Re: HEADS UP: Re: FreeBSD Security Advisory FreeBSD-SA-07:01.jail



Hi Colin,

On Thu, Jan 11, 2007 at 04:51:02PM -0800, Colin Percival wrote:
Hello Everyone,

I usually let security advisories speak for themselves, but I want to call
special attention to this one: If you use jails, READ THE ADVISORY, in
particular the "NOTE WELL" part below; and if you have problems after applying
the security patch, LET US KNOW -- we do everything we can to make sure
that security updates will never cause problems, but in this case we could
not fix the all of the security issues without either making assumptions
about how systems are configured or reducing functionality.

In the end we opted to reduce functionality (the jail startup process is
no longer logged to /var/log/console.log inside the jail), make an assumption
about how systems are configured (filesystems which are mounted via per-jail
fstab files should not be mounted on symlinks -- if you do this, adjust your
fstab files to give the real, non-symlinked, path to the mount point), and
leave a potential security problem unfixed (if you mount any filesystems via
per-jail fstab files on mount points which are visible within multiple jails,
there are problems -- don't do this).

While this is not ideal, this security issue was extraordinarily messy due to
the power and flexibility of the jails and the jail rc.d script. I can't
recall any other time when the security team has spent this long trying to
find a working patch for a security issue. I'd like to publicly thank Simon
Nielsen for the many many hours he spent working on this issue, as well as
the release engineering team for being very patient with us and delaying the
upcoming release to give us time to fix this.

Thank you very much to Simon Nielsen for the work being accomplished.
According to the patch itself, it is clear he should have spent much
time to resolve this issue.

However both Pawel and Dirk seem to have proposed less limitating
solutions. I understand we are talking about security and we may not
have much time experimenting every solutions on RELENG_6. Nonetheless
CURRENT the one place to experiment such solutions with a larger
audience and I would be very pleased to see a less restrictive
workaround for this problem. Indeed I'm using the same setup as Pawel
(/jail -> /usr/jail).

Thank you for your work as a security officer.
Best regards,
--
Jeremie Le Hen
< jeremie at le-hen dot org >< ttz at chchile dot org >
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: [Full-disclosure] Possible security issue with FreeBSD 5.4 jailing and BPF
    ... you should use devfs rulesets if you are using jails as a ... >>is a bad idea security wise, not just with regards to BPF. ... > BPF code in the kernel source tree. ... one of the appropriate FreeBSD mailing lists. ...
    (Full-Disclosure)
  • Re: HEADS UP: Re: FreeBSD Security Advisory FreeBSD-SA-07:01.jail
    ... I usually let security advisories speak for themselves, ... per-jail fstab files on mount points which are visible within multiple jails, ... Nielsen for the many many hours he spent working on this issue, ...
    (freebsd-stable)
  • Re: OT: SHUT DOWN BOTH BORDERS!!
    ... Right, and you want to spend lots and lots of money on security, ... Juan the gardner raped your wife, and then took off to mexico, when you ... our jails are illegal aliens, it costs us $56k per year to keep each one ... So sorry about your wife but one less illegal in our jails is a good ...
    (alt.sports.football.pro.ne-patriots)
  • Re: jails, cron and sendmail
    ... I wasn't aware of that strange behavior of jails. ... Because of the security aspect it's a good ... through packet filter and port forwarding anyway. ... localhost IP address to the outside world. ...
    (freebsd-hackers)
  • Re: Warning - Bullguard causes problems!
    ... any other computer supplier that bundles Bullguard Security). ... I spent quite a bit of time on the phone to her ISP, ... The problem wasn't the security package the problem was that you didn't ... manual would have helped but they seldom come with manuals nowadays ...
    (uk.telecom.broadband)