Bug 13839

Summary: [CVE 21] fapolicyd 1.0.3 CVEs found
Product: [ROSA-based products] ROSA Fresh Reporter: Yury <y.tumanov>
Component: System (kernel, glibc, systemd, bash, PAM...)Assignee: ROSA Linux Bugs <bugs>
Status: VERIFIED FIXED QA Contact: ROSA Linux Bugs <bugs>
Severity: critical    
Priority: Highest CC: a.proklov, e.kosachev, e.malashin, s.matveev, v.potapov, y.tumanov
Version: AllFlags: v.potapov: qa_verified+
y.tumanov: secteam_verified+
a.proklov: published+
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: CVE-2022-1117,
Whiteboard:
Platform: 2021.1 ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:

Description Yury 2023-10-18 20:25:15 MSK
Please patch CVEs for package fapolicyd version 1.0.3
  
INFO (CVEs are): fapolicyd 1.0.3
 cves found
CVE-2022-1117
Desc: A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker, a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern detection for applications launched by the run time linker may fail to detect the pattern and allow execution.
Link: https://nvd.nist.gov/vuln/detail/CVE-2022-1117
Severity: HIGH
Comment 1 Vladimir Potapov 2023-10-20 12:46:12 MSK
*** Bug 13707 has been marked as a duplicate of this bug. ***
Comment 2 Vladimir Potapov 2023-10-20 12:46:25 MSK
*** Bug 13487 has been marked as a duplicate of this bug. ***
Comment 3 Aleksandr Proklov 2023-10-26 07:08:18 MSK
Предлагаю закрыть обновлением

fapolicyd	1.3.2-2

https://abf.io/build_lists/4765022
https://abf.io/build_lists/4765023
https://abf.io/build_lists/4765024
https://abf.io/build_lists/4765025
https://abf.io/build_lists/4765026
Comment 4 Yury 2023-10-27 21:22:05 MSK
secteam_verified
Comment 5 e.malashin@rosalinux.ru 2023-11-14 13:45:08 MSK
(In reply to Aleksandr Proklov from comment #3)
> Предлагаю закрыть обновлением
> 
> fapolicyd	1.3.2-2
> 
> https://abf.io/build_lists/4765022
> https://abf.io/build_lists/4765023
> https://abf.io/build_lists/4765024
> https://abf.io/build_lists/4765025
> https://abf.io/build_lists/4765026

==============================================================================================================================================================================================
 Пакет                         Архитектура                Версия                      Репозиторий                                                                                       Размер
==============================================================================================================================================================================================
Удаление:
 fapolicyd                     x86_64                     1.3.2-2                     @abf-downloads.rosalinux.ru_rosa2021.1_container_4765023_x86_64_main_release_                     340 k

Результат транзакции
==============================================================================================================================================================================================
Удаление  1 Пакет

Освобожденное место: 340 k
Продолжить? [д/Н]: y
Проверка транзакции
Проверка транзакции успешно завершена.
Идет проверка транзакции
Тест транзакции проведен успешно.
Выполнение транзакции
  Подготовка       :                                                                                                                                                                      1/1 
  Запуск скриптлета: fapolicyd-1.3.2-2.x86_64                                                                                                                                             1/1 
/var/tmp/rpm-tmp.WxqH03: строка 10: fg: нет управления заданиями
ошибка: %preun(fapolicyd-1.3.2-2.x86_64) scriptlet failed, exit status 1

Error in PREUN scriptlet in rpm package fapolicyd
  Проверка         : fapolicyd-1.3.2-2.x86_64                                                                                                                                             1/1 

Сбой:
  fapolicyd-1.3.2-2.x86_64                                                                                                                                                                    

Ошибка: Сбой транзакции
Comment 6 e.malashin@rosalinux.ru 2023-11-14 13:58:02 MSK
Пакет не удаляется из системы
Comment 8 e.malashin@rosalinux.ru 2023-11-15 12:41:48 MSK
(In reply to Aleksandr Proklov from comment #7)
> Исправил вроде.
> 
> fapolicyd	1.3.2-3
> 
> https://abf.io/build_lists/4824122
> https://abf.io/build_lists/4824123 х64
> https://abf.io/build_lists/4824124
> https://abf.io/build_lists/4824125
> https://abf.io/build_lists/4824126

The update sent to testings
Comment 9 Vladimir Potapov 2023-11-22 16:23:16 MSK
fapolicyd-1.3.2-3
https://abf.io/build_lists/4824122
https://abf.io/build_lists/4824123 х64
https://abf.io/build_lists/4824124
https://abf.io/build_lists/4824125
https://abf.io/build_lists/4824126
********************** Advisory ***********************
CVE-2022-1117 fix by version update
*******************************************************
QA Verified