<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>14125</bug_id>
          
          <creation_ts>2020-11-12 15:45:28 +0000</creation_ts>
          <short_desc>busybox wget ssl is exposed to MitM attack due to CVE-2018-1000500</short_desc>
          <delta_ts>2024-07-18 17:26:17 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>11</classification_id>
          <classification>Runtime</classification>
          <product>Security</product>
          <component>security</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium+</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>5.1 M2</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Shachar Menashe">shachar</reporter>
          <assigned_to name="Randy MacLeod">randy.macleod</assigned_to>
          <cc>akuster808</cc>
    
    <cc>randy.macleod</cc>
    
    <cc>richard.purdie</cc>
    
    <cc>ross.burton</cc>
    
    <cc>shachar</cc>
    
    <cc>tgamblin</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>88599</commentid>
    <comment_count>0</comment_count>
    <who name="Shachar Menashe">shachar</who>
    <bug_when>2020-11-12 15:45:28 +0000</bug_when>
    <thetext>The version of busybox shipped with Yocto builds (which is 1.31.1) is exposed to a severe CVE which easily allows for SSL MitM attacks (when using busybox wget)

To remediate, the following steps need to be done:
1. Update busybox to version 1.32.0

2. Change busybox build configuration (ex. https://git.yoctoproject.org/cgit/cgit.cgi/poky/tree/meta-poky/recipes-core/busybox/busybox/poky-tiny/defconfig?h=dunfell) to:

CONFIG_FEATURE_WGET_OPENSSL=y
# CONFIG_FEATURE_WGET_HTTPS is not set</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88709</commentid>
    <comment_count>1</comment_count>
    <who name="akuster">akuster808</who>
    <bug_when>2020-12-03 15:26:18 +0000</bug_when>
    <thetext>Master and gatesgarth are both at 1.32.0.

1) action to send config change

Dunfell is at 1.31.1 an may or may not be able to be updated. 

It will need #1 and a source change patch or otherwise.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88749</commentid>
    <comment_count>2</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2020-12-10 15:54:40 +0000</bug_when>
    <thetext>Either way we might want to apply this patch from Alpine which prints a big warning when using the insecure codepaths:

https://github.com/alpinelinux/aports/commit/a93da0e814c542ff3a76cba0b557ee51c8124d1e

I&apos;d say that telling the user that their connection isn&apos;t being verified is enough to mitigate the CVE, as the issue is that MitM can happen without your knowledge.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88768</commentid>
    <comment_count>3</comment_count>
    <who name="akuster">akuster808</who>
    <bug_when>2020-12-11 23:43:31 +0000</bug_when>
    <thetext>As this is a team effort, i will take the next step and send a patch to move us to the next step of resolving this issue.

I have a few options to select from.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88769</commentid>
    <comment_count>4</comment_count>
    <who name="Shachar Menashe">shachar</who>
    <bug_when>2020-12-12 14:37:10 +0000</bug_when>
    <thetext>I sent the patch a few weeks ago, but got pushback because it required building the &quot;openssl&quot; binary and not just the library (that&apos;s just how the busybox team chose to use openssl unfortunately... not through the library but by calling the binary)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88937</commentid>
    <comment_count>5</comment_count>
    <who name="akuster">akuster808</who>
    <bug_when>2021-01-14 16:17:21 +0000</bug_when>
    <thetext>This is the patch.

https://lists.yoctoproject.org/g/yocto-security/message/229

sent to the security-list.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88939</commentid>
    <comment_count>6</comment_count>
    <who name="akuster">akuster808</who>
    <bug_when>2021-01-14 16:22:57 +0000</bug_when>
    <thetext>In master.

https://git.openembedded.org/openembedded-core/commit/meta/recipes-connectivity/openssl?id=304417a97db89d9ea4a41aa7c92b5a052896d63b</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88941</commentid>
    <comment_count>7</comment_count>
    <who name="akuster">akuster808</who>
    <bug_when>2021-01-14 16:33:26 +0000</bug_when>
    <thetext>I think this can be marked as fixed.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88943</commentid>
    <comment_count>8</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2021-01-14 17:05:41 +0000</bug_when>
    <thetext>Are the backports done or going to happen?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88975</commentid>
    <comment_count>9</comment_count>
    <who name="akuster">akuster808</who>
    <bug_when>2021-01-21 15:32:39 +0000</bug_when>
    <thetext>(In reply to comment #8)
&gt; Are the backports done or going to happen?

Its not obvious in the commit that its addressing a CVE so a backport request needs to be sent to the list.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>89006</commentid>
    <comment_count>10</comment_count>
    <who name="Shachar Menashe">shachar</who>
    <bug_when>2021-01-23 20:55:30 +0000</bug_when>
    <thetext>I think there&apos;s been a bit of a mixup
The patch referenced in this thread before (this one - https://lists.yoctoproject.org/g/yocto-security/message/229) DOESN&apos;T resolve the CVE. It&apos;s related to a different issue.

