mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-09 17:03:35 -09:00
package/nginx: patch CVE-2025-53859
Fix the following vulnerability:
- CVE-2025-53859:
NGINX Open Source and NGINX Plus have a vulnerability in the
ngx_mail_smtp_module that might allow an unauthenticated attacker to
over-read NGINX SMTP authentication process memory; as a result, the
server side may leak arbitrary bytes sent in a request to the
authentication server. This issue happens during the NGINX SMTP
authentication process and requires the attacker to make preparations
against the target system to extract the leaked data. The issue
affects NGINX only if (1) it is built with the ngx_mail_smtp_module,
(2) the smtp_auth directive is configured with method "none," and (3)
the authentication server returns the "Auth-Wait" response header.
Note: Software versions which have reached End of Technical Support
(EoTS) are not evaluated.
For more information, see:
- https://nvd.nist.gov/vuln/detail/CVE-2025-53859
- https://nginx.org/download/patch.2025.smtp.txt
(cherry picked from commit a0081aa1f8)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
130
package/nginx/0010-CVE-2025-53859.patch
Normal file
130
package/nginx/0010-CVE-2025-53859.patch
Normal file
@@ -0,0 +1,130 @@
|
||||
CVE: CVE-2025-53859
|
||||
Upstream: https://nginx.org/download/patch.2025.smtp.txt
|
||||
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
|
||||
|
||||
diff --git a/src/mail/ngx_mail_handler.c b/src/mail/ngx_mail_handler.c
|
||||
index 1167df3fb..d3be7f3b3 100644
|
||||
--- a/src/mail/ngx_mail_handler.c
|
||||
+++ b/src/mail/ngx_mail_handler.c
|
||||
@@ -523,7 +523,7 @@ ngx_mail_starttls_only(ngx_mail_session_t *s, ngx_connection_t *c)
|
||||
ngx_int_t
|
||||
ngx_mail_auth_plain(ngx_mail_session_t *s, ngx_connection_t *c, ngx_uint_t n)
|
||||
{
|
||||
- u_char *p, *last;
|
||||
+ u_char *p, *pos, *last;
|
||||
ngx_str_t *arg, plain;
|
||||
|
||||
arg = s->args.elts;
|
||||
@@ -555,7 +555,7 @@ ngx_mail_auth_plain(ngx_mail_session_t *s, ngx_connection_t *c, ngx_uint_t n)
|
||||
return NGX_MAIL_PARSE_INVALID_COMMAND;
|
||||
}
|
||||
|
||||
- s->login.data = p;
|
||||
+ pos = p;
|
||||
|
||||
while (p < last && *p) { p++; }
|
||||
|
||||
@@ -565,7 +565,8 @@ ngx_mail_auth_plain(ngx_mail_session_t *s, ngx_connection_t *c, ngx_uint_t n)
|
||||
return NGX_MAIL_PARSE_INVALID_COMMAND;
|
||||
}
|
||||
|
||||
- s->login.len = p++ - s->login.data;
|
||||
+ s->login.len = p++ - pos;
|
||||
+ s->login.data = pos;
|
||||
|
||||
s->passwd.len = last - p;
|
||||
s->passwd.data = p;
|
||||
@@ -583,24 +584,26 @@ ngx_int_t
|
||||
ngx_mail_auth_login_username(ngx_mail_session_t *s, ngx_connection_t *c,
|
||||
ngx_uint_t n)
|
||||
{
|
||||
- ngx_str_t *arg;
|
||||
+ ngx_str_t *arg, login;
|
||||
|
||||
arg = s->args.elts;
|
||||
|
||||
ngx_log_debug1(NGX_LOG_DEBUG_MAIL, c->log, 0,
|
||||
"mail auth login username: \"%V\"", &arg[n]);
|
||||
|
||||
- s->login.data = ngx_pnalloc(c->pool, ngx_base64_decoded_length(arg[n].len));
|
||||
- if (s->login.data == NULL) {
|
||||
+ login.data = ngx_pnalloc(c->pool, ngx_base64_decoded_length(arg[n].len));
|
||||
+ if (login.data == NULL) {
|
||||
return NGX_ERROR;
|
||||
}
|
||||
