Debian Patches
Status for nagios4/4.4.6-4+deb12u2
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| 103_getcgi-pairlist-truncation.patch | Fix one-element heap overflow when appending the NagFormId cookie. No CVE has been assigned to this as yet. It is a memory-safety bug in the same function as the CVE fixes above, reachable from an unauthenticated request, so it is fixed here too. . getcgivars() allocates pairlist in blocks of 256 entries, then appends the NagFormId cookie under an "if(!(paircount % 256))" guard that also fires when paircount is still zero. For a request with no query parameters and no request body the realloc() therefore *shrinks* the array to a single element, after which the cookie is stored in pairlist[0] and the NULL terminator is written to pairlist[1], one element past the end of the allocation. . Reserve two elements, as upstream does. . Committed upstream 2021-03-13, first released in Nagios Core 4.4.7. Upstream did not treat it as a security fix and issued no disclosure. |
Ariadne Conill <ariadne@dereferenced.org> | no | upstream, https://github.com/NagiosEnterprises/nagioscore/commit/32eaed0f3e99b05f4339ed85fb6a2dea6a53b41e | ||
| 50-log-file-location.patch | Move log files to where Debian has them: /var/log. | Russell Stuart <russell-debian@stuart.id.au> | no | |||
| 55_strip_logarchivepath.patch | stripping the log_archive_path value from cgi.cfg (#578232) | Omni Flux <omniflux@omniflux.com> | no | |||
| 60_debianise_plugins.patch | Debianise the config | Russell Stuart <russell-debian@stuart.id.au> | no | |||
| 70_remove_check-host-alive.patch | Remove check-host-alive as it conflicts with the command of the same name from ping.cfg in monitoring-plugins-basic. |
Russell Stuart <russell-debian@stuart.id.au> | no | |||
| 80_no_phone_home.patch | Remove stuff that pings Nagios or youtube. | Russell Stuart <russell-debian@stuart.id.au> | no | |||
| 90_turn-off-use-authentication.path | Turn off nagios security This is done so a newbie can play with the default install. As a compromise the shipped apache2.conf only allows private ip's access. |
Russell Stuart <russell-debian@stuart.id.au> | no | |||
| 9103-fix-unknown-rpm-arch.patch | Skip the RPM_ARCH check when building for Debian. Fixes #902216 =================================================================== |
Russell Stuart <russell-debian@stuart.id.au> | no | |||
| 95_CSRF-cookie-security-fix.patch | CSRF security fix backported from upstream 4.5.12. . cgi/cmd.c: make the CSRF cookie mandatory (default formid_ok=ERROR, not OK), generate a pseudo-random NagFormId cookie server-side in cmd.cgi's document_header() and emit it via Set-Cookie with SameSite=Strict. Previously the cookie was generated client-side by JavaScript in html/index.php, which is bypassed by attacker pages. html/index.php.in: remove the now-redundant client-side cookie setter. . See upstream's disclosure at https://www.nagios.com/security-disclosures/nagios-core/4-5-12/ . |
Emmett Kapsner <ekapsner@nagios.com> | no | upstream, https://github.com/NagiosEnterprises/nagioscore/commit/e5ed38e53a5d65721520c7c67be0746d63da28cb | ||
| 96_CSRF-cookie-fail-open-option.patch | Add `cgi_cookie_fail_open` config option for the CSRF cookie check. . The security fix in 95_CSRF-cookie-security-fix.patch unconditionally rejects any request to cmd.cgi that arrives without a valid NagFormId cookie. That is the secure default, but it also breaks legitimate third-party integrations (custom dashboards, automation scripts, add-ons like NagiosBP) that POST commands to cmd.cgi without first visiting the web UI in the same browser session. . This patch (upstream PR 1055, merged 2026-04-03, scheduled for the next upstream release after 4.5.12) adds a cgi.cfg option: . cgi_cookie_fail_open=0 (default: secure -- reject without cookie) cgi_cookie_fail_open=1 (insecure: revert to pre-fix behaviour) . Setting it to 1 reopens the CSRF window, but is the only way to keep those third-party integrations working without rewriting them to authenticate via the UI first. . NOTE for Debian: this option is *not* in upstream 4.5.12, only in the unreleased 4.5.13+. It is present in this 4.4.6-4.1+deb12u1 stable security update so that bookworm users can opt back to the old behaviour locally; it will disappear when the package is upgraded to 4.5.12+ds via bookworm -> trixie. |
Emmett Kapsner <ekapsner@nagios.com> | no | upstream, https://github.com/NagiosEnterprises/nagioscore/pull/1055 | ||
