6 ms·
RCE via ND6 Router Advertisements in FreeBSD
- _f9cu 10mo agois my understanding right? "PC or computers or hardware that uses OS that consume FreeBSD, has a faulty software for the router's firmware?" "The router's software performs ad distributions?" "The version of internet, the router uses, is updated, whereas, the target machine, or the user's machine is still running a old version" "The security patch works for the modern but not the precursor version?" "This leaves older systems obsolete in the market?" "is this a step-by-step instructions to business owners to introduce new products, selling that older products are obsolete" ?
- eptcyka 10mo agoNo, I don't think you are understanding this right, but there are some good questions you are asking. Where is the flag button? If you are a real human, the most interesting question you're bringing up is What about all the appliances backed by FreeBSD? Yes, they are obsolete if they use IPv6 and accept RAs and if they don't get updates.
- jacquesm 10mo agoThat was my first thought, if this is an embedded system without an update path this will be super hard to solve. People usually are not even aware of what OS their appliances run under the hood and whether or not they are updated automatically and how to update them if they are not.
- jacquesm 10mo agoOh that's a nasty one, embedded FreeBSD users will have a hard time mitigating this.
- formerly_proven 10mo agoFree jailbreaks for everyone though!
- jacquesm 10mo agoWe had a soccer player in NL that was wildly popular and he had these funny remarks every now and then which got him nicknamed the most well known dutch philosopher. One of these was 'every advantage has its disadvantage', I guess this is one of those.
- tecleandor 10mo agoHa! He was famous for that even when coaching in Spain
- atmosx 10mo agoIs the op referring to J. Cruyff?
- tecleandor 10mo agoI think so!
- wyldfire 10mo ago> It's pronounced "Cruyff".
- gosub100 10mo agoOoh maybe for playstation?
- crest 10mo agoThe mitigation is applying the security patch, using static IPv6 addresses, or using a userspace client like dhcpcd.
- TekMol 10mo agovulnerable to remote code execution from systems on the same network segment Isn't almost every laptop these days autoconnecting to known network names like "Starbucks" etc, because the user used it once in the past? That would mean that every FreeBSD laptop in proximity of an attacker is vulnerable, right? Since the attacker could just create a hotspot with the SSID "Starbucks" on their laptop and the victim's laptop will connect to it automatically.
- francasso 10mo agoIf you run FreeBSD on your laptop you don't auto connect to public WiFi. Joking, but not that much :)
- badgersnake 10mo agoYour wifi chip probably isn’t supported tbh.
- keyle 10mo agoThis is the real joke.
- BSDobelix 10mo agoFreeBSD 15 had a massive improvement with WiFi, however if you let your Computer auto-connect to a "unknown" Network...well that's not good.
- TekMol 10mo agoMy question was about known networks. As far as I know, access points only identify via their SSID. Which is a string like "Starbucks". So there is no way to tell if it is the real Starbucks WiFi or a hotspot some dude started on their laptop.
- BSDobelix 10mo ago>So there is no way to tell if it is the real Starbucks WiFi or a hotspot some dude started on their laptop. Aka "unknown" or "public" Network....don't do that.
- rs_rs_rs_rs_rs 10mo agoIPv6 is a prerequisite for the bug to be exploited, it won't affect anyone.
- ale42 10mo agoWhy, is IPv6 activation manual in FreeBSD?
- rs_rs_rs_rs_rs 10mo agoIt's enabled by default, I was mostly talking about being in a lan with active ipv6, imo that's not that common.
- tuetuopay 10mo agoCan we be done with the house of cards that are shell scripts everywhere? Anyways, this feels like a big issue for "hidden" FreeBSD installs, like pfSense or TrueNAS (if they are still based on it though). Or for servers on hosting providers where they share a LAN with their neighbors in the same rack. And it's a big win for jailbreaking routers :D
- wahern 10mo agoSure, as long as the solution isn't to just bolt on another distinct DNS monolith. The root of the problem IMO is that no libc, AFAIK, exports an API for parsing, let alone composing or manipulating, resolv.conf formatted data. The solutions have either been the same as FreeBSD (openresolv, a portable implementation of Debian's resolvconf tool), or just freezing resolv.conf (notwithstanding occassional new libc features) and bolting atop (i.e. keeping in place) the existing infrastructure a monolithic resolver service with their own bespoke configs, such as macOS and Linux/systemd have done. But resolv.conf can never go away, because it's the only sane and portable way for your average userland program to load DNS configuration, especially async resolver libraries. It's a coordination problem. Note that the original notion of resolvconf, IIUC, was it was only stitching together trusted configuration data. That's no excuse, of course, for not rigorously isolating data from execution, which is more difficult in shell scripts--at least, if you're not treating the data as untrusted from the get go. It's not that difficult to write shell code to handle untrusted data, you just can't hack it together without keeping this is mind. And it would be much easier if the resolver infrastructure in libc had a proper API for dealing with resolv.conf (and others), which could be exported by a small utility which in turn could be used to slice and dice configurations from shell scripts. The problem with the new, alternative monoliths is they very quickly run off into the weeds with their crazy features and configuration in ways that create barriers for userland applications and libraries to rely upon, beyond bootstrapping them to query 127.0.0.1:53. At the end of the day, resolv.conf can never really go away. So the proper solution, IMO, is to begin to carefully build layers around the one part that we know for a fact won't go away, rather than walking away with your ball to build a new playground. But that requires some motivated coordination and cooperation with libc developers.
- 10mo ago
- wahern 10mo agoIs somebody fuzzing IPv6 autoconfiguration stacks? OpenBSD published an nd6 kernel fix earlier this month for an unrelated issue: https://ftp.openbsd.org/pub/OpenBSD/patches/7.8/common/011_nd6.patch.sig https://ftp.openbsd.org/pub/OpenBSD/patches/7.8/common/011_n...
- clan 10mo agoThis actually makes me happy! I must be getting old! It truly is a bad one but I really appreciate Kevin Day for finding/reporting this and for all the volunteer work fixing this. All I had to do was "freebsd-update fetch install && reboot" on my systems and I could continue my day. Fleet management can be that easy for both pets and cattle. I do however feel for those who have deployed embedded systems. We can only hope the firmware vendors are on top of their game. My HN addiction is now vindicated as I would probably not have noticed this RCE until after christmas. This makes me very grateful and gives me a warm fuzzy feeling inside!
- barnas2 10mo ago> We can only hope the firmware vendors are on top of their game. You should go into comedy, this would kill at an open mic!
- formerly_proven 10mo ago> My HN addiction is now vindicated as I would probably not have noticed this RCE until after christmas. Always makes sense to subscribe to the security-announce mailing list of major dependencies (distro/vendor, openssh, openssl etc.) and oss-security.
- tete 10mo agoWhere major dependency is everything that even indirectly touches network. Doesn't really matter if the thing that gives everyone access to your systems is major or not.
- elcritch 10mo agoIf it’s a shell script fix does it even need a reboot?
- cornonthecobra 10mo agoEven better, the reboot wasn't needed as the kernel didn't get bumped on this one. Just restart the rtsold service if you're using it and sanity check your resolv.conf and resolvconf.conf. As for noticing it quickly, add `freebsd-update cron` to crontab and it will email you the fetch summary when updates are available
- chaz6 10mo agoHaving a shell script in the code path that processes router advertisements seems sub-optimal.
- IshKebab 10mo agoIt's amazing the number of people that thing shell scripts should be anything other than throwaway single-person hacks. They should probably go through their whole system and verify that there aren't more shell scripts being used, e.g. in the init system. Ideally a default distro would have zero shell scripts.
- valleyer 10mo agoI can't tell whether you're making a joke, seeing as the entire BSD init system is built on shell scripts.
- cesarb 10mo agoProbably not a joke. In the same way people want to get away from the C language due to its propensity to memory vulnerabilities, shell scripts have their own share of footguns, the most common being a variable not being quoted when it should (which is exactly the issue described in this advisory). It doesn't mean getting away from scripting languages; it means getting away from shell scripts in particular (the parent poster said specifically "zero shell scripts"). If the script in question was written in Lua, or heck even Javascript, this particular issue most probably wouldn't have happened, since these scripting languages do not require the programmer to manually quote every single variable use.
- valleyer 10mo agoThat's fine; I just thought it was weird to say that we should check to see whether any shell scripts are used in the BSD init system. We know there are; it was a deliberate design decision at the time, even if we might now wish for it to be different.
- 10mo ago
- VoidWhisperer 10mo ago> no workaround > IPv6 users that do not configure the system to accept router advertisement messages, are not affected. Maybe I'm missing something but isnt that a workaround?
- bah_humbug 10mo ago> resolvconf(8) is a shell script which does not validate its input. A lack of quoting meant that shell commands pass as input to resolvconf(8) may be executed. The fix consists of implementing an XXX present since the code was added: /* * XXX validate that domain name only contains valid characters * for two reasons: 1) correctness, 2) we do not want to pass * possible malicious, unescaped characters like `` to a script * or program that could be exploited that way. */ https://www.freebsd.org/security/patches/SA-25:12/rtsold.patch https://www.freebsd.org/security/patches/SA-25:12/rtsold.pat...
- jandrese 10mo agoIt is wild that it was in that state for so long. It probably took just about as long to write that comment as it would have to implement the proper solution.
- apstls 10mo agogrep --include=*.{c,h} -rnw -B3 -A15 'XXX' ./ | claude -p 'Analyze each code snippet and pick the five most concerning, from a security perspective.'