Re: Malware find in the news: xz related.

Liste des GroupesRevenir à col misc 
Sujet : Re: Malware find in the news: xz related.
De : gtaylor (at) *nospam* tnetconsulting.net (Grant Taylor)
Groupes : comp.os.linux.misc
Date : 31. Mar 2024, 20:36:03
Autres entêtes
Organisation : TNet Consulting
Message-ID : <uucdv3$47g$3@tncsrv09.home.tnetconsulting.net>
References : 1 2 3 4 5
User-Agent : Mozilla Thunderbird
On 3/31/24 11:41, David W. Hodgins wrote:
The link to systemd is an after the fact detail. Likely systemd was intended as another target, but the attack was caught before it got that far.
I don't think it's proper to consider something to be after the fact when it is an integral link in the chain for the vulnerability to be exploitable.

The key in deciding whether or not a distribution is impacted, is whether or not it includes version 5.6.0 or 5.6.1 of xz.
I agree that it's possible for a non-systemd distro to have the bad versions of xz.
But it is almost certain that OpenSSH on that non-systemd distro won't be effected because it doesn't have support for xz in sshd.
The sshd vector requires all three components, sshd and systemd and xz.
If you remove systemd from that chain, sshd doesn't have xz in it and as such sshd isn't vulnerable to this attack even if the vulnerable xz is on the system.
At least that's my understanding.

The remote code execution is in those versions of the xz package.
And that RCE in the xz package isn't incorporated into sshd on non-systemd distros.

Once the RCE is available, ssh is vulnerable as sshd supports compression and xz is one option for compression.
OpenSSH / sshd upstream doesn't support xz as a compression.
Some distros have modified to make OpenSSH / sshd play nicer with systemd and it's that modification that pulls xz in as a dependency.
So if your OpenSSH / sshd isn't ""enhanced - scoff - to support systemd, then it will not have xz support.  If your OpenSSH / sshd doesn't have xz support then it's not vulnerable to the xz compromise.

It doesn't matter whether xz is linked in to sshd or called at run time to decompress the data.
 https://gynvael.coldwind.pl/?lang=en&id=782
https://tukaani.org/xz-backdoor/
 The RCE just happened to be found while running detailed timing tests that included sshd with xz compression support. It impacts anything that supports using xz as a compression utility, or any xz decompression of untrusted input by an end user or other system service.
I question the veracity of that.
There may be a root hole in xz that matches what you say.
But my understanding of the xz RCE is that it is specifically written for xz to be indirectly pulled into OpenSSH / sshd via systemd and that it is expecting very specific behavior / assumptions.  I seriously doubt that those assumptions will be valid in other things.
Could the root hole in xz be abused as a gadget to target other things besides sshd-modified-for-systemd?  Probably.  Or at least it conceptually could have if it hadn't been discovered.
--
Grant. . . .

