Commit Graph

18450 Commits

Author SHA1 Message Date
Roland C. Dowdeswell 6bb4ff842d lib/roken: fix hex digit table initializer 2026-07-06 09:06:35 -05:00
Daniil Sarafannikov 5b90bc8285 roken:strsep_copy: Fix out-of-bounds write in strsep_copy
In case len < (size_t)(*stringp - save) and len > 0
access to buf[l] leads to out-of-bounds write as
l = len and len means the length of buffer.

Change evaluation of l: only len - 1 elements of
buffer can be used for memcpy and terminator
should be written to buf[len - 1] (in case l = len - 1).
Also, this value of l is not used when len == 0,
so we calculate it only when len > 0.

Pair-Programmed-With: Dmitry Mikhalchenko <tascad@altlinux.org>
Signed-off-by: Daniil Sarafannikov <sarafannikovda@sgu.ru>
2026-06-30 10:19:03 +01:00
Linar Galimov ac1c2d05bc krb5: Fix a double free when running into ENOMEM
In cred_delete(), sp is freed after returning from krb5_storage_to_data().
Between this point and the subsequent assignment to sp via krb_storage_emem()
there are two jumps to out, both are executed in an ENOMEM scenario: malloc fail
for cred_data_in_file and krb5_principal_set_realm() fail. In out, sp is freed
again.

This patch fixes the issue by freeing sp right before the krb5_storage_emem()
call.

Signed-off-by: Linar Galimov <galimovlz@sgu.ru>
Signed-off-by: Dmitry Mikhalchenko <tascad@altlinux.org>
2026-06-23 15:34:32 +01:00
Roland C. Dowdeswell 37f93f85dd gss-token: add local user authorization check 2026-06-22 18:43:44 +01:00
mikhailofff afc4c486a1 lib/asn1: fix USE_AFTER_FREE in der_print_hex_heim_integer
Set *p to NULL on asprintf failure to prevent a dangling pointer
and subsequent USE_AFTER_FREE when the caller ignores ENOMEM.

Pair-Programmed-With: Dmitry Mikhalchenko <tascad@altlinux.org>
Signed-off-by: Egor Mikhailov <mikhailovev@sgu.ru>
2026-06-18 17:23:24 -05:00
Roland C. Dowdeswell 5ac91f2dc9 hx509: preserve received certificate encodings
Keep the original DER encoding around when decoding certificates so hx509_cert_binary() does not rewrite certificates unnecessarily.

Add regression coverage for direct certificate binary output and keyless stores.
2026-06-16 11:02:29 -05:00
Roland C. Dowdeswell 9cf1b20313 asn1: clamp far-future times on 32-bit time_t
Compute DER generalized time conversion in uint64_t and clamp to the
local time_t range before returning.  This avoids wrapping far-future
ASN.1 times on 32-bit time_t platforms.  We do not address time_t
being a non-integral type.
2026-06-15 14:09:41 -05:00
Roland C. Dowdeswell 97b07c5632 krb5: skip vanished keyring ccache keys 2026-06-10 17:26:54 -05:00
Roland C. Dowdeswell 8a0fc8d032 Add credential cache coverage tests 2026-06-10 17:26:54 -05:00
Roland C. Dowdeswell 34ab0b7c77 asn1: fix open type alignment on ILP32
Do not assume that the open-type payload needs 8-byte alignment.
Align to pointer size instead, which avoids reading the wrong location
on ILP32 layouts.
2026-06-10 10:38:43 -05:00
Roland C. Dowdeswell 9bb80f4747 hx509: choose certificate time encoding portably
Select UTCTime versus GeneralizedTime with a helper that only performs
the 2050 comparison when the local time_t range can represent that value.
This avoids ILP32 type-limit problems while preserving GeneralizedTime
output on 64-bit and unsigned 32-bit time_t platforms.
2026-06-10 09:59:13 -05:00
Roland C. Dowdeswell 5ebe5b4582 asn1: compare int32 default values safely
Move the int32 ptr comparison into a helper that first checks
whether the encoded pointer-sized default is representable as int32_t.
This avoids ILP32 type-limit warnings.
2026-06-10 09:57:03 -05:00
Roland C. Dowdeswell f609aae209 krb5: avoid time-difference overflow
Use krb5_time_abs() rather than subtracting time_t values before passing the result to labs().  On signed 32-bit time_t platforms, subtracting far-apart times can overflow before labs() sees the value.
2026-06-10 09:39:19 -05:00
Pino Toscano 2194be6c92 asn1: Include <errno.h> before using/checking bits from it
Commit 232c936ea3 added a fallback ENOTSUP
definition. The check itself and the fallback definition rely on
<errno.h> to be included already, so in case it was not (depending on
the platform) then there will be a wrong definition of ENOTSUP.

Instead of rely on <errno.h> to be included before including a
generated header from this tool, include it manually. This way both
the ENOTSUP check and its fallback definition (if ever) will always
work.
2026-06-06 23:54:47 +01:00
Roland C. Dowdeswell a735b65b70 gssapi: avoid putenv use-after-free in store_cred
Fixes #1163
2026-06-06 23:38:21 +01:00
Roy Marples 1f0f31c954 roken: Don't define any global vars in the pidfile namespace.
Newer util.h from NetBSD defines pidfile_path() which conflicts
here.
2026-05-30 12:06:31 -05:00
Roland C. Dowdeswell 421c40c73e kadm5: make ipropd-master listen on IPv6
Fixes #1330.
2026-05-27 14:11:04 -05:00
Roland C. Dowdeswell de7aa57362 treewide: fix many null dereference reports
Add defensive handling for several NULL allocation and formatting paths reported across issues #820-#829.

