diff --git a/SPECS/perl-HTTP-Daemon/CVE-2026-8450.patch b/SPECS/perl-HTTP-Daemon/CVE-2026-8450.patch new file mode 100644 index 00000000000..433d0b3bfef --- /dev/null +++ b/SPECS/perl-HTTP-Daemon/CVE-2026-8450.patch @@ -0,0 +1,113 @@ +From 69a56a5ddec54d2b78e3653b8809af84da94eb3a Mon Sep 17 00:00:00 2001 +From: Olaf Alders +Date: Thu, 14 May 2026 00:09:58 +0000 +Subject: [PATCH] Fix CVE-2026-8450: send_file() honoured 2-arg open() + shell-magic + +HTTP::Daemon::ClientConn::send_file() used the 2-arg form +open(FILE, $file), which interprets shell-magic prefixes in the +path argument: '| cmd' (write pipe -- RCE), 'cmd |' (read pipe -- +RCE plus response-body exfiltration via the sysread / print loop +below), '> path' (write-truncate -- arbitrary file write), and +'>> path', '+< path', '<&fd', and leading-whitespace variants of +the above. + +Any HTTP::Daemon-based application that passed attacker-influenced +bytes to send_file($string) -- for example, a download endpoint +that derived the filename from a query parameter -- granted command +execution and/or arbitrary file write at the daemon's UID. + +Switch to 3-arg open(my $fh, '<', $file): the explicit '<' mode +makes the path argument a literal filename, so every magic shape +above is opened (and fails, returning undef) as an ordinary file by +that exact name. The localized typeglob is no longer needed and is +replaced with a lexical filehandle. + +Two collateral hardening changes ride along: + + - binmode() failure now closes the handle and returns undef, + rather than streaming the file with a wrong PerlIO layer. + + - send_file() returns '0E0' (true zero) on a successful zero-byte + transfer so callers using "send_file or die" can distinguish + open failure (undef) from an empty-but-successful copy. + +The POD now documents the new return-value contract and spells +out that the fix only neutralises 2-arg open() shell-magic; +callers remain responsible for validating attacker-influenced +paths against symlinks, character/block devices (e.g. /dev/zero), +named pipes, and document-root escapes. + +Reported and patched by Stig Palmquist (stigtsp). + +Co-Authored-By: Claude Opus 4.7 +Signed-off-by: Azure Linux Security Servicing Account +Upstream-reference: https://github.com/libwww-perl/HTTP-Daemon/commit/945d35141d94490f749640bd4390acd6a2193995.patch +--- + lib/HTTP/Daemon.pm | 35 ++++++++++++++++++++++++++++++----- + 1 file changed, 30 insertions(+), 5 deletions(-) + +diff --git a/lib/HTTP/Daemon.pm b/lib/HTTP/Daemon.pm +index f9b3216..0707b9b 100644 +--- a/lib/HTTP/Daemon.pm ++++ b/lib/HTTP/Daemon.pm +@@ -592,11 +592,10 @@ sub send_dir { + sub send_file { + my ($self, $file) = @_; + my $opened = 0; +- local (*FILE); + if (!ref($file)) { +- open(FILE, $file) || return undef; +- binmode(FILE); +- $file = \*FILE; ++ open(my $fh, '<', $file) || return undef; ++ binmode($fh) || do { close($fh); return undef }; ++ $file = $fh; + $opened++; + } + my $cnt = 0; +@@ -608,7 +607,11 @@ sub send_file { + print $self $buf; + } + close($file) if $opened; +- $cnt; ++ ++ # Return a "true zero" for empty-but-successful copies so callers ++ # using `send_file or die` can distinguish open failure (undef) ++ # from a successful zero-byte transfer. ++ $cnt || '0E0'; + } + + sub daemon { +@@ -902,6 +905,28 @@ Copy the file to the client. The file can be a string (which + will be interpreted as a filename) or a reference to an C + or glob. + ++Returns the number of bytes copied on success, or C if the ++filename form failed to open. An empty file returns the string ++C<'0E0'> (zero numerically, true in boolean context) so that callers ++using C<< send_file or die >> can distinguish open failure from a ++successful zero-byte transfer. ++ ++The filename form uses Perl's 3-argument C with an explicit C<< ++< >> mode, so the path is no longer interpreted as a 2-argument ++C shell-magic shape such as C<< | cmd >>, C<< cmd | >>, or ++C<< > path >>. See ++L for ++the prior 2-argument C behaviour this replaces. ++ ++Note that this fix only neutralises 2-argument C shell-magic. ++Callers remain responsible for validating attacker-influenced paths: ++C will still happily open symlinks, character/block devices ++(e.g. C, C), named pipes (which may block the ++worker), and files outside an intended document root. If C<$filename> ++can be derived from request input, validate it (canonicalise, reject ++C<..> segments, require C<-f _> and a vetted prefix) before passing it ++in. ++ + =item $c->daemon + + Return a reference to the corresponding C object. +-- +2.45.4 + diff --git a/SPECS/perl-HTTP-Daemon/perl-HTTP-Daemon.spec b/SPECS/perl-HTTP-Daemon/perl-HTTP-Daemon.spec index 2edbd81c0e6..51f6f7007f4 100644 --- a/SPECS/perl-HTTP-Daemon/perl-HTTP-Daemon.spec +++ b/SPECS/perl-HTTP-Daemon/perl-HTTP-Daemon.spec @@ -1,6 +1,6 @@ Name: perl-HTTP-Daemon Version: 6.16 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Simple HTTP server class License: GPL+ or Artistic Vendor: Microsoft Corporation @@ -9,6 +9,7 @@ URL: https://metacpan.org/release/HTTP-Daemon Source0: https://cpan.metacpan.org/authors/id/O/OA/OALDERS/HTTP-Daemon-%{version}.tar.gz#/perl-HTTP-Daemon-%{version}.tar.gz # Use Makefile.PL without unneeded dependencies Patch0: HTTP-Daemon-6.04-EU-MM-is-not-deprecated.patch +Patch1: CVE-2026-8450.patch BuildArch: noarch BuildRequires: coreutils BuildRequires: make @@ -80,8 +81,7 @@ Tests from %{name}. Execute them with "%{_libexecdir}/%{name}/test". %prep -%setup -q -n HTTP-Daemon-%{version} -%patch 0 -p1 +%autosetup -n HTTP-Daemon-%{version} -p1 %build perl Makefile.PL INSTALLDIRS=vendor NO_PACKLIST=1 NO_PERLLOCAL=1 @@ -116,6 +116,9 @@ make test %{_libexecdir}/%{name} %changelog +* Thu Jul 23 2026 Azure Linux Security Servicing Account - 6.16-2 +- Patch for CVE-2026-8450 + * Wed Mar 27 2024 Sam Meluch - 6.16-1 - Upgrade to version 6.16 for Azure Linux 3.0 - Add tests package