Date Sujet#  Auteur
30 Mar 24 * Malware find in the news: xz related.59pH
30 Mar 24 +- Re: Malware find in the news: xz related.1Woozy Song
30 Mar 24 +* Re: Malware find in the news: xz related.2Eli the Bearded
31 Mar 24 i`- Re: Malware find in the news: xz related.1Computer Nerd Kev
31 Mar 24 +* Re: Malware find in the news: xz related.25MarioCCCP
31 Mar 24 i`* Re: Malware find in the news: xz related.24Computer Nerd Kev
31 Mar 24 i `* Re: Malware find in the news: xz related.23Computer Nerd Kev
31 Mar 24 i  +* Re: Malware find in the news: xz related.16D
31 Mar 24 i  i`* Re: Malware find in the news: xz related.15Lew Pitcher
31 Mar 24 i  i +* Re: Malware find in the news: xz related.12Nuno Silva
31 Mar 24 i  i i+- Re: Malware find in the news: xz related.1Lew Pitcher
31 Mar 24 i  i i+- Re: Malware find in the news: xz related.1Rich
31 Mar 24 i  i i`* Re: Malware find in the news: xz related.9Richard Kettlewell
1 Apr 24 i  i i `* Re: Malware find in the news: xz related.8Carlos E.R.
1 Apr 24 i  i i  `* Re: Malware find in the news: xz related.7Rich
2 Apr 24 i  i i   `* Re: Malware find in the news: xz related.6Carlos E.R.
6 Apr 24 i  i i    `* Re: Malware find in the news: xz related.5MarioCCCP
6 Apr 24 i  i i     `* Re: Malware find in the news: xz related.4Rich
6 Apr 24 i  i i      `* Re: Malware find in the news: xz related.3The Natural Philosopher
7 Apr 24 i  i i       +- Re: Malware find in the news: xz related.1Computer Nerd Kev
8 Apr 24 i  i i       `- Re: Malware find in the news: xz related.1Rich
31 Mar 24 i  i +- Re: Malware find in the news: xz related.1D
6 Apr 24 i  i `- Re: Malware find in the news: xz related.1Popping Mad
31 Mar 24 i  +- Re: Malware find in the news: xz related.1Woozy Song
31 Mar 24 i  `* Re: Malware find in the news: xz related.5Carlos E.R.
31 Mar 24 i   +- Re: Malware find in the news: xz related.1David W. Hodgins
31 Mar 24 i   `* Re: Malware find in the news: xz related.3D
31 Mar 24 i    `* Re: Malware find in the news: xz related.2Carlos E.R.
1 Apr 24 i     `- Re: Malware find in the news: xz related.1D
31 Mar 24 `* Re: Malware find in the news: xz related.30John McCue
31 Mar 24  `* Re: Malware find in the news: xz related.29Grant Taylor
31 Mar 24   +* Re: Malware find in the news: xz related.11David W. Hodgins
31 Mar 24   i+* Re: Malware find in the news: xz related.8Rich
31 Mar 24   ii`* Re: Malware find in the news: xz related.7David W. Hodgins
31 Mar 24   ii `* Re: Malware find in the news: xz related.6Lew Pitcher
31 Mar 24   ii  `* Re: Malware find in the news: xz related.5Marco Moock
31 Mar 24   ii   `* Re: Malware find in the news: xz related.4Grant Taylor
31 Mar 24   ii    +- Re: Malware find in the news: xz related.1David W. Hodgins
1 Apr 24   ii    `* Re: Malware find in the news: xz related.2Marco Moock
1 Apr 24   ii     `- Re: Malware find in the news: xz related.1Grant Taylor
31 Mar 24   i`* Re: Malware find in the news: xz related.2Grant Taylor
31 Mar 24   i `- Re: Malware find in the news: xz related.1Marc Haber
31 Mar 24   `* Re: Malware find in the news: xz related.17Rich
31 Mar 24    +* Re: Malware find in the news: xz related.4David W. Hodgins
31 Mar 24    i+* Re: Malware find in the news: xz related.2Grant Taylor
31 Mar 24    ii`- Re: Malware find in the news: xz related.1Richard Kettlewell
31 Mar 24    i`- Re: Malware find in the news: xz related.1D
31 Mar 24    +* Re: Malware find in the news: xz related.7Carlos E.R.
31 Mar 24    i`* Re: Malware find in the news: xz related.6D
31 Mar 24    i +* Re: Malware find in the news: xz related.4Carlos E.R.
31 Mar 24    i i`* Re: Malware find in the news: xz related.3Computer Nerd Kev
1 Apr 24    i i +- Re: Malware find in the news: xz related.1candycanearter07
1 Apr 24    i i `- Re: Malware find in the news: xz related.1John Dallman
6 Apr 24    i `- Re: Malware find in the news: xz related.1Popping Mad
31 Mar 24    `* Re: Malware find in the news: xz related.5Grant Taylor
1 Apr 24     +- Re: Malware find in the news: xz related.1Rich
1 Apr 24     `* Re: Malware find in the news: xz related.3Marco Moock
7 Apr 24      `* Re: Malware find in the news: xz related.2Carlos E.R.
7 Apr 24       `- Re: Malware find in the news: xz related.1John Dallman

Haut de la page

Les messages affichés proviennent d'usenet.

NewsPortal