From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from simark.ca by simark.ca with LMTP id IO5nG7POE2Y09ScAWB0awg (envelope-from ) for ; Mon, 08 Apr 2024 07:02:11 -0400 Authentication-Results: simark.ca; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=HYLT0XAo; dkim-atps=neutral Received: by simark.ca (Postfix, from userid 112) id 66DA41E0C0; Mon, 8 Apr 2024 07:02:11 -0400 (EDT) Received: from server2.sourceware.org (server2.sourceware.org [8.43.85.97]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by simark.ca (Postfix) with ESMTPS id 344CB1E092 for ; Mon, 8 Apr 2024 07:02:09 -0400 (EDT) Received: from server2.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 8DE263858C39 for ; Mon, 8 Apr 2024 11:02:08 +0000 (GMT) Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by sourceware.org (Postfix) with ESMTPS id 1EB393858D32 for ; Mon, 8 Apr 2024 11:01:44 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 1EB393858D32 Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=redhat.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=redhat.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 1EB393858D32 Authentication-Results: server2.sourceware.org; arc=none smtp.remote-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1712574106; cv=none; b=igINEqx7FrCKUN1acb0RJUkdIdjORyfsqGvT8/LSHriI8FW9cSVFW3gGlMwHhtzw5mcNNF9gxeilyvDaTrSGaUhjIkfFCz2vh1bgNNWIeoRdnr34/6anJWnKu7DgNmO2m+8WQPAGXPrD4KwIY6KutzvVPev9s4A++EEDXYPvlOI= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1712574106; c=relaxed/simple; bh=6k/s3eOaKtDqkSOXfVPjWfRaZTs7yM2RNLCIBxFncKU=; h=DKIM-Signature:From:To:Subject:Date:Message-ID:MIME-Version; b=fYXT7zuqwPHr+MUyKVdJsRXGaJ3CTazMBt7YmMX33QPamdjlQTXco2RTQHP8U3GVRlRY0Ip2PZi5KK0g3gSpt87AE+71TWqV/EjLBNTz/s5pVMoWjYYeemCwAhIP8WDLf3iysDkcmjshp69w9CLo6bxc+wGtRjDNEYBR0yf8b90= ARC-Authentication-Results: i=1; server2.sourceware.org DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1712574103; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=T1zAScoUy3ugXZGg7T/PI9jFofv1TgwGPvM7yWqXrkQ=; b=HYLT0XAonUd0TSuITCCr6DFIGFSZ2dJyO7T+UpWwvI610oV85+5PQlrUqWTwC8Rg3X9cwe wjd232fGpLtlRnd5CwZxTECKwtqu+d5OqukLD7Hi875j4XGynPXxJx2RKsZp3cuAU/gasN F2gAcuIV5H/zQ3mi+Nhd5//doJxLePc= Received: from mail-ej1-f72.google.com (mail-ej1-f72.google.com [209.85.218.72]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-323-TQWdBzd7MVOtXmw3Ue5CrQ-1; Mon, 08 Apr 2024 07:01:42 -0400 X-MC-Unique: TQWdBzd7MVOtXmw3Ue5CrQ-1 Received: by mail-ej1-f72.google.com with SMTP id a640c23a62f3a-a51a1c8d979so23248666b.2 for ; Mon, 08 Apr 2024 04:01:42 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1712574101; x=1713178901; h=mime-version:message-id:date:references:in-reply-to:subject:cc:to :from:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=T1zAScoUy3ugXZGg7T/PI9jFofv1TgwGPvM7yWqXrkQ=; b=kyoc/pfcvFM5iU1vFC4VKBXJe2XdJcmvJ9alHHS8L/+5lNZCyAnv0IZs0t4iD1ymj9 o6gkyPQjQdcr6uWg0WiwuhLfmYS0dtqgS8Xay/D0amozhLDKyDTYvcWGXnzi9XzyZuCH fMlo2APh7GZCc1yMZM7smbnxwsDxionuhaxLd6CsN4PQVS086d6K80RfnrSaNo7WvZMN PNi3V/+Zk/uYOu/JHzaQaRdgkjxxqTXpJJVp+wKiduOrgfMn6YGjNBh0SPs8lCN3ktbo T5aAewwtwyrSjf5uuH8lxrUSe2cLWX5+rXtA45b8K97BL+R8kATf12xIo/INGFJdTbjc n+vA== X-Gm-Message-State: AOJu0Yy0eGAOMQxcXon5QSdFKxcFHU3RpKMDrUi1sTy/5GM3t1L8I/XM N2kPtcuhVQVxdNSZu+BpZ8EBDYnmsGxmgDU1t8p5Uncg/rLIbeAMpR4ZucqN5sUBm9qe8L3JziW Yy+FFSEqFabyaBKzuShBylz9HgXg/yAVU6mP0WkAomEfO1UK/aw1EWSEmSFmUIrFRImbxfdt0Cs AV4skDLhLttyEcep0P9jt+O+nixcGQ8CZkNz9JK2hOGvU= X-Received: by 2002:a50:bb05:0:b0:56d:f3f3:f61f with SMTP id y5-20020a50bb05000000b0056df3f3f61fmr6777057ede.9.1712574100505; Mon, 08 Apr 2024 04:01:40 -0700 (PDT) X-Google-Smtp-Source: AGHT+IHKHi3uouFKUlFin5kNzJkU3OOiR1epx8V07KxCo+la4DQRKvS3Q1FGBPumw7FZAXvX2hfXkQ== X-Received: by 2002:a50:bb05:0:b0:56d:f3f3:f61f with SMTP id y5-20020a50bb05000000b0056df3f3f61fmr6777015ede.9.1712574099927; Mon, 08 Apr 2024 04:01:39 -0700 (PDT) Received: from localhost (185.223.159.143.dyn.plus.net. [143.159.223.185]) by smtp.gmail.com with ESMTPSA id gx12-20020a1709068a4c00b00a4e03c28fd5sm4319691ejc.43.2024.04.08.04.01.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 08 Apr 2024 04:01:39 -0700 (PDT) From: Andrew Burgess To: gdb-patches@sourceware.org Cc: Siddhesh Poyarekar , Kevin Buettner , Simon Marchi , felix.willgerodt@intel.com, Paul Koning Subject: [V5] [RFC] Adding a SECURITY policy for GDB In-Reply-To: <87msqk3pnt.fsf@redhat.com> References: <877cmvui64.fsf@redhat.com> <87wmtog2f4.fsf@redhat.com> <874jeo5jip.fsf@redhat.com> <87o7cd6fmk.fsf@redhat.com> <87msqk3pnt.fsf@redhat.com> Date: Mon, 08 Apr 2024 12:01:38 +0100 Message-ID: <87r0fg15kd.fsf@redhat.com> MIME-Version: 1.0 X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Type: text/plain X-Spam-Status: No, score=-6.2 required=5.0 tests=BAYES_00, DKIMWL_WL_HIGH, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, KAM_ASCII_DIVIDERS, RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H4, RCVD_IN_MSPIKE_WL, SPF_HELO_NONE, SPF_NONE, TXREP autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org