aboutsummaryrefslogtreecommitdiffstats
path: root/meta-oe/recipes-support/multipath-tools/files/CVE-2022-41974.patch
blob: 7cdb5f9bda262ad67e7dbb127e69a86601693029 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
From 0168696f95b5c610c3861ced8ef98accd1a83b91 Mon Sep 17 00:00:00 2001
From: Benjamin Marzinski <bmarzins@redhat.com>
Date: Tue, 27 Sep 2022 12:36:37 +0200
Subject: [PATCH] multipathd: ignore duplicated multipathd command keys

multipath adds rather than or-s the values of command keys. Fix this.
Also, return an invalid fingerprint if a key is used more than once.

CVE: CVE-2022-41974

References:
https://nvd.nist.gov/vuln/detail/CVE-2022-41974
https://github.com/opensvc/multipath-tools/issues/59

Upstream-Status: Backport
[https://github.com/openSUSE/multipath-tools/commit/fbbf280a0e26026c19879d938ebb2a8200b6357c]

Signed-off-by: Benjamin Marzinski <bmarzins@redhat.com>

Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
---
 multipathd/cli.c  |   8 ++--
 multipathd/main.c | 104 +++++++++++++++++++++++-----------------------
 2 files changed, 57 insertions(+), 55 deletions(-)

diff --git a/multipathd/cli.c b/multipathd/cli.c
index 800c0fbe..0a266761 100644
--- a/multipathd/cli.c
+++ b/multipathd/cli.c
@@ -336,9 +336,11 @@ fingerprint(vector vec)
	if (!vec)
		return 0;

-	vector_foreach_slot(vec, kw, i)
-		fp += kw->code;
-
+	vector_foreach_slot(vec, kw, i) {
+		if (fp & kw->code)
+			return (uint64_t)-1;
+		fp |= kw->code;
+	}
	return fp;
 }

diff --git a/multipathd/main.c b/multipathd/main.c
index 8baf9abe..975287d2 100644
--- a/multipathd/main.c
+++ b/multipathd/main.c
@@ -1522,61 +1522,61 @@ uxlsnrloop (void * ap)
	/* Tell main thread that thread has started */
	post_config_state(DAEMON_CONFIGURE);

