]> git.ipfire.org Git - thirdparty/libvirt.git/commitdiff
storage: create images with a private umask during qemu-img create/convert master v12.6.0-rc2
authorHE WEI(ギカク) <skyexpoc@gmail.com>
Tue, 28 Jul 2026 16:30:57 +0000 (17:30 +0100)
committerDaniel P. Berrangé <berrange@redhat.com>
Thu, 30 Jul 2026 10:21:28 +0000 (11:21 +0100)
On the local (non-NETFS) path virStorageBackendCreateExecCommand() ran
qemu-img with umask 0, so the destination image was created
world-readable (0644) and the full source disk was written into it
before libvirt tightened the mode with a later chmod(). This is the same
class as CVE-2025-13193; apply the same fix by setting a 0077 umask so
qemu-img creates the file private from the start.

Fixes: CVE-2026-63623
Reported-by: HE WEI(ギカク) <skyexpoc@gmail.com>
Signed-off-by: HE WEI(ギカク) <skyexpoc@gmail.com>
[DB: merged the two virCommandSetUmask to one]
Reviewed-by: Ján Tomko <jtomko@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
src/storage/storage_util.c

index 78dc9f9f1cce41ca97efacca736b51bf5a4597e7..9e6b266842ede79fce1abc5695a00e95dcdc489b 100644 (file)
@@ -464,6 +464,7 @@ virStorageBackendCreateExecCommand(virStoragePoolObj *pool,
     bool filecreated = false;
     int ret = -1;
 
+    virCommandSetUmask(cmd, S_IRWXUGO ^ mode);
     if ((def->type == VIR_STORAGE_POOL_NETFS)
         && (((geteuid() == 0)
              && (vol->target.perms->uid != (uid_t)-1)
@@ -473,7 +474,6 @@ virStorageBackendCreateExecCommand(virStoragePoolObj *pool,
 
         virCommandSetUID(cmd, vol->target.perms->uid);
         virCommandSetGID(cmd, vol->target.perms->gid);
-        virCommandSetUmask(cmd, S_IRWXUGO ^ mode);
 
         if (virCommandRun(cmd, NULL) == 0) {
             /* command was successfully run, check if the file was created */
@@ -505,7 +505,6 @@ virStorageBackendCreateExecCommand(virStoragePoolObj *pool,
         /* don't change uid/gid/mode if we retry */
         virCommandSetUID(cmd, -1);
         virCommandSetGID(cmd, -1);
-        virCommandSetUmask(cmd, 0);
 
         if (virCommandRun(cmd, NULL) < 0)
             goto cleanup;