Bug 23799 - u-boot new security issues CVE-2018-18439, CVE-2018-18440
Summary: u-boot new security issues CVE-2018-18439, CVE-2018-18440
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Olivier Blin
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on: 26358
Blocks:
  Show dependency treegraph
 
Reported: 2018-11-02 13:59 CET by David Walser
Modified: 2021-07-01 18:17 CEST (History)
5 users (show)

See Also:
Source RPM: u-boot-20180507-3.mga7.src.rpm
CVE:
Status comment: Fixed upstream in 2019.04


Attachments

Description David Walser 2018-11-02 13:59:14 CET
An advisory has been issued today (November 2):
https://www.openwall.com/lists/oss-security/2018/11/02/2

A fix doesn't appear to be available yet.

Mageia 6 is also affected.
David Walser 2018-11-02 13:59:25 CET

Whiteboard: (none) => MGA6TOO

Comment 1 Marja Van Waes 2018-11-03 08:54:41 CET
Assigning to the registered maintainer.

Assignee: bugsquad => mageia
CC: (none) => marja11

Comment 2 David Walser 2019-02-03 02:44:51 CET
May not be a real issue.

SUSE says:
We don't use fit (or any verified boot) in any of our distros with U-Boot, so I guess this doesn't affect us.

Debian says:
No security impact as supported/packaged in Debian

Status comment: (none) => Not fixed upstream as of end of 2018

David Walser 2019-06-23 19:31:31 CEST

Whiteboard: MGA6TOO => MGA7TOO, MGA6TOO

David Walser 2020-03-18 23:29:21 CET

Depends on: (none) => 26358

Nicolas Lécureuil 2020-05-22 14:08:41 CEST

CC: (none) => mageia
Whiteboard: MGA7TOO, MGA6TOO => MGA7TOO

Comment 3 Aurelien Oudelet 2020-10-06 16:27:49 CEST
U-Boot 2020.10 is released upstream.
Nicolas Lécureuil 2020-12-26 19:57:25 CET

Version: Cauldron => 7
Whiteboard: MGA7TOO => (none)

David Walser 2020-12-26 20:31:39 CET

Whiteboard: (none) => MGA7TOO
Version: 7 => Cauldron

Comment 4 Nicolas Lécureuil 2020-12-27 00:33:11 CET
should this have to be kept open if "not a real issue" for every distro ? :-)
Comment 5 David Walser 2020-12-27 00:39:09 CET
Only for two.  I don't know enough about this software or how we use/package it in Mageia to know if it impacts us or not.  Maybe Pascal, Thierry, or Olivier know?

CC: (none) => pterjan, thierry.vignaud

Comment 6 r howard 2020-12-27 02:43:36 CET
This was fixed in the uboot/master in July 2018 so is included in any official uboot release after that date.
https://lists.denx.de/pipermail/u-boot/2018-July/334277.html

Any how it is my understanding it is irrelevant to Mageia ARM 32 bit builds as FIT (flattened image tree) is not used but FDT (flattened device tree) is.

CC: (none) => rihoward1

Comment 7 David Walser 2020-12-27 03:03:32 CET
Upstream advisory says fixed in 2019.04.  I don't see anything about it being specific to ARM or FIT.

Version: Cauldron => 7
Status comment: Not fixed upstream as of end of 2018 => Fixed upstream in 2019.04
Whiteboard: MGA7TOO => (none)

Comment 8 r howard 2020-12-27 03:14:16 CET
David Walser You have to scroll down in the original openwall link to the over verbose message at openwall and you will see the reference to the original email which refers to FIT.
The actual code for the fix is at https://lists.denx.de/pipermail/u-boot/2018-June/331095.html which was applied in July 2018 to uboot/master.
Mageia only supports uboot on ARM.
Comment 9 David Walser 2020-12-27 03:48:37 CET
That's certainly not clear.  There's no mention of FIT (other than those letters in that order being used in filenames in the PoC) and we have the u-boot packages on Intel, and the package description says that it supports x86.
Comment 10 r howard 2020-12-27 04:19:45 CET
It is clear if you have a knowledge of uboot code and have been using it for over a decade and read much of the source code.
David which Intel boards does Mageia support that uses uboot instead of bios?
Comment 11 David Walser 2020-12-27 04:26:10 CET
I'm just the security guy, I can't be expected to have intimate knowledge of 10,000 packages, but I do my best to learn from those who know.  So I take it that u-boot is used for creating firmwares, from what you're saying.  Is our package hobbled in some way that it doesn't support x86 like upstream does?  Whether you would run Mageia on a system for which you create a firmware is probably irrelevant.
Comment 12 David Walser 2021-07-01 18:17:36 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.