-	set_handler_callback(LIST+PATHS, cli_list_paths);
-	set_handler_callback(LIST+PATHS+FMT, cli_list_paths_fmt);
-	set_handler_callback(LIST+PATHS+RAW+FMT, cli_list_paths_raw);
-	set_handler_callback(LIST+PATH, cli_list_path);
-	set_handler_callback(LIST+MAPS, cli_list_maps);
-	set_handler_callback(LIST+STATUS, cli_list_status);
-	set_unlocked_handler_callback(LIST+DAEMON, cli_list_daemon);
-	set_handler_callback(LIST+MAPS+STATUS, cli_list_maps_status);
-	set_handler_callback(LIST+MAPS+STATS, cli_list_maps_stats);
-	set_handler_callback(LIST+MAPS+FMT, cli_list_maps_fmt);
-	set_handler_callback(LIST+MAPS+RAW+FMT, cli_list_maps_raw);
-	set_handler_callback(LIST+MAPS+TOPOLOGY, cli_list_maps_topology);
-	set_handler_callback(LIST+TOPOLOGY, cli_list_maps_topology);
-	set_handler_callback(LIST+MAPS+JSON, cli_list_maps_json);
-	set_handler_callback(LIST+MAP+TOPOLOGY, cli_list_map_topology);
-	set_handler_callback(LIST+MAP+FMT, cli_list_map_fmt);
-	set_handler_callback(LIST+MAP+RAW+FMT, cli_list_map_fmt);
-	set_handler_callback(LIST+MAP+JSON, cli_list_map_json);
-	set_handler_callback(LIST+CONFIG+LOCAL, cli_list_config_local);
-	set_handler_callback(LIST+CONFIG, cli_list_config);
-	set_handler_callback(LIST+BLACKLIST, cli_list_blacklist);
-	set_handler_callback(LIST+DEVICES, cli_list_devices);
-	set_handler_callback(LIST+WILDCARDS, cli_list_wildcards);
-	set_handler_callback(RESET+MAPS+STATS, cli_reset_maps_stats);
-	set_handler_callback(RESET+MAP+STATS, cli_reset_map_stats);
-	set_handler_callback(ADD+PATH, cli_add_path);
-	set_handler_callback(DEL+PATH, cli_del_path);
-	set_handler_callback(ADD+MAP, cli_add_map);
-	set_handler_callback(DEL+MAP, cli_del_map);
-	set_handler_callback(SWITCH+MAP+GROUP, cli_switch_group);
+	set_handler_callback(LIST|PATHS, cli_list_paths);
+	set_handler_callback(LIST|PATHS|FMT, cli_list_paths_fmt);
+	set_handler_callback(LIST|PATHS|RAW|FMT, cli_list_paths_raw);
+	set_handler_callback(LIST|PATH, cli_list_path);
+	set_handler_callback(LIST|MAPS, cli_list_maps);
+	set_handler_callback(LIST|STATUS, cli_list_status);
+	set_unlocked_handler_callback(LIST|DAEMON, cli_list_daemon);
+	set_handler_callback(LIST|MAPS|STATUS, cli_list_maps_status);
+	set_handler_callback(LIST|MAPS|STATS, cli_list_maps_stats);
+	set_handler_callback(LIST|MAPS|FMT, cli_list_maps_fmt);
+	set_handler_callback(LIST|MAPS|RAW|FMT, cli_list_maps_raw);
+	set_handler_callback(LIST|MAPS|TOPOLOGY, cli_list_maps_topology);
+	set_handler_callback(LIST|TOPOLOGY, cli_list_maps_topology);
+	set_handler_callback(LIST|MAPS|JSON, cli_list_maps_json);
+	set_handler_callback(LIST|MAP|TOPOLOGY, cli_list_map_topology);
+	set_handler_callback(LIST|MAP|FMT, cli_list_map_fmt);
+	set_handler_callback(LIST|MAP|RAW|FMT, cli_list_map_fmt);
+	set_handler_callback(LIST|MAP|JSON, cli_list_map_json);
+	set_handler_callback(LIST|CONFIG|LOCAL, cli_list_config_local);
+	set_handler_callback(LIST|CONFIG, cli_list_config);
+	set_handler_callback(LIST|BLACKLIST, cli_list_blacklist);
+	set_handler_callback(LIST|DEVICES, cli_list_devices);
+	set_handler_callback(LIST|WILDCARDS, cli_list_wildcards);
+	set_handler_callback(RESET|MAPS|STATS, cli_reset_maps_stats);
+	set_handler_callback(RESET|MAP|STATS, cli_reset_map_stats);
+	set_handler_callback(ADD|PATH, cli_add_path);
+	set_handler_callback(DEL|PATH, cli_del_path);
+	set_handler_callback(ADD|MAP, cli_add_map);
+	set_handler_callback(DEL|MAP, cli_del_map);
+	set_handler_callback(SWITCH|MAP|GROUP, cli_switch_group);
	set_unlocked_handler_callback(RECONFIGURE, cli_reconfigure);
-	set_handler_callback(SUSPEND+MAP, cli_suspend);
-	set_handler_callback(RESUME+MAP, cli_resume);
-	set_handler_callback(RESIZE+MAP, cli_resize);
-	set_handler_callback(RELOAD+MAP, cli_reload);
-	set_handler_callback(RESET+MAP, cli_reassign);
-	set_handler_callback(REINSTATE+PATH, cli_reinstate);
-	set_handler_callback(FAIL+PATH, cli_fail);
-	set_handler_callback(DISABLEQ+MAP, cli_disable_queueing);
-	set_handler_callback(RESTOREQ+MAP, cli_restore_queueing);
-	set_handler_callback(DISABLEQ+MAPS, cli_disable_all_queueing);
-	set_handler_callback(RESTOREQ+MAPS, cli_restore_all_queueing);
+	set_handler_callback(SUSPEND|MAP, cli_suspend);
+	set_handler_callback(RESUME|MAP, cli_resume);
+	set_handler_callback(RESIZE|MAP, cli_resize);
+	set_handler_callback(RELOAD|MAP, cli_reload);
+	set_handler_callback(RESET|MAP, cli_reassign);
+	set_handler_callback(REINSTATE|PATH, cli_reinstate);
+	set_handler_callback(FAIL|PATH, cli_fail);
+	set_handler_callback(DISABLEQ|MAP, cli_disable_queueing);
+	set_handler_callback(RESTOREQ|MAP, cli_restore_queueing);
+	set_handler_callback(DISABLEQ|MAPS, cli_disable_all_queueing);
+	set_handler_callback(RESTOREQ|MAPS, cli_restore_all_queueing);
	set_unlocked_handler_callback(QUIT, cli_quit);
	set_unlocked_handler_callback(SHUTDOWN, cli_shutdown);
-	set_handler_callback(GETPRSTATUS+MAP, cli_getprstatus);
-	set_handler_callback(SETPRSTATUS+MAP, cli_setprstatus);
-	set_handler_callback(UNSETPRSTATUS+MAP, cli_unsetprstatus);
-	set_handler_callback(FORCEQ+DAEMON, cli_force_no_daemon_q);
-	set_handler_callback(RESTOREQ+DAEMON, cli_restore_no_daemon_q);
-	set_handler_callback(GETPRKEY+MAP, cli_getprkey);
-	set_handler_callback(SETPRKEY+MAP+KEY, cli_setprkey);
-	set_handler_callback(UNSETPRKEY+MAP, cli_unsetprkey);
-	set_handler_callback(SETMARGINAL+PATH, cli_set_marginal);
-	set_handler_callback(UNSETMARGINAL+PATH, cli_unset_marginal);
-	set_handler_callback(UNSETMARGINAL+MAP, cli_unset_all_marginal);
+	set_handler_callback(GETPRSTATUS|MAP, cli_getprstatus);
+	set_handler_callback(SETPRSTATUS|MAP, cli_setprstatus);
+	set_handler_callback(UNSETPRSTATUS|MAP, cli_unsetprstatus);
+	set_handler_callback(FORCEQ|DAEMON, cli_force_no_daemon_q);
+	set_handler_callback(RESTOREQ|DAEMON, cli_restore_no_daemon_q);
+	set_handler_callback(GETPRKEY|MAP, cli_getprkey);
+	set_handler_callback(SETPRKEY|MAP|KEY, cli_setprkey);
+	set_handler_callback(UNSETPRKEY|MAP, cli_unsetprkey);
+	set_handler_callback(SETMARGINAL|PATH, cli_set_marginal);
+	set_handler_callback(UNSETMARGINAL|PATH, cli_unset_marginal);
+	set_handler_callback(UNSETMARGINAL|MAP, cli_unset_all_marginal);

	umask(077);
	uxsock_listen(&uxsock_trigger, ux_sock, ap);
--
2.31.1