|
||||
- if (ngx_decode_base64(&s->login, &arg[n]) != NGX_OK) {
|
||||
+ if (ngx_decode_base64(&login, &arg[n]) != NGX_OK) {
|
||||
ngx_log_error(NGX_LOG_INFO, c->log, 0,
|
||||
"client sent invalid base64 encoding in AUTH LOGIN command");
|
||||
return NGX_MAIL_PARSE_INVALID_COMMAND;
|
||||
}
|
||||
|
||||
+ s->login = login;
|
||||
+
|
||||
ngx_log_debug1(NGX_LOG_DEBUG_MAIL, c->log, 0,
|
||||
"mail auth login username: \"%V\"", &s->login);
|
||||
|
||||
@@ -611,7 +614,7 @@ ngx_mail_auth_login_username(ngx_mail_session_t *s, ngx_connection_t *c,
|
||||
ngx_int_t
|
||||
ngx_mail_auth_login_password(ngx_mail_session_t *s, ngx_connection_t *c)
|
||||
{
|
||||
- ngx_str_t *arg;
|
||||
+ ngx_str_t *arg, passwd;
|
||||
|
||||
arg = s->args.elts;
|
||||
|
||||
@@ -620,18 +623,19 @@ ngx_mail_auth_login_password(ngx_mail_session_t *s, ngx_connection_t *c)
|
||||
"mail auth login password: \"%V\"", &arg[0]);
|
||||
#endif
|
||||
|
||||
- s->passwd.data = ngx_pnalloc(c->pool,
|
||||
- ngx_base64_decoded_length(arg[0].len));
|
||||
- if (s->passwd.data == NULL) {
|
||||
+ passwd.data = ngx_pnalloc(c->pool, ngx_base64_decoded_length(arg[0].len));
|
||||
+ if (passwd.data == NULL) {
|
||||
return NGX_ERROR;
|
||||
}
|
||||
|
||||
- if (ngx_decode_base64(&s->passwd, &arg[0]) != NGX_OK) {
|
||||
+ if (ngx_decode_base64(&passwd, &arg[0]) != NGX_OK) {
|
||||
ngx_log_error(NGX_LOG_INFO, c->log, 0,
|
||||
"client sent invalid base64 encoding in AUTH LOGIN command");
|
||||
return NGX_MAIL_PARSE_INVALID_COMMAND;
|
||||
}
|
||||
|
||||
+ s->passwd = passwd;
|
||||
+
|
||||
#if (NGX_DEBUG_MAIL_PASSWD)
|
||||
ngx_log_debug1(NGX_LOG_DEBUG_MAIL, c->log, 0,
|
||||
"mail auth login password: \"%V\"", &s->passwd);
|
||||
@@ -674,24 +678,26 @@ ngx_int_t
|
||||
ngx_mail_auth_cram_md5(ngx_mail_session_t *s, ngx_connection_t *c)
|
||||
{
|
||||
u_char *p, *last;
|
||||
- ngx_str_t *arg;
|
||||
+ ngx_str_t *arg, login;
|
||||
|
||||
arg = s->args.elts;
|
||||
|
||||
ngx_log_debug1(NGX_LOG_DEBUG_MAIL, c->log, 0,
|
||||
"mail auth cram-md5: \"%V\"", &arg[0]);
|
||||
|
||||
- s->login.data = ngx_pnalloc(c->pool, ngx_base64_decoded_length(arg[0].len));
|
||||
- if (s->login.data == NULL) {
|
||||
+ login.data = ngx_pnalloc(c->pool, ngx_base64_decoded_length(arg[0].len));
|
||||
+ if (login.data == NULL) {
|
||||
return NGX_ERROR;
|
||||
}
|
||||
|
||||
- if (ngx_decode_base64(&s->login, &arg[0]) != NGX_OK) {
|
||||
+ if (ngx_decode_base64(&login, &arg[0]) != NGX_OK) {
|
||||
ngx_log_error(NGX_LOG_INFO, c->log, 0,
|
||||
"client sent invalid base64 encoding in AUTH CRAM-MD5 command");
|
||||
return NGX_MAIL_PARSE_INVALID_COMMAND;
|
||||
}
|
||||
|
||||
+ s->login = login;
|
||||
+
|
||||
p = s->login.data;
|
||||
last = p + s->login.len;
|
||||
@@ -19,6 +19,9 @@ NGINX_CONF_OPTS = \
|
||||
--with-cpp="$(TARGET_CC)" \
|
||||
--with-ld-opt="$(TARGET_LDFLAGS)"
|
||||
|
||||
# 0010-CVE-2025-53859.patch
|
||||
NGINX_IGNORE_CVES += CVE-2025-53859
|
||||
|
||||
# www-data user and group are used for nginx. Because these user and group
|
||||
# are already set by buildroot, it is not necessary to redefine them.
|
||||
# See system/skeleton/etc/passwd
|
||||
|
||||
Reference in New Issue
Block a user