Resolving the CVE requires:
1. Changing the busybox config to use OpenSSL by enabling CONFIG_FEATURE_WGET_OPENSSL

2. Building the openssl executable (today it&apos;s being built as a library only, but busybox uses openssl as an executable when CONFIG_FEATURE_WGET_OPENSSL is enabled)

So I wrote the patch for #1 a while back, but then got pushback regarding point #2, and didn&apos;t submit it, since I thought we&apos;re going with Ross&apos; suggestion of just including a warning, the alpine patch - https://github.com/alpinelinux/aports/commit/a93da0e814c542ff3a76cba0b557ee51c8124d1e</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>89642</commentid>
    <comment_count>11</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2021-03-18 14:37:53 +0000</bug_when>
    <thetext>Shakar, Can you send a patch to at least issue a warning?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>89963</commentid>
    <comment_count>12</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2021-04-15 18:28:01 +0000</bug_when>
    <thetext>The discussion  on the email list wasn&apos;t conclusive. Do you want to drop the issue or add a PACKAGECONFIG to make busybox wget secure using openssl. I suspect that making it secure by default will not be viable due to pulling in some of openssl but that&apos;s just my opinion.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>89964</commentid>
    <comment_count>13</comment_count>
    <who name="akuster">akuster808</who>
    <bug_when>2021-04-15 21:24:42 +0000</bug_when>
    <thetext>(In reply to comment #12)
&gt; The discussion  on the email list wasn&apos;t conclusive. Do you want to drop the
&gt; issue or add a PACKAGECONFIG to make busybox wget secure using openssl. I
&gt; suspect that making it secure by default will not be viable due to pulling
&gt; in some of openssl but that&apos;s just my opinion.

I have been wondering if something like defining something at the DISTRO level to enable mitigation of this CVE so folks can OPT in knowing the affects of doing so then we could have Busybox and openssl do the appropriate things based on that OPT in directive?

I know the kernel has done this from time to time. The early Meltdown &amp; Sepectra come to mind.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>89979</commentid>
    <comment_count>14</comment_count>
    <who name="Shachar Menashe">shachar</who>
    <bug_when>2021-04-17 11:26:10 +0000</bug_when>
    <thetext>Hey guys, I looked into it further and it seems the &quot;issue&quot; with openssl and the yocto build is not that it&apos;s compiled without the binary part, but rather that in &quot;core-image-base&quot; and &quot;core-image-minimal&quot; openssl is not getting compiled at all, and thus busybox wget will not be able to rely on it

I think that adding openssl to minimal builds will cause a lot of friction in the community, so I&apos;d rather not go that path

I suggest that to cause the least amount of friction, I will submit a patch that enables busybox&apos;s CONFIG_FEATURE_WGET_OPENSSL for all builds

This means that in builds WITH openssl (ex. sato) the issue will be completely fixed, and in builds WITHOUT openssl, busybox will fallback to using the internal (insecure) client which will print out a message &quot;note: TLS certificate validation not implemented&quot;

Also note that busybox does not rely in any way on the OpenSSL library (it just executes the standalone binary, if it is found) so we shouldn&apos;t have linkage issues is CONFIG_FEATURE_WGET_OPENSSL is enabled but OpenSSL is not getting built

WDYT? Makes sense?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>89980</commentid>
    <comment_count>15</comment_count>
    <who name="Shachar Menashe">shachar</who>
    <bug_when>2021-04-17 14:41:29 +0000</bug_when>
    <thetext>Sent to yocto-security

https://lists.yoctoproject.org/g/yocto-security/topic/patch_busybox_use_openssl/82166345?p=,,,20,0,0,0::recentpostdate%2Fsticky,,,20,2,0,82166345</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>90015</commentid>
    <comment_count>16</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2021-04-20 01:27:42 +0000</bug_when>
    <thetext>Makes sense to me. Thanks Shachar.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>90016</commentid>
    <comment_count>17</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2021-04-20 01:29:50 +0000</bug_when>
    <thetext>I don&apos;t see the patch yet (21:30 ET). Maybe it&apos;s in the mail! ;-)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>90018</commentid>
    <comment_count>18</comment_count>
    <who name="Shachar Menashe">shachar</who>
    <bug_when>2021-04-20 06:03:55 +0000</bug_when>
    <thetext>Oh, just look at the link I sent -
https://lists.yoctoproject.org/g/yocto-security/topic/patch_busybox_use_openssl/82166345?p=,,,20,0,0,0::recentpostdate%2Fsticky,,,20,2,0,82166345

Again, in this case the patch really comes out as minimal (just enabling CONFIG_FEATURE_WGET_OPENSSL for all builds)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>90030</commentid>
    <comment_count>19</comment_count>
    <who name="Shachar Menashe">shachar</who>
    <bug_when>2021-04-20 18:49:44 +0000</bug_when>
    <thetext>Some extra information about the patch I submitted - 

By enabling the busybox feature CONFIG_FEATURE_WGET_OPENSSL, in builds WITH openssl (ex. &quot;sato&quot; build) 
the issue will be completely fixed, and in builds WITHOUT openssl, busybox will fallback 
to using the internal (insecure) client which will print out a message 
&quot;note: TLS certificate validation not implemented&quot; 

