Skip to content

pam: validate auth_token_length in extract_authtok_v1() - #9040

Open
alexey-tikhonov wants to merge 1 commit into
SSSD:masterfrom
alexey-tikhonov:bz_2510305
Open

pam: validate auth_token_length in extract_authtok_v1()#9040
alexey-tikhonov wants to merge 1 commit into
SSSD:masterfrom
alexey-tikhonov:bz_2510305

Conversation

@alexey-tikhonov

@alexey-tikhonov alexey-tikhonov commented Aug 4, 2026

Copy link
Copy Markdown
Member

The check mimics one existing in extract_authtok_v2()

:fixes: CVE-2026-68743

Assisted-By: Claude Code (Opus 4.6)

RHBZ: https://bugzilla.redhat.com/show_bug.cgi?id=2510305

@sumit-bose sumit-bose left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi,

thank you for the fix, ACK.

bye,
Sumit

The check mimics one existing in `extract_authtok_v2()`

:fixes: CVE-2026-68743

Assisted-By: Claude Code (Opus 4.6)
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
Reviewed-by: Sumit Bose <sbose@redhat.com>
@sssd-bot

Copy link
Copy Markdown
Contributor

The pull request was accepted by @alexey-tikhonov with the following PR CI status:


🟢 CodeQL (success)
NEUTRAL osh-diff-scan:fedora-rawhide-x86_64:upstream (neutral)
🟢 rpm-build:centos-stream-10-x86_64:upstream (success)
🟢 rpm-build:fedora-43-x86_64:upstream (success)
🟢 rpm-build:fedora-44-x86_64:upstream (success)
🟢 rpm-build:fedora-rawhide-x86_64:upstream (success)
🟢 testing-farm:centos-stream-10-x86_64:upstream (success)
🔴 testing-farm:fedora-43-x86_64:upstream (failure)
🔴 testing-farm:fedora-44-x86_64:upstream (failure)
🔴 testing-farm:fedora-rawhide-x86_64:upstream (failure)
🟢 Build / freebsd (success)
🟢 Build / make-distcheck (success)
🟢 ci / intgcheck (centos-10) (success)
🟢 ci / intgcheck (fedora-43) (success)
🟢 ci / intgcheck (fedora-44) (success)
🟢 ci / intgcheck (fedora-45) (success)
🟢 ci / prepare (success)
🟢 ci / system (centos-10) (success)
🟢 ci / system (fedora-43) (success)
🟢 ci / system (fedora-44) (success)
🔴 ci / system (fedora-45) (failure)
➖ Coverity scan / coverity (skipped)
🟢 Static code analysis / codeql (success)
🟢 Static code analysis / pre-commit (success)
🟢 Static code analysis / python-system-tests (success)


There are unsuccessful or unfinished checks. Make sure that the failures are not related to this pull request before merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants