The ncurses terminfo flaw: a setuid program reading a terminal description the user wrote
ncurses looked for terminal definitions in places an unprivileged user can write, even when the program using it was setuid. The library is linked into a great deal of software, which is what makes a small parsing bug worth a page.
A fixed package version is available on 4 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.
What it actually is
When used by a setuid application, ncurses could be steered into loading a terminfo database from a user-controlled location, and mishandled malformed entries once it did. The combination gives a local user influence over memory in a privileged process.
What an attacker gets: Memory corruption inside a setuid process, which is the starting point for privilege escalation rather than the finish.
When it applies to you, and when it does not
An old package version and a real exposure are different things. These are the conditions this one needs.
- It needs a setuid program linked against ncurses. Which of those exist varies by distribution more than most flaws on this site.
- Local only, and it needs the attacker to control the environment of the privileged process being launched.
- The fix makes ncurses ignore the user-controlled search paths when the process is privileged, which is the behaviour that should always have applied.
Check your own server
find /usr/bin /usr/sbin /bin /sbin -perm -4000 -type f -exec sh -c 'ldd "$1" 2>/dev/null | grep -q ncurses && echo "$1"' _ {} \; 2>/dev/nullLists setuid binaries on this machine that link ncurses. An empty list is the common and reassuring answer.
Fixed package version, per distribution
From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.
| Release | Source package | State | Fixed in |
|---|---|---|---|
| Ubuntu 22.04 LTS | ncurses | Fixed | 6.3-2ubuntu0.1 |
| Ubuntu 24.04 LTS | ncurses | No advisory names it | no advisory for this release names it |
| Debian 12 (bookworm) | ncurses | Fixed | 6.4-3 |
| Debian 13 (trixie) | ncurses | Fixed | 6.4-3 |
| Rocky Linux 9 | ncurses | No advisory names it | no advisory for this release names it |
| AlmaLinux 9 | ncurses | Fixed | 6.2-10.20210508.el9 |
Install the fix with apt update && apt install --only-upgrade ncurses-bin on Debian and Ubuntu, or dnf update ncurses on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.
What SecAI has recorded about it
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
Recorded from nvd. Its weakness class is CWE-787, from NVD.
- http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56
- http://www.openwall.com/lists/oss-security/2023/04/19/10
- http://www.openwall.com/lists/oss-security/2023/04/19/11
- https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/
- https://security.netapp.com/advisory/ntap-20230517-0009/
Read next
Check whether this vulnerability affects your Linux server
One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2023-29491 included. It changes nothing.