From 887ebbaafd861eaecc8d7976b12ec6563bc79feb Mon Sep 17 00:00:00 2001 From: deepin-ci-robot Date: Tue, 14 Apr 2026 10:38:50 +0800 Subject: [PATCH] fix: Fix CVE-2026-35535 - exec_mailer privilege escalation vulnerability - Set group as well as uid when running the mailer - Make setuid(), setgid() or setgroups() failure fatal - Add mailgid field to eventlog_config structure - Update eventlog_set_mailuid() to eventlog_set_mailuser() with gid parameter Upstream: https://www.sudo.ws/security/advisories/CVE-2026-35535/ --- debian/changelog | 7 ++ debian/patches/cve_2026_35535.patch | 141 ++++++++++++++++++++++++++++ debian/patches/series | 1 + 3 files changed, 149 insertions(+) create mode 100644 debian/patches/cve_2026_35535.patch diff --git a/debian/changelog b/debian/changelog index 71a81e0..43c8bc9 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,10 @@ +sudo (1.9.16p2-3deepin2) unstable; urgency=medium + + * Fix CVE-2026-35535: exec_mailer: Set group as well as uid when + running the mailer. + + -- deepin-ci-robot Mon, 13 Apr 2026 21:24:10 +0800 + sudo (1.9.16p2-3deepin1) unstable; urgency=medium [ zhouzilong ] diff --git a/debian/patches/cve_2026_35535.patch b/debian/patches/cve_2026_35535.patch new file mode 100644 index 0000000..565d20b --- /dev/null +++ b/debian/patches/cve_2026_35535.patch @@ -0,0 +1,141 @@ +Description: exec_mailer: Set group as well as uid when running the mailer. + Also make a setuid(), setgid() or setgroups() failure fatal. +Author: Todd C. Miller +Origin: upstream +Bug: https://security-tracker.debian.org/tracker/CVE-2026-35535 +Forwarded: not-needed +Last-Update: 2026-04-13 +--- + include/sudo_eventlog.h | 3 ++- + lib/eventlog/eventlog.c | 21 +++++++++++++++++---- + lib/eventlog/eventlog_conf.c | 4 +++- + plugins/sudoers/logging.c | 2 +- + plugins/sudoers/policy.c | 2 +- + 5 files changed, 24 insertions(+), 8 deletions(-) +Index: github-sudo-CVE-2026-35535/include/sudo_eventlog.h +=================================================================== +--- github-sudo-CVE-2026-35535.orig/include/sudo_eventlog.h ++++ github-sudo-CVE-2026-35535/include/sudo_eventlog.h +@@ -80,6 +80,7 @@ struct eventlog_config { + int syslog_rejectpri; + int syslog_alertpri; + uid_t mailuid; ++ gid_t mailgid; + bool omit_hostname; + const char *logpath; + const char *time_fmt; +@@ -151,7 +152,7 @@ void eventlog_set_syslog_rejectpri(int p + void eventlog_set_syslog_alertpri(int pri); + void eventlog_set_syslog_maxlen(size_t len); + void eventlog_set_file_maxlen(size_t len); +-void eventlog_set_mailuid(uid_t uid); ++void eventlog_set_mailuser(uid_t uid, gid_t gid); + void eventlog_set_omit_hostname(bool omit_hostname); + void eventlog_set_logpath(const char *path); + void eventlog_set_time_fmt(const char *fmt); +Index: github-sudo-CVE-2026-35535/lib/eventlog/eventlog.c +=================================================================== +--- github-sudo-CVE-2026-35535.orig/lib/eventlog/eventlog.c ++++ github-sudo-CVE-2026-35535/lib/eventlog/eventlog.c +@@ -304,15 +304,13 @@ exec_mailer(int pipein) + syslog(LOG_ERR, _("unable to dup stdin: %m")); // -V618 + sudo_debug_printf(SUDO_DEBUG_ERROR, + "unable to dup stdin: %s", strerror(errno)); +- sudo_debug_exit(__func__, __FILE__, __LINE__, sudo_debug_subsys); +- _exit(127); ++ goto bad; + } + + /* Build up an argv based on the mailer path and flags */ + if ((mflags = strdup(evl_conf->mailerflags)) == NULL) { + syslog(LOG_ERR, _("unable to allocate memory")); // -V618 +- sudo_debug_exit(__func__, __FILE__, __LINE__, sudo_debug_subsys); +- _exit(127); ++ goto bad; + } + argv[0] = sudo_basename(mpath); + +@@ -331,11 +329,23 @@ exec_mailer(int pipein) + if (setuid(ROOT_UID) != 0) { + sudo_debug_printf(SUDO_DEBUG_ERROR, "unable to change uid to %u", + ROOT_UID); ++ goto bad; ++ } ++ if (setgid(evl_conf->mailgid) != 0) { ++ sudo_debug_printf(SUDO_DEBUG_ERROR, "unable to change gid to %u", ++ (unsigned int)evl_conf->mailgid); ++ goto bad; ++ } ++ if (setgroups(1, &evl_conf->mailgid) != 0) { ++ sudo_debug_printf(SUDO_DEBUG_ERROR, "unable to set groups to %u", ++ (unsigned int)evl_conf->mailgid); ++ goto bad; + } + if (evl_conf->mailuid != ROOT_UID) { + if (setuid(evl_conf->mailuid) != 0) { + sudo_debug_printf(SUDO_DEBUG_ERROR, "unable to change uid to %u", + (unsigned int)evl_conf->mailuid); ++ goto bad; + } + } + sudo_debug_exit(__func__, __FILE__, __LINE__, sudo_debug_subsys); +@@ -347,6 +357,9 @@ exec_mailer(int pipein) + sudo_debug_printf(SUDO_DEBUG_ERROR, "unable to execute %s: %s", + mpath, strerror(errno)); + _exit(127); ++bad: ++ sudo_debug_exit(__func__, __FILE__, __LINE__, sudo_debug_subsys); ++ _exit(127); + } + + /* Send a message to the mailto user */ +Index: github-sudo-CVE-2026-35535/lib/eventlog/eventlog_conf.c +=================================================================== +--- github-sudo-CVE-2026-35535.orig/lib/eventlog/eventlog_conf.c ++++ github-sudo-CVE-2026-35535/lib/eventlog/eventlog_conf.c +@@ -70,6 +70,7 @@ static struct eventlog_config evl_conf = + MAXSYSLOGLEN, /* syslog_maxlen */ + 0, /* file_maxlen */ + ROOT_UID, /* mailuid */ ++ ROOT_GID, /* mailgid */ + false, /* omit_hostname */ + _PATH_SUDO_LOGFILE, /* logpath */ + "%h %e %T", /* time_fmt */ +@@ -151,9 +152,10 @@ eventlog_set_file_maxlen(size_t len) + } + + void +-eventlog_set_mailuid(uid_t uid) ++eventlog_set_mailuser(uid_t uid, gid_t gid) + { + evl_conf.mailuid = uid; ++ evl_conf.mailgid = gid; + } + + void +Index: github-sudo-CVE-2026-35535/plugins/sudoers/logging.c +=================================================================== +--- github-sudo-CVE-2026-35535.orig/plugins/sudoers/logging.c ++++ github-sudo-CVE-2026-35535/plugins/sudoers/logging.c +@@ -1155,7 +1155,7 @@ init_eventlog_config(void) + eventlog_set_syslog_alertpri(def_syslog_badpri); + eventlog_set_syslog_maxlen(def_syslog_maxlen); + eventlog_set_file_maxlen(def_loglinelen); +- eventlog_set_mailuid(ROOT_UID); ++ eventlog_set_mailuser(ROOT_UID, ROOT_GID); + eventlog_set_omit_hostname(!def_log_host); + eventlog_set_logpath(def_logfile); + eventlog_set_time_fmt(def_log_year ? "%h %e %T %Y" : "%h %e %T"); +Index: github-sudo-CVE-2026-35535/plugins/sudoers/policy.c +=================================================================== +--- github-sudo-CVE-2026-35535.orig/plugins/sudoers/policy.c ++++ github-sudo-CVE-2026-35535/plugins/sudoers/policy.c +@@ -639,7 +639,7 @@ sudoers_policy_deserialize_info(struct s + } + + #ifdef NO_ROOT_MAILER +- eventlog_set_mailuid(ctx->user.uid); ++ eventlog_set_mailuser(ctx->user.uid, ctx->user.gid); + #endif + + /* Dump settings and user info (XXX - plugin args) */ diff --git a/debian/patches/series b/debian/patches/series index 36ad3d9..f9a9455 100644 --- a/debian/patches/series +++ b/debian/patches/series @@ -6,3 +6,4 @@ X11R6.patch 0007-upstream-patch-for-CVE-2025-32463.patch 0008-upstream-patch-for-CVE-2025-32462.patch developer-mode-verify.patch +cve_2026_35535.patch