X-BeenThere: gdb-patches@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Gdb-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: gdb-patches-bounces+public-inbox=simark.ca@sourceware.org In V5: - Fixed a couple of minor typos that were pointed out by someone off-list. Any additional feedback would be great. If there's no feedback, how would people feel about me merging this? So long as the content is not objectionable then minor corrections or additions can be made via the normal patch process in the future. I know I mentioned adding this text to the GDB manual previously, but I recall someone objected to that at the time. Right now I'm thinking to add this as a standalone document, and possibly merge it into the manual later in the year. Thoughts? Thanks, Andrew --- GNU Debugger Security Policy ============================ Introduction ------------ The GNU Debugger (GDB) is a tool for diagnosing issues "inside" another program. This can be done by controlling the execution of the program being debugged and allowing the user to inspect and modify the state of the running program. Or GDB can be used to analyse the program or a core file generated from the program without needing to execute the program. The program being debugged may be local i.e. on the system on which GDB runs or remote, on a different system. Policy Objectives ----------------- The objective of this policy is define what the GDB project considers a security bug and what is a non-security bug, and how bugs can be reported. Additionally this policy discusses areas of GDB in which there are known bugs, how these might lead to security issues, and how this risk can be mitigated. Scope Of This Policy -------------------- This policy covers all currently supported versions of GDB as released from the official GDB website and covers gdb, gdbserver, as well as gcore and gdb-add-index, which are packaged with each GDB release. The official GDB website can be found here: https://sourceware.org/gdb/ Remote debugging uses GDB to connect to a remote target. GDB sends commands to the remote target which then controls the process being debugged. The GDB project provides one remote target, gdbserver, which is included with official GDB releases. Bugs within gdbserver are in scope for this policy. Other projects also implement remote targets to which GDB can connect. Any bugs in these remote targets are out of scope for this policy and should be reported to the relevant project. However, any bugs in GDB caused by a misbehaving remote target, even when that target is not gdbserver, are in scope for this policy. What Is A Security Bug? ----------------------- Any bugs in GDB or gdbserver that result in an unexpected crossing of a privilege boundary are considered security bugs. Some examples of crossing a privilege boundary include: being able to execute code as an arbitrarily different user, or accessing resources (e.g. files, sockets, etc) for which the original user would not normally have access. Any bugs in GDB that result in execution of the program being debugged without the user issuing a GDB command triggering execution (either from the GDB command line, a GDB configuration file, or from the GDB prompt) are considered security bugs. GDB will check for and load multiple configuration files. When initially started GDB can load user- and system-specific configuration files, this is done unconditionally as it is assumed these files are under control of the user and are always safe to load. GDB can also load per-project and per-program configuration files, this is done when a program to debug is loaded into GDB. These configuration files will only be loaded if the user has given GDB permission to load these files. Any bug in GDB which allows per-project or per-program configuration files to be loaded without permission having been granted by the user is considered a security bug. When gdbserver is started, if it is passed a program on its command line then that program will be started, but paused before executing its first instruction. Any bug in gdbserver which results in further execution of the program being debugged without GDB first connecting to the target and sending a command that is intended to trigger execution is a security bug in gdbserver. Any bug in GDB or gdbserver that can trigger arbitrary code execution without the program being debugged having been executed by a user command, is considered a security bug, e.g. if loading a program into GDB could trigger arbitrary code execution, then this is a security issue. The additional tools gcore and gdb-add-index are scripts that wrap around GDB. Any issue in these tools that meet the above definitions of a security bug, are considered a security bug. What Is Not A Security Bug -------------------------- In the context of local debugging, when GDB is used to execute a program, the program runs with the same privileges as GDB itself. Any issues that arise from running an untrusted program outside