| 97_CVE-2026-48549.patch | CVE-2026-48549: CSRF protection bypass in cmd.cgi. cmd.cgi's double-submit cookie check compares the NagFormId cookie against the nagFormId form field. getcgivars() appended the cookie to the same name/value list it built from the query string and the POST body, so a request that carried no Cookie header at all could supply both halves itself and satisfy the comparison, letting an attacker submit Nagios commands as an authenticated user. . Ignore any NagFormId supplied through the query string or request body, so it can only ever come from a real cookie. . Released in Nagios Core 4.5.13. Reported by SeungMyung Lee. See upstream's disclosure at https://www.nagios.com/security-disclosures/nagios- core/4-5-13/ . |
Emmett Kapsner <ekapsner@nagios.com> | no | debian | upstream, https://github.com/NagiosEnterprises/nagioscore/commit/02aba584656eb10c2ff83a696b166f4bc7dd1304 | |
| 98_CVE-2026-48550.patch | CVE-2026-48550: reflected XSS in cmd.cgi via NagFormId. The NagFormId value is echoed back into the generated HTML without being sanitised, so an attacker who can get a victim to load a crafted URL can execute JavaScript in the victim's session. . Strip angle brackets from the cookie value, as is already done for the other CGI inputs. . Released in Nagios Core 4.5.14. Reported by Zach Hanley of Horizon3.ai. See upstream's disclosure at https://www.nagios.com/security-disclosures/nagios- core/4-5-14/ . |
Emmett Kapsner <ekapsner@nagios.com> | no | debian | upstream, https://github.com/NagiosEnterprises/nagioscore/commit/acd2365e816dda4a8dce61709f8d3a3b4ab04a6f | |
| 99_CVE-2026-48551.patch | CVE-2026-48551: CSRF bypass via a self-supplied double-submit cookie. Completes the fix in 97_CVE-2026-48549.patch. Matching "NagFormId=" anywhere in a name/value pair rather than only at its start let the check be evaded, and the CGI input was unescaped only after the pair had been split, so a percent-encoded parameter name could smuggle one past the test. Unescape each pair before inspecting it and anchor the comparison at the start of the name. . Also mark the NagFormId cookie HttpOnly so script running in the page cannot read it. . Released in Nagios Core 4.5.14. Reported by Zach Hanley of Horizon3.ai. See upstream's disclosure at https://www.nagios.com/security-disclosures/nagios- core/4-5-14/ . |
Emmett Kapsner <ekapsner@nagios.com> | no | debian | upstream, https://github.com/NagiosEnterprises/nagioscore/commit/bcd4c2a4b5dfe51bdb2b227af8945ad8751a820d | |
| 100_CVE-2026-48552.patch | CVE-2026-48552: DOM-based XSS in jsonquery.js. The JSON query results page rendered unencoded string values from stored fields straight into the DOM via jQuery's .html(), so values an attacker had previously stored (host names, comments, plugin output) executed as script when a user viewed the page. . Render the response as text inside a <pre> element instead. . Released in Nagios Core 4.5.14. Reported by Zach Hanley of Horizon3.ai. See upstream's disclosure at https://www.nagios.com/security-disclosures/nagios- core/4-5-14/ . |
Emmett Kapsner <ekapsner@nagios.com> | no | debian | upstream, https://github.com/NagiosEnterprises/nagioscore/commit/acd2365e816dda4a8dce61709f8d3a3b4ab04a6f | |
| 101_CVE-2026-48553.patch | CVE-2026-48553: authenticated RCE via custom-variable macro injection. Custom variable macros ($_HOST.../$_SERVICE.../$_CONTACT...) were expanded into command lines without the illegal-character filtering applied to other untrusted macros, so shell metacharacters stored in a custom variable -- reachable through the Nagios Remote Data Processor in a non-default configuration -- ran as the nagios user. . Always set STRIP_ILLEGAL_MACRO_CHARS when expanding a custom macro. . Released in Nagios Core 4.5.13. Reported by Gabriel "Texugo" Rodrigues. See upstream's disclosure at https://www.nagios.com/security-disclosures/nagios- core/4-5-13/ . |
Emmett Kapsner <ekapsner@nagios.com> | no | debian | upstream, https://github.com/NagiosEnterprises/nagioscore/commit/0b68220529d461c9fba198a904049ea332bdb1da | |
| 102_CVE-2026-48554.patch | CVE-2026-48554: authenticated RCE via NOTIFICATION macro substitution. The $NOTIFICATIONAUTHOR$, $NOTIFICATIONAUTHORNAME$, $NOTIFICATIONAUTHORALIAS$ and $NOTIFICATIONCOMMENT$ macros were substituted unfiltered, so an author or comment submitted through cmd.cgi's com_data parameter could inject shell metacharacters into a notification command. . Give them the same STRIP_ILLEGAL_MACRO_CHARS and ESCAPE_MACRO_CHARS treatment as the other operator-supplied macros. . Released in Nagios Core 4.5.14. Reported by Zach Hanley of Horizon3.ai. See upstream's disclosure at https://www.nagios.com/security-disclosures/nagios- core/4-5-14/ . |
Emmett Kapsner <ekapsner@nagios.com> | no | debian | upstream, https://github.com/NagiosEnterprises/nagioscore/commit/1d1f65390dae0bdff05da4ccba4b2db58c0f0d8e |
All known versions for source package 'nagios4'
- 4.5.14+ds-1 (sid)
- 4.4.6-4.1+deb13u1 (trixie-security, trixie)
- 4.4.6-4+deb12u2 (bookworm-security)
- 4.4.6-4+deb12u1 (bookworm)