Fixes #820, fixes #821, fixes #822, fixes #823, fixes #825, fixes #828
2026-05-27 13:47:41 -05:00
Roland C. Dowdeswell 9a9da70626 krb5: clean up get_cred_kdc on send context failure
Fixes #1207
2026-05-27 12:12:03 -05:00
Roland C. Dowdeswell 98d6fcacb4 krb5: fix ap_req_nofail documentation
Fixes #1371
2026-05-27 11:56:23 -05:00
Roland C. Dowdeswell 4f147f5e1b doc: trim krb5_verify_user xrefs
Fixes #1127
2026-05-27 16:01:16 +01:00
Roland C. Dowdeswell ef3860d6c3 doc: clean up krb5_init_context man page
Fixes #1125
2026-05-27 15:42:57 +01:00
Alexey Shapovalov 20d4e914e3 gss: Fix NULL minor_status arguments 2026-05-27 14:30:27 +01:00
Florian Best cdd22b6061 refactor(changepw): replace select() with poll()
Issue #1338
2026-05-27 14:16:23 +01:00
Florian Best 73acb1df8e refactor(send_to_kdc): replace select() with poll()
Issue #1338
2026-05-27 14:16:23 +01:00
Roland C. Dowdeswell abec12ef7f ipropd-slave: get a TGT before authenticating
Do not request an iprop/<master> initial ticket directly. With
name_canon_rules = as-is: this can leave the acquired credential
mismatched with what krb5_sendauth() later asks for. Get a normal TGT
and let sendauth acquire the service ticket.

Fixes #1332.
2026-05-26 17:20:15 -05:00
Roland C. Dowdeswell a66cb84e70 In krb5.conf make underscores and dashes equivalent 2026-05-25 20:14:36 -05:00
Roland C. Dowdeswell e89417f2a1 tests: cover MEMORY ccache cursor invalidation for #547 2026-05-25 20:09:20 -05:00
Roland C. Dowdeswell a105e8e117 tests: cover MEMORY gss_store_cred storage for #132 2026-05-25 20:01:05 -05:00
Roland C. Dowdeswell e836e36d06 Remove duplicated libedit, find/use installed version 2026-05-25 20:00:24 -05:00
Roland C. Dowdeswell 19325d4252 lib/gssapi/test_context.c: fix typo 2026-05-25 19:59:28 -05:00
Roland C. Dowdeswell 3ff4191ba9 krb5: fail krb5_verify_user() early if service key missing
Fixes #1157.
2026-05-25 19:42:40 -05:00
Roland C. Dowdeswell d47f526f55 ipc: serialize mig generated files 2026-05-25 17:32:05 -05:00
Roland C. Dowdeswell 6efb8b405e roken: provide poll fallback 2026-05-25 17:31:26 -05:00
Jennifer Sutton c65cd331e4 gsskrb5: Correctly check EVP_Cipher() return value for RC4
If the flag EVP_CIPH_FLAG_CUSTOM_CIPHER is set for the cipher, EVP_Cipher()
returns the number of bytes written to ‘out’.
2026-05-20 11:46:35 -05:00
Jennifer Sutton f93aeb3f8f krb5: Correctly check if RC4 enctype is valid
krb5_enctype_valid() returns zero on success.
2026-05-20 11:45:57 -05:00
Jennifer Sutton dafc36e26c krb5: Promote AES SHA2 enctypes to preferred 2026-05-20 11:45:57 -05:00
Jennifer Sutton b7f4f62dfa krb5: Fix non‐RC4 build
The function _krb5_usage2arcfour() is only declared if Heimdal is built with
RC4. Put calls to this function behind #ifdef guards so that the build can
succeed.
2026-05-20 11:43:53 -05:00
Roland C. Dowdeswell e4a885074b krb5: make KRB5_TRACE default to tracing not just debugging 2026-05-19 12:01:42 -05:00
Ivan Korytov ffb01963fc lib:roken: allow large fragmented UDP replies from glibc resolver
glibc resolver returns same answer length as buffer size when
buffer is too small for the answer.

Signed-off-by: Ivan Korytov <toreonify@altlinux.org>
2026-05-19 11:52:18 -05:00
Roland C. Dowdeswell 8dba1f4810 add a bit more logging in gss mechglue 2026-05-19 11:14:39 -05:00
Roland C. Dowdeswell e11f8a8823 Eliminate \n from _gss_mg_log() calls 2026-05-19 11:14:39 -05:00
Nicolas Williams 609e36de13 krb5: Only lock keytabs to write to them (fix #1319) 2026-02-08 01:30:28 -06:00
Nicolas Williams ce85c64b84 iprop: Make ipropd-master not lock the log (fix #1308) 2026-02-07 17:59:03 -06:00
Nicolas Williams c76a096a28 roken: Add pread() for Windows 2026-02-07 17:59:03 -06:00
Nicolas Williams 8a22366b55 roken: Don't define flock() ops if HAVE_FLOCK (fix #1313) 2026-02-07 17:46:19 -06:00
Nicolas Williams 1a7e3c4a5c kadm5: Fix client-side double-free (fix #1315) 2026-02-07 17:46:19 -06:00
Nicolas Williams 26dca502be kpasswdd: Allow password changes through NATs (fix #1286 again) 2026-01-23 00:37:44 -06:00
Nicolas Williams cc272a4838 krb5: Try up to all kpasswdd IPs (fix #1304) 2026-01-22 23:38:42 -06:00
Nicolas Williams dedeea1b6a sqlite: Fix warnings (fix #1306) 2026-01-22 23:32:14 -06:00