of a secure environment are not security bugs in GDB. Any issues that arise from running an untrusted program through GDB inside a secure environment are only security bugs if GDB is required in order to trigger the issue. It is possible for a program to detect when it is run under GDB and to change its behavior so that unwanted behavior may only appear when a program is run under GDB. Any issues that arise due to an untrusted program detecting GDB and changing its behaviour are not security issues in GDB unless the issue also meet some other definition of a security bug. In the context of remote debugging, the program being debugged is run with the same privileges as gdbserver. As with GDB in the local debugging case, any issues that arise from running an untrusted program outside of a secure environment are not security bugs in gdbserver. The connection between GDB and a remote target is not protected by either authentication or encryption. Connecting to a remote target allows for arbitrary code execution on the remote system with the same privileges as the remote user, and any resource that the remote user can access can be read by GDB, and downloaded to the local machine on which GDB is running. As such, users need to take independent measures to secure the connection between GDB and the remote target. Any issues that arise due to a failure to protect the connection between GDB and a remote target are not security bugs in either GDB or gdbserver. Security Realities Of The GDB Project ------------------------------------- Within this section, references to GDB should be read as meaning GDB, gdbserver, gcore, or gdb-add-index, unless specifically stated otherwise. The most common use case for GDB is a developer trying to resolve issues within a program that they have either written themselves, or within a program that they trust not to be malicious. In this situation we would say GDB is being used to debug trusted code. There is no greater security risk from running the program to debug through GDB than there is running the program directly. Additional process isolation for the GDB process is only needed if additional isolation would have been applied anyway when running the program to debug. In some cases a developer may be given a program from an untrusted source and be asked to debug an issue. In this situation we would say GDB is being used to debug untrusted code. In this case the user should take all the precautions when running GDB that they would normally take when running an untrusted program outside of GDB, e.g. running within a secure, sandboxed environment. When using GDB to examine, but not execute, an untrusted program (with gdbserver, the program will be started, but paused at the first instruction and not run further), there should be no security risks, however the GDB maintainers don't currently believe that GDB or gdbserver is reliable enough to ensure that there are no security risks. There are known bugs in GDB related to loading malformed executables and parsing the debug information, a consequence of these bugs is that a malicious program could trigger undefined behaviour in GDB, which could be used to trigger arbitrary code execution. Given these risks, the advice of the GDB project is that, when using GDB with an untrusted binary, always do so in a secure, sandboxed environment. As there are already known bugs in GDB relating to undefined behaviour triggered from malformed programs, further bugs in this area should still be reported, but are unlikely to be given high priority. Bugs in GDB that are triggered by well-formed programs should also be reported, and are likely to be treated as higher priority as these are more likely to impact normal use of GDB. When using GDB and gdbserver to perform remote debug, the connection between the two components is by design insecure. It is up to the user to protect this connection, for example, by only starting gdbserver within a secure network. Reporting Non-Security Bugs --------------------------- NOTE: All bugs reported in the GDB Bugzilla are public. Non-security bugs, as well as any security bugs that pose limited risk to users should be reported in GDB's bugzilla system. Bugs reported in this way will be public. The bugzilla system can be found here: https://sourceware.org/bugzilla/ Reporting Security Bugs ----------------------- In order to report a private security bug that is not immediately made public, please contact one of the downstream distributions with security teams. The following teams have volunteered to handle such bugs: Red Hat: secalert@redhat.com SUSE: security@suse.de Please report the bug to just one of these teams. It will be shared with other teams as necessary. The team contacted will take care of details such as vulnerability rating and CVE assignment (http://cve.mitre.org/about/). It is likely that the team will ask to file a public bug because the issue is sufficiently minor and does not warrant keeping details of the bug private.