180-1.htm for descriptions. */ - -+#include "pam_inline.h" - #include - #include - #include -@@ -47,7 +48,6 @@ - #include - #include - #include "sha1.h" --#include "pam_inline.h" - - static const unsigned char - padding[SHA1_BLOCK_SIZE] = { -diff --git a/modules/pam_unix/audit.c b/modules/pam_unix/audit.c -index 1547a652..9513aaa9 100644 ---- a/modules/pam_unix/audit.c -+++ b/modules/pam_unix/audit.c -@@ -1,5 +1,3 @@ --#include "audit.h" -- - #include "config.h" - - #ifdef HAVE_LIBAUDIT -@@ -11,6 +9,7 @@ - - #include - -+#include "audit.h" - #include "passverify.h" - - int audit_log(int type, const char *uname, int retval) -diff --git a/modules/pam_unix/bigcrypt_main.c b/modules/pam_unix/bigcrypt_main.c -index fab212d9..22d325da 100644 ---- a/modules/pam_unix/bigcrypt_main.c -+++ b/modules/pam_unix/bigcrypt_main.c -@@ -1,3 +1,5 @@ -+#include "config.h" -+ - #include - #include - -diff --git a/modules/pam_unix/md5.c b/modules/pam_unix/md5.c -index 95b8de4c..78e9af27 100644 ---- a/modules/pam_unix/md5.c -+++ b/modules/pam_unix/md5.c -@@ -18,11 +18,11 @@ - * - */ - -+#include "pam_inline.h" -+ - #include - #include "md5.h" - --#include "pam_inline.h" -- - #ifndef HIGHFIRST - #define byteReverse(buf, len) /* Nothing */ - #else -diff --git a/modules/pam_unix/md5_crypt.c b/modules/pam_unix/md5_crypt.c -index 9a6bd4f9..9451f376 100644 ---- a/modules/pam_unix/md5_crypt.c -+++ b/modules/pam_unix/md5_crypt.c -@@ -12,11 +12,11 @@ - * - */ - -+#include "pam_inline.h" - #include - #include - #include - #include "md5.h" --#include "pam_inline.h" - - static const unsigned char itoa64[] = /* 0 ... 63 => ascii - 64 */ - "./0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz"; -diff --git a/modules/pam_unix/yppasswd.h b/modules/pam_unix/yppasswd.h -index dc686cd7..3a40c3ea 100644 ---- a/modules/pam_unix/yppasswd.h -+++ b/modules/pam_unix/yppasswd.h -@@ -6,6 +6,8 @@ - #ifndef _YPPASSWD_H_RPCGEN - #define _YPPASSWD_H_RPCGEN - -+#include "config.h" -+ - #include - - --- -2.47.1 - diff --git a/package/linux-pam/0002-pam_access-rework-resolving-of-tokens-as-hostname.patch b/package/linux-pam/0002-pam_access-rework-resolving-of-tokens-as-hostname.patch deleted file mode 100644 index 367cdf6202..0000000000 --- a/package/linux-pam/0002-pam_access-rework-resolving-of-tokens-as-hostname.patch +++ /dev/null @@ -1,229 +0,0 @@ -From d82b7ef5fc8afd7841735a4d0fcef6237193e183 Mon Sep 17 00:00:00 2001 -From: Thorsten Kukuk -Date: Thu, 14 Nov 2024 10:27:28 +0100 -Subject: [PATCH] pam_access: rework resolving of tokens as hostname - -* modules/pam_access/pam_access.c: separate resolving of IP addresses - from hostnames. Don't resolve TTYs or display variables as hostname - (#834). - Add "nodns" option to disallow resolving of tokens as hostname. -* modules/pam_access/pam_access.8.xml: document nodns option -* modules/pam_access/access.conf.5.xml: document that hostnames should - be written as FQHN. - -CVE: CVE-2024-10963 -Upstream: https://github.com/linux-pam/linux-pam/commit/940747f88c16e029b69a74e80a2e94f65cb3e628 -Signed-off-by: Raphael Pavlidis ---- - modules/pam_access/access.conf.5.xml | 4 ++ - modules/pam_access/pam_access.8.xml | 46 ++++++++++++------ - modules/pam_access/pam_access.c | 72 +++++++++++++++++++++++++++- - 3 files changed, 105 insertions(+), 17 deletions(-) - -diff --git a/modules/pam_access/access.conf.5.xml b/modules/pam_access/access.conf.5.xml -index 2dc5d477..b2997e10 100644 ---- a/modules/pam_access/access.conf.5.xml -+++ b/modules/pam_access/access.conf.5.xml -@@ -232,6 +232,10 @@ - An IPv6 link local host address must contain the interface - identifier. IPv6 link local network/netmask is not supported. - -+ -+ Hostnames should be written as Fully-Qualified Host Name (FQHN) to avoid -+ confusion with device names or PAM service names. -+ - - - -diff --git a/modules/pam_access/pam_access.8.xml b/modules/pam_access/pam_access.8.xml -index c991d7a0..71a4f7ee 100644 ---- a/modules/pam_access/pam_access.8.xml -+++ b/modules/pam_access/pam_access.8.xml -@@ -22,11 +22,14 @@ - - debug - -+ -+ noaudit -+ - - nodefgroup - - -- noaudit -+ nodns - - - quiet_log -@@ -132,6 +135,33 @@ - - - -+ -+ -+ nodefgroup -+ -+ -+ -+ User tokens which are not enclosed in parentheses will not be -+ matched against the group database. The backwards compatible default is -+ to try the group database match even for tokens not enclosed -+ in parentheses. -+ -+ -+ -+ -+ -+ -+ nodns -+ -+ -+ -+ Do not try to resolve tokens as hostnames, only IPv4 and IPv6 -+ addresses will be resolved. Which means to allow login from a -+ remote host, the IP addresses need to be specified in access.conf. -+ -+ -+ -+ - - - quiet_log -@@ -185,20 +215,6 @@ - - - -- -- -- nodefgroup -- -- -- -- User tokens which are not enclosed in parentheses will not be -- matched against the group database. The backwards compatible default is -- to try the group database match even for tokens not enclosed -- in parentheses. -- -- -- -- - - - -diff --git a/modules/pam_access/pam_access.c b/modules/pam_access/pam_access.c -index 2ab1ca94..fdb5dd86 100644 ---- a/modules/pam_access/pam_access.c -+++ b/modules/pam_access/pam_access.c -@@ -100,6 +100,7 @@ struct login_info { - int only_new_group_syntax; /* Only allow group entries of the form "(xyz)" */ - int noaudit; /* Do not audit denials */ - int quiet_log; /* Do not log denials */ -+ int nodns; /* Do not try to resolve tokens as hostnames */ - const char *fs; /* field separator */ - const char *sep; /* list-element separator */ - int from_remote_host; /* If PAM_RHOST was used for from */ -@@ -154,6 +155,8 @@ parse_args(pam_handle_t *pamh, struct login_info *loginfo, - loginfo->noaudit = YES; - } else if (strcmp (argv[i], "quiet_log") == 0) { - loginfo->quiet_log = YES; -+ } else if (strcmp (argv[i], "nodns") == 0) { -+ loginfo->nodns = YES; - } else { - pam_syslog(pamh, LOG_ERR, "unrecognized option [%s]", argv[i]); - } -@@ -741,7 +744,7 @@ remote_match (pam_handle_t *pamh, char *tok, struct login_info *item) - if ((str_len = strlen(string)) > tok_len - && strcasecmp(tok, string + str_len - tok_len) == 0) - return YES; -- } else if (tok[tok_len - 1] == '.') { /* internet network numbers (end with ".") */ -+ } else if (tok[tok_len - 1] == '.') { /* internet network numbers/subnet (end with ".") */ - struct addrinfo hint; - - memset (&hint, '\0', sizeof (hint)); -@@ -816,6 +819,39 @@ string_match (pam_handle_t *pamh, const char *tok, const char *string, - } - - -+static int -+is_device (pam_handle_t *pamh, const char *tok) -+{ -+ struct stat st; -+ const char *dev = "/dev/"; -+ char *devname; -+ -+ devname = malloc (strlen(dev) + strlen (tok) + 1); -+ if (devname == NULL) { -+ pam_syslog(pamh, LOG_ERR, "Cannot allocate memory for device name: %m"); -+ /* -+ * We should return an error and abort, but pam_access has no good -+ * error handling. -+ */ -+ return NO; -+ } -+ -+ char *cp = stpcpy (devname, dev); -+ strcpy (cp, tok); -+ -+ if (lstat(devname, &st) != 0) -+ { -+ free (devname); -+ return NO; -+ } -+ free (devname); -+ -+ if (S_ISCHR(st.st_mode)) -+ return YES; -+ -+ return NO; -+} -+ - /* network_netmask_match - match a string against one token - * where string is a hostname or ip (v4,v6) address and tok - * represents either a hostname, a single ip (v4,v6) address -@@ -877,10 +913,42 @@ network_netmask_match (pam_handle_t *pamh, - return NO; - } - } -+ else if (isipaddr(tok, NULL, NULL) == YES) -+ { -+ if (getaddrinfo (tok, NULL, NULL, &ai) != 0) -+ { -+ if (item->debug) -+ pam_syslog(pamh, LOG_DEBUG, "cannot resolve IP address \"%s\"", tok); -+ -+ return NO; -+ } -+ netmask_ptr = NULL; -+ } -+ else if (item->nodns) -+ { -+ /* Only hostnames are left, which we would need to resolve via DNS */ -+ return NO; -+ } - else - { -+ /* Bail out on X11 Display entries and ttys. */ -+ if (tok[0] == ':') -+ { -+ if (item->debug) -+ pam_syslog (pamh, LOG_DEBUG, -+ "network_netmask_match: tok=%s is X11 display", tok); -+ return NO; -+ } -+ if (is_device (pamh, tok)) -+ { -+ if (item->debug) -+ pam_syslog (pamh, LOG_DEBUG, -+ "network_netmask_match: tok=%s is a TTY", tok); -+ return NO; -+ } -+ - /* -- * It is either an IP address or a hostname. -+ * It is most likely a hostname. - * Let getaddrinfo sort everything out - */ - if (getaddrinfo (tok, NULL, NULL, &ai) != 0) --- -2.53.0 - diff --git a/package/linux-pam/linux-pam.hash b/package/linux-pam/linux-pam.hash index 353613e6e6..8688dc2af6 100644 --- a/package/linux-pam/linux-pam.hash +++ b/package/linux-pam/linux-pam.hash @@ -1,6 +1,6 @@ # Locally computed hashes after checking signature at -# https://github.com/linux-pam/linux-pam/releases/download/v1.6.1/Linux-PAM-1.6.1.tar.xz.asc -# signed with the key 8C6BFD92EE0F42EDF91A6A736D1A7F052E5924BB -sha256 f8923c740159052d719dbfc2a2f81942d68dd34fcaf61c706a02c9b80feeef8e Linux-PAM-1.6.1.tar.xz +# https://github.com/linux-pam/linux-pam/releases/download/v1.7.2/Linux-PAM-1.7.2.tar.xz.asc +# signed with the key 7BECFE3AF7B280BB52FF77F104BA4521C996DDE1 +sha256 3d86b6383fb5fd9eb9578d2cd47d92801191f4bf3f9bc61419bfefc8aa1e531a Linux-PAM-1.7.2.tar.xz # Locally computed sha256 133d98e7a2ab3ffd330b4debb0bfc10fea21e4b2b5a5b09de2e924293be5ff08 Copyright diff --git a/package/linux-pam/linux-pam.mk b/package/linux-pam/linux-pam.mk index f4e488428d..799e74c911 100644 --- a/package/linux-pam/linux-pam.mk +++ b/package/linux-pam/linux-pam.mk @@ -4,18 +4,15 @@ # ################################################################################ -LINUX_PAM_VERSION = 1.6.1 +LINUX_PAM_VERSION = 1.7.2 LINUX_PAM_SOURCE = Linux-PAM-$(LINUX_PAM_VERSION).tar.xz LINUX_PAM_SITE = https://github.com/linux-pam/linux-pam/releases/download/v$(LINUX_PAM_VERSION) LINUX_PAM_INSTALL_STAGING = YES LINUX_PAM_CONF_OPTS = \ - --disable-prelude \ - --disable-isadir \ - --disable-nis \ - --disable-db \ - --disable-regenerate-docu \ - --enable-securedir=/lib/security \ - --libdir=/lib + -Disadir=disabled \ + -Dnis=disabled \ + -Dpam_userdb=disabled \ + -Ddocs=disabled LINUX_PAM_DEPENDENCIES = host-flex host-pkgconf \ $(if $(BR2_PACKAGE_LIBXCRYPT),libxcrypt) \ $(TARGET_NLS_DEPENDENCIES) @@ -25,46 +22,43 @@ LINUX_PAM_LIBS = $(TARGET_NLS_LIBS) LINUX_PAM_MAKE_OPTS += LIBS="$(LINUX_PAM_LIBS)" LINUX_PAM_CPE_ID_VENDOR = linux-pam -# 0002-pam_access-rework-resolving-of-tokens-as-hostname.patch -LINUX_PAM_IGNORE_CVES += CVE-2024-10963 - ifeq ($(BR2_TOOLCHAIN_HAS_LIBATOMIC),y) LINUX_PAM_LIBS += -latomic endif ifeq ($(BR2_PACKAGE_LIBSELINUX),y) -LINUX_PAM_CONF_OPTS += --enable-selinux +LINUX_PAM_CONF_OPTS += -Dselinux=enabled LINUX_PAM_DEPENDENCIES += libselinux define LINUX_PAM_SELINUX_PAMFILE_TWEAK $(SED) 's/^# \(.*pam_selinux.so.*\)$$/\1/' \ $(TARGET_DIR)/etc/pam.d/login endef else -LINUX_PAM_CONF_OPTS += --disable-selinux +LINUX_PAM_CONF_OPTS += -Dselinux=disabled endif ifeq ($(BR2_PACKAGE_AUDIT),y) -LINUX_PAM_CONF_OPTS += --enable-audit +LINUX_PAM_CONF_OPTS += -Daudit=enabled LINUX_PAM_DEPENDENCIES += audit else -LINUX_PAM_CONF_OPTS += --disable-audit +LINUX_PAM_CONF_OPTS += -Daudit=disabled endif ifeq ($(BR2_PACKAGE_OPENSSL),y) -LINUX_PAM_CONF_OPTS += --enable-openssl +LINUX_PAM_CONF_OPTS += -Dopenssl=enabled LINUX_PAM_DEPENDENCIES += openssl else -LINUX_PAM_CONF_OPTS += --disable-openssl +LINUX_PAM_CONF_OPTS += -Dopenssl=disabled endif ifeq ($(BR2_PACKAGE_LINUX_PAM_LASTLOG),y) -LINUX_PAM_CONF_OPTS += --enable-lastlog +LINUX_PAM_CONF_OPTS += -Dpam_lastlog=enabled define LINUX_PAM_LASTLOG_PAMFILE_TWEAK $(SED) 's/^# \(.*pam_lastlog.so.*\)$$/\1/' \ $(TARGET_DIR)/etc/pam.d/login endef else -LINUX_PAM_CONF_OPTS += --disable-lastlog +LINUX_PAM_CONF_OPTS += -Dpam_lastlog=disabled endif # Install default pam config (deny everything except login) @@ -79,4 +73,4 @@ endef LINUX_PAM_POST_INSTALL_TARGET_HOOKS += LINUX_PAM_INSTALL_CONFIG -$(eval $(autotools-package)) +$(eval $(meson-package))