From 6c2e1d761be58fb707fcf2960452ba467a6ebc4c Mon Sep 17 00:00:00 2001 From: Azure Linux Security Servicing Account Date: Thu, 23 Jul 2026 18:32:25 +0000 Subject: [PATCH 1/2] Patch perl-HTTP-Daemon for CVE-2026-8450 --- SPECS/perl-HTTP-Daemon/CVE-2026-8450.patch | 113 +++++++++++++++++++ SPECS/perl-HTTP-Daemon/perl-HTTP-Daemon.spec | 7 +- 2 files changed, 119 insertions(+), 1 deletion(-) create mode 100644 SPECS/perl-HTTP-Daemon/CVE-2026-8450.patch diff --git a/SPECS/perl-HTTP-Daemon/CVE-2026-8450.patch b/SPECS/perl-HTTP-Daemon/CVE-2026-8450.patch new file mode 100644 index 00000000000..433d0b3bfef --- /dev/null +++ b/SPECS/perl-HTTP-Daemon/CVE-2026-8450.patch @@ -0,0 +1,113 @@ +From 69a56a5ddec54d2b78e3653b8809af84da94eb3a Mon Sep 17 00:00:00 2001 +From: Olaf Alders +Date: Thu, 14 May 2026 00:09:58 +0000 +Subject: [PATCH] Fix CVE-2026-8450: send_file() honoured 2-arg open() + shell-magic + +HTTP::Daemon::ClientConn::send_file() used the 2-arg form +open(FILE, $file), which interprets shell-magic prefixes in the +path argument: '| cmd' (write pipe -- RCE), 'cmd |' (read pipe -- +RCE plus response-body exfiltration via the sysread / print loop +below), '> path' (write-truncate -- arbitrary file write), and +'>> path', '+< path', '<&fd', and leading-whitespace variants of +the above. + +Any HTTP::Daemon-based application that passed attacker-influenced +bytes to send_file($string) -- for example, a download endpoint +that derived the filename from a query parameter -- granted command +execution and/or arbitrary file write at the daemon's UID. + +Switch to 3-arg open(my $fh, '<', $file): the explicit '<' mode +makes the path argument a literal filename, so every magic shape +above is opened (and fails, returning undef) as an ordinary file by +that exact name. The localized typeglob is no longer needed and is +replaced with a lexical filehandle. + +Two collateral hardening changes ride along: + + - binmode() failure now closes the handle and returns undef, + rather than streaming the file with a wrong PerlIO layer. + + - send_file() returns '0E0' (true zero) on a successful zero-byte + transfer so callers using "send_file or die" can distinguish + open failure (undef) from an empty-but-successful copy. + +The POD now documents the new return-value contract and spells +out that the fix only neutralises 2-arg open() shell-magic; +callers remain responsible for validating attacker-influenced +paths against symlinks, character/block devices (e.g. /dev/zero), +named pipes, and document-root escapes. + +Reported and patched by Stig Palmquist (stigtsp). + +Co-Authored-By: Claude Opus 4.7 +Signed-off-by: Azure Linux Security Servicing Account +Upstream-reference: https://github.com/libwww-perl/HTTP-Daemon/commit/945d35141d94490f749640bd4390acd6a2193995.patch +--- + lib/HTTP/Daemon.pm | 35 ++++++++++++++++++++++++++++++----- + 1 file changed, 30 insertions(+), 5 deletions(-) + +diff --git a/lib/HTTP/Daemon.pm b/lib/HTTP/Daemon.pm +index f9b3216..0707b9b 100644 +--- a/lib/HTTP/Daemon.pm ++++ b/lib/HTTP/Daemon.pm +@@ -592,11 +592,10 @@ sub send_dir { + sub send_file { + my ($self, $file) = @_; + my $opened = 0; +- local (*FILE); + if (!ref($file)) { +- open(FILE, $file) || return undef; +- binmode(FILE); +- $file = \*FILE; ++ open(my $fh, '<', $file) || return undef; ++ binmode($fh) || do { close($fh); return undef }; ++ $file = $fh; + $opened++; + } + my $cnt = 0; +@@ -608,7 +607,11 @@ sub send_file { + print $self $buf; + } + close($file) if $opened; +- $cnt; ++ ++ # Return a "true zero" for empty-but-successful copies so callers ++ # using `send_file or die` can distinguish open failure (undef) ++ # from a successful zero-byte transfer. ++ $cnt || '0E0'; + } + + sub daemon { +@@ -902,6 +905,28 @@ Copy the file to the client. The file can be a string (which + will be interpreted as a filename) or a reference to an C + or glob. + ++Returns the number of bytes copied on success, or C if the ++filename form failed to open. An empty file returns the string ++C<'0E0'> (zero numerically, true in boolean context) so that callers ++using C<< send_file or die >> can distinguish open failure from a ++successful zero-byte transfer. ++ ++The filename form uses Perl's 3-argument C with an explicit C<< ++< >> mode, so the path is no longer interpreted as a 2-argument ++C shell-magic shape such as C<< | cmd >>, C<< cmd | >>, or ++C<< > path >>. See ++L for ++the prior 2-argument C behaviour this replaces. ++ ++Note that this fix only neutralises 2-argument C shell-magic. ++Callers remain responsible for validating attacker-influenced paths: ++C will still happily open symlinks, character/block devices ++(e.g. C, C), named pipes (which may block the ++worker), and files outside an intended document root. If C<$filename> ++can be derived from request input, validate it (canonicalise, reject ++C<..> segments, require C<-f _> and a vetted prefix) before passing it ++in. ++ + =item $c->daemon + + Return a reference to the corresponding C object. +-- +2.45.4 + diff --git a/SPECS/perl-HTTP-Daemon/perl-HTTP-Daemon.spec b/SPECS/perl-HTTP-Daemon/perl-HTTP-Daemon.spec index 2edbd81c0e6..373d9a3309f 100644 --- a/SPECS/perl-HTTP-Daemon/perl-HTTP-Daemon.spec +++ b/SPECS/perl-HTTP-Daemon/perl-HTTP-Daemon.spec @@ -1,6 +1,6 @@ Name: perl-HTTP-Daemon Version: 6.16 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Simple HTTP server class License: GPL+ or Artistic Vendor: Microsoft Corporation @@ -9,6 +9,7 @@ URL: https://metacpan.org/release/HTTP-Daemon Source0: https://cpan.metacpan.org/authors/id/O/OA/OALDERS/HTTP-Daemon-%{version}.tar.gz#/perl-HTTP-Daemon-%{version}.tar.gz # Use Makefile.PL without unneeded dependencies Patch0: HTTP-Daemon-6.04-EU-MM-is-not-deprecated.patch +Patch1: CVE-2026-8450.patch BuildArch: noarch BuildRequires: coreutils BuildRequires: make @@ -81,6 +82,7 @@ with "%{_libexecdir}/%{name}/test". %prep %setup -q -n HTTP-Daemon-%{version} +%patch 1 -p1 %patch 0 -p1 %build @@ -116,6 +118,9 @@ make test %{_libexecdir}/%{name} %changelog +* Thu Jul 23 2026 Azure Linux Security Servicing Account - 6.16-2 +- Patch for CVE-2026-8450 + * Wed Mar 27 2024 Sam Meluch - 6.16-1 - Upgrade to version 6.16 for Azure Linux 3.0 - Add tests package From 6e1994026cdd670a3530e13b41573be4ddf07615 Mon Sep 17 00:00:00 2001 From: Kanishk Bansal <103916909+Kanishk-Bansal@users.noreply.github.com> Date: Fri, 24 Jul 2026 00:03:53 +0530 Subject: [PATCH 2/2] Simplify setup process using %autosetup Replaced manual setup and patch commands with autosetup. --- SPECS/perl-HTTP-Daemon/perl-HTTP-Daemon.spec | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/SPECS/perl-HTTP-Daemon/perl-HTTP-Daemon.spec b/SPECS/perl-HTTP-Daemon/perl-HTTP-Daemon.spec index 373d9a3309f..51f6f7007f4 100644 --- a/SPECS/perl-HTTP-Daemon/perl-HTTP-Daemon.spec +++ b/SPECS/perl-HTTP-Daemon/perl-HTTP-Daemon.spec @@ -81,9 +81,7 @@ Tests from %{name}. Execute them with "%{_libexecdir}/%{name}/test". %prep -%setup -q -n HTTP-Daemon-%{version} -%patch 1 -p1 -%patch 0 -p1 +%autosetup -n HTTP-Daemon-%{version} -p1 %build perl Makefile.PL INSTALLDIRS=vendor NO_PACKLIST=1 NO_PERLLOCAL=1