Note that busybox does not rely in any way on the OpenSSL library 
(it just executes the standalone binary, if it is found) so 
we shouldn&apos;t have linkage issues if CONFIG_FEATURE_WGET_OPENSSL is enabled but OpenSSL is not getting built in this particular build (ex. &quot;minimal&quot; build)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>90153</commentid>
    <comment_count>20</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2021-04-29 14:37:26 +0000</bug_when>
    <thetext>Shachar, it seems like you have agreement with Andre so I&apos;m moving this to 3.4-M1.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91179</commentid>
    <comment_count>21</comment_count>
    <who name="akuster">akuster808</who>
    <bug_when>2021-08-12 22:19:15 +0000</bug_when>
    <thetext>the busybox fix to address this is:
https://git.busybox.net/busybox/commit/?id=45fa3f18adf57ef9d743038743d9c90573aeeb91</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91180</commentid>
    <comment_count>22</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2021-08-12 23:29:45 +0000</bug_when>
    <thetext>Thanks Armin.

$ cd .../busybox.git &amp;&amp; git pull
$ git branch -a --contains 45fa3f18adf57ef9d743038743d9c90573aeeb91
* 1_33_stable
  master
  remotes/origin/1_32_stable
  remotes/origin/1_33_stable
  remotes/origin/HEAD -&gt; origin/master
  remotes/origin/master
$ git tag --contains 45fa3f18adf57ef9d743038743d9c90573aeeb91
1_32_0
1_32_1
1_33_0
1_33_1

and we have 1.33.1:
http://cgit.openembedded.org/openembedded-core/commit/meta/recipes-core/busybox/busybox_1.33.1.bb?id=544236b12a72ee5be5ef0147249ead112082b871

so the questions I have are:
1. is the code is enabled for YP by default and
2. do we want to backport the fix to previous releases?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91276</commentid>
    <comment_count>23</comment_count>
    <who name="akuster">akuster808</who>
    <bug_when>2021-08-26 14:31:46 +0000</bug_when>
    <thetext>(In reply to comment #22)
&gt; Thanks Armin.
&gt; 
&gt; $ cd .../busybox.git &amp;&amp; git pull
&gt; $ git branch -a --contains 45fa3f18adf57ef9d743038743d9c90573aeeb91
&gt; * 1_33_stable
&gt;   master
&gt;   remotes/origin/1_32_stable
&gt;   remotes/origin/1_33_stable
&gt;   remotes/origin/HEAD -&gt; origin/master
&gt;   remotes/origin/master
&gt; $ git tag --contains 45fa3f18adf57ef9d743038743d9c90573aeeb91
&gt; 1_32_0
&gt; 1_32_1
&gt; 1_33_0
&gt; 1_33_1
&gt; 
&gt; and we have 1.33.1:
&gt; http://cgit.openembedded.org/openembedded-core/commit/meta/recipes-core/
&gt; busybox/busybox_1.33.1.bb?id=544236b12a72ee5be5ef0147249ead112082b871
&gt; 
&gt; so the questions I have are:
&gt; 1. is the code is enabled for YP by default and
&gt; 2. do we want to backport the fix to previous releases?
Hardknott 1.32.0
Dunfell 1.31.1 so dunfell needs this. I can send a patch for dunfell</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91800</commentid>
    <comment_count>24</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2021-10-21 14:35:39 +0000</bug_when>
    <thetext>Shakjar, Armin,

Do we have consensus about how to handle this bug?
I&apos;m reluctant to keep moving the bug to newer releases...</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91819</commentid>
    <comment_count>25</comment_count>
    <who name="Shachar Menashe">shachar</who>
    <bug_when>2021-10-21 21:42:23 +0000</bug_when>
    <thetext>Armin, do you think it makes sense to replace BusyBox&apos;s wget with GNU wget? (I see there&apos;s already a recipe for that)
This should solve the issue and retain compatibility</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>93369</commentid>
    <comment_count>26</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2022-06-02 14:34:42 +0000</bug_when>
    <thetext>We think this is fixed in newer busybox releases. Armin to look into it.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>94210</commentid>
    <comment_count>27</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2022-10-20 14:33:46 +0000</bug_when>
    <thetext>This may have been fixed. I just have to find the time to confirm.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>95350</commentid>
    <comment_count>28</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2023-04-13 14:27:11 +0000</bug_when>
    <thetext>From a recent poky build:
$ grep WGET_OPENSSL tmp/work/core2-64-poky-linux/busybox/1.36.0-r0/busybox-1.36.0/.config
# CONFIG_FEATURE_WGET_OPENSSL is not set

I&apos;ll enable it and send a patch.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99380</commentid>
    <comment_count>29</comment_count>
    <who name="Richard Purdie">richard.purdie</who>
    <bug_when>2024-07-12 13:52:15 +0000</bug_when>
    <thetext>Patch sent for master to switch to the openssl option.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99416</commentid>
    <comment_count>30</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2024-07-18 17:26:17 +0000</bug_when>
    <thetext>Fixed by Richard - Thanks!!!

https://git.openembedded.org/openembedded-core/commit/?id=5d4ad13462f12355ff0f2bc1773ab4b1814b165a</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>