Skip to content

process: refuse GetMemoryDump of the server's own process and pid 1 - #641

Open
sfc-gh-ikryvanos wants to merge 2 commits into
mainfrom
fix/memorydump-target-guard
Open

process: refuse GetMemoryDump of the server's own process and pid 1#641
sfc-gh-ikryvanos wants to merge 2 commits into
mainfrom
fix/memorydump-target-guard

Conversation

@sfc-gh-ikryvanos

Copy link
Copy Markdown
Collaborator

Producing a memory dump of the sansshell server's own process would expose its in-memory secrets (for example its private TLS key), and pid 1 is never a legitimate dump target. Guard the target pid via an overridable predicate so deployments can enforce a narrower allowlist.

Producing a memory dump of the sansshell server's own process would expose its
in-memory secrets (for example its private TLS key), and pid 1 is never a
legitimate dump target. Guard the target pid via an overridable predicate so
deployments can enforce a narrower allowlist.
Comment on lines +129 to +137
var memoryDumpTargetAllowed = func(pid int) error {
if pid == os.Getpid() {
return status.Error(codes.PermissionDenied, "refusing to dump the sansshell server's own process")
}
if pid == 1 {
return status.Error(codes.PermissionDenied, "refusing to dump pid 1")
}
return nil
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 MEDIUM · GetMemoryDump target guard omits child/related PIDs and defaults to allowing any non-self, non-PID-1 process · CWE-284

Attaching to the sansshell server's own process can expose its in-memory
secrets, and pid 1 is never a legitimate target. These RPCs also briefly stop
the target, so restricting them limits abuse. Guard the target pid via an
overridable predicate so deployments can enforce a narrower allowlist.
Comment on lines +129 to +137
var memoryDumpTargetAllowed = func(pid int) error {
if pid == os.Getpid() {
return status.Error(codes.PermissionDenied, "refusing to dump the sansshell server's own process")
}
if pid == 1 {
return status.Error(codes.PermissionDenied, "refusing to dump pid 1")
}
return nil
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 MEDIUM · GetMemoryDump can dump arbitrary PIDs; guard only excludes self and PID 1 (sensitive-data exposure) · CWE-200

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant