Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
rsync vulnerabilities
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
Goverp
Advocate
Advocate


Joined: 07 Mar 2007
Posts: 2201

PostPosted: Sat Jan 25, 2025 9:50 am    Post subject: rsync vulnerabilities Reply with quote

There's been a flurry of interest in a batch of vulnerabilities in rsyncd. Release 3.4.0 is supposed to contain the fixes, so after my "emerge --update --..." today I thought I'd check, and found it was still at net-misc/rsync-3.3.0-r2, so I got all worked up. However, a dig on bugs.gentoo.org turns up bug 948106, which shows the fixes are in that "-r2", so all is well.

The bug report is interesting reading. Kudos to the Gentoo devs for taking it carefully, rather than just pumping 3.4.0 out (as at least one other distro has already done).
_________________
Greybeard
Back to top
View user's profile Send private message
bunder
Bodhisattva
Bodhisattva


Joined: 10 Apr 2004
Posts: 5947

PostPosted: Mon Jan 27, 2025 11:26 am    Post subject: Reply with quote

I wish that they would have put out a "news" article on the exploit(s), given that almost every gentoo install needs to sync their trees over rsync (that is unless you switch to git pulls, which I believe is still frowned upon).

Given that it's still in progress after two weeks doesn't instill much confidence either. :roll:
_________________
Neddyseagoon wrote:
The problem with leaving is that you can only do it once and it reduces your influence.

banned from #gentoo since sept 2017
Back to top
View user's profile Send private message
Hu
Administrator
Administrator


Joined: 06 Mar 2007
Posts: 23059

PostPosted: Mon Jan 27, 2025 12:27 pm    Post subject: Reply with quote

It looks like sam_ published a backport of the fixes fairly quickly, and that backport has been keyworded stable in Gentoo for more than a week. Yes, there seem to be reports of ongoing regressions, but given that the reporter of one such was a Debian user, it seems at least plausible that the problem is in the backport patches generally, not with anything Gentoo did specifically. Moreover, I read bug #948106, comment #10 to be that even the v3.4.0 release of rsync is experiencing regressions due to these fixes. As such, I find it quite reasonable that Gentoo is not publishing v3.4.0 yet, since it looks like 3.4.0 has even more regressions than just 3.3.0-r2. It would be nice if upstream could get this fixed more quickly, but if the CVE fixes are effective at their stated purpose, at least users can choose between having an rsync with regressions or an rsync with vulnerabilities.
Back to top
View user's profile Send private message
sam_
Developer
Developer


Joined: 14 Aug 2020
Posts: 2111

PostPosted: Mon Jan 27, 2025 2:26 pm    Post subject: Reply with quote

We already published a GLSA too, so I'm not sure what bunder is requesting.
Back to top
View user's profile Send private message
bunder
Bodhisattva
Bodhisattva


Joined: 10 Apr 2004
Posts: 5947

PostPosted: Mon Jan 27, 2025 9:33 pm    Post subject: Reply with quote

I didn't see the GLSA because I had already known about the issue from online reports outside of gentoo, and had already run package updates... but if I was living under a rock, the only way I would have known it was an issue was if I manually ran glsa-check... I still think something in eselect news would have been nice, since it would have been visible any time I ran emerge.
_________________
Neddyseagoon wrote:
The problem with leaving is that you can only do it once and it reduces your influence.

banned from #gentoo since sept 2017
Back to top
View user's profile Send private message
sam_
Developer
Developer


Joined: 14 Aug 2020
Posts: 2111

PostPosted: Mon Jan 27, 2025 10:11 pm    Post subject: Reply with quote

We publish GLSAs on the website, glsa-check, the mailing list, and others (e.g. LWN) repost security messages from all distros including us. We don't generally do news items for security issues because it's not the right mechanism (and it'd be duplicating it).

I think having some way of making GLSAs more visible would be nice, I'm just not yet sure what that would be.

Sometimes, for such severe vulnerabilities, we p.mask as well, but the regressions here have made that sort of painful to do (which is the same reason the bug is still IN_PROGRESS -- because cleanup remains to be done, and I haven't cleaned up yet for the same reason: in case people need to downgrade if they're affected by the regressions).
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum