Debian Patches

Status for nagios4/4.4.6-4+deb12u2

Patch Description Author Forwarded Bugs Origin Last update
103_getcgi-pairlist-truncation.patch Fix one-element heap overflow when appending the NagFormId cookie. No CVE has been assigned to this as yet. It is a memory-safety bug in
the same function as the CVE fixes above, reachable from an
unauthenticated request, so it is fixed here too.
.
getcgivars() allocates pairlist in blocks of 256 entries, then appends
the NagFormId cookie under an "if(!(paircount % 256))" guard that also
fires when paircount is still zero. For a request with no query
parameters and no request body the realloc() therefore *shrinks* the
array to a single element, after which the cookie is stored in
pairlist[0] and the NULL terminator is written to pairlist[1], one
element past the end of the allocation.
.
Reserve two elements, as upstream does.
.
Committed upstream 2021-03-13, first released in Nagios Core 4.4.7.
Upstream did not treat it as a security fix and issued no disclosure.
Ariadne Conill <ariadne@dereferenced.org> no upstream, https://github.com/NagiosEnterprises/nagioscore/commit/32eaed0f3e99b05f4339ed85fb6a2dea6a53b41e
50-log-file-location.patch Move log files to where Debian has them: /var/log. Russell Stuart <russell-debian@stuart.id.au> no
55_strip_logarchivepath.patch stripping the log_archive_path value from cgi.cfg (#578232) Omni Flux <omniflux@omniflux.com> no
60_debianise_plugins.patch Debianise the config Russell Stuart <russell-debian@stuart.id.au> no
70_remove_check-host-alive.patch Remove check-host-alive as it conflicts with the command of the same name
from ping.cfg in monitoring-plugins-basic.
Russell Stuart <russell-debian@stuart.id.au> no
80_no_phone_home.patch Remove stuff that pings Nagios or youtube. Russell Stuart <russell-debian@stuart.id.au> no
90_turn-off-use-authentication.path Turn off nagios security This is done so a newbie can play with the default install.
As a compromise the shipped apache2.conf only allows private ip's access.
Russell Stuart <russell-debian@stuart.id.au> no
9103-fix-unknown-rpm-arch.patch Skip the RPM_ARCH check when building for Debian. Fixes #902216

===================================================================
Russell Stuart <russell-debian@stuart.id.au> no
95_CSRF-cookie-security-fix.patch CSRF security fix backported from upstream 4.5.12. .
cgi/cmd.c: make the CSRF cookie mandatory (default formid_ok=ERROR,
not OK), generate a pseudo-random NagFormId cookie server-side in
cmd.cgi's document_header() and emit it via Set-Cookie with
SameSite=Strict. Previously the cookie was generated client-side
by JavaScript in html/index.php, which is bypassed by attacker pages.
html/index.php.in: remove the now-redundant client-side cookie setter.
.
See upstream's disclosure at
https://www.nagios.com/security-disclosures/nagios-core/4-5-12/ .
Emmett Kapsner <ekapsner@nagios.com> no upstream, https://github.com/NagiosEnterprises/nagioscore/commit/e5ed38e53a5d65721520c7c67be0746d63da28cb
96_CSRF-cookie-fail-open-option.patch Add `cgi_cookie_fail_open` config option for the CSRF cookie check. .
The security fix in 95_CSRF-cookie-security-fix.patch unconditionally
rejects any request to cmd.cgi that arrives without a valid NagFormId
cookie. That is the secure default, but it also breaks legitimate
third-party integrations (custom dashboards, automation scripts,
add-ons like NagiosBP) that POST commands to cmd.cgi without first
visiting the web UI in the same browser session.
.
This patch (upstream PR 1055, merged 2026-04-03, scheduled for the
next upstream release after 4.5.12) adds a cgi.cfg option:
.
cgi_cookie_fail_open=0 (default: secure -- reject without cookie)
cgi_cookie_fail_open=1 (insecure: revert to pre-fix behaviour)
.
Setting it to 1 reopens the CSRF window, but is the only way to keep
those third-party integrations working without rewriting them to
authenticate via the UI first.
.
NOTE for Debian: this option is *not* in upstream 4.5.12, only in
the unreleased 4.5.13+. It is present in this 4.4.6-4.1+deb12u1
stable security update so that bookworm users can opt back to the
old behaviour locally; it will disappear when the package is
upgraded to 4.5.12+ds via bookworm -> trixie.
Emmett Kapsner <ekapsner@nagios.com> no upstream, https://github.com/NagiosEnterprises/nagioscore/pull/1055
97_CVE-2026-48549.patch CVE-2026-48549: CSRF protection bypass in cmd.cgi. cmd.cgi's double-submit cookie check compares the NagFormId cookie
against the nagFormId form field. getcgivars() appended the cookie to
the same name/value list it built from the query string and the POST
body, so a request that carried no Cookie header at all could supply
both halves itself and satisfy the comparison, letting an attacker
submit Nagios commands as an authenticated user.
.
Ignore any NagFormId supplied through the query string or request body,
so it can only ever come from a real cookie.
.
Released in Nagios Core 4.5.13. Reported by SeungMyung Lee. See
upstream's
disclosure at https://www.nagios.com/security-disclosures/nagios-
core/4-5-13/ .
Emmett Kapsner <ekapsner@nagios.com> no debian upstream, https://github.com/NagiosEnterprises/nagioscore/commit/02aba584656eb10c2ff83a696b166f4bc7dd1304
98_CVE-2026-48550.patch CVE-2026-48550: reflected XSS in cmd.cgi via NagFormId. The NagFormId value is echoed back into the generated HTML without
being sanitised, so an attacker who can get a victim to load a crafted
URL can execute JavaScript in the victim's session.
.
Strip angle brackets from the cookie value, as is already done for the
other CGI inputs.
.
Released in Nagios Core 4.5.14. Reported by Zach Hanley of Horizon3.ai.
See upstream's
disclosure at https://www.nagios.com/security-disclosures/nagios-
core/4-5-14/ .
Emmett Kapsner <ekapsner@nagios.com> no debian upstream, https://github.com/NagiosEnterprises/nagioscore/commit/acd2365e816dda4a8dce61709f8d3a3b4ab04a6f
99_CVE-2026-48551.patch CVE-2026-48551: CSRF bypass via a self-supplied double-submit cookie. Completes the fix in 97_CVE-2026-48549.patch. Matching "NagFormId="
anywhere in a name/value pair rather than only at its start let the
check be evaded, and the CGI input was unescaped only after the pair had
been split, so a percent-encoded parameter name could smuggle one past
the test. Unescape each pair before inspecting it and anchor the
comparison at the start of the name.
.
Also mark the NagFormId cookie HttpOnly so script running in the page
cannot read it.
.
Released in Nagios Core 4.5.14. Reported by Zach Hanley of Horizon3.ai.
See upstream's
disclosure at https://www.nagios.com/security-disclosures/nagios-
core/4-5-14/ .
Emmett Kapsner <ekapsner@nagios.com> no debian upstream, https://github.com/NagiosEnterprises/nagioscore/commit/bcd4c2a4b5dfe51bdb2b227af8945ad8751a820d
100_CVE-2026-48552.patch CVE-2026-48552: DOM-based XSS in jsonquery.js. The JSON query results page rendered unencoded string values from
stored fields straight into the DOM via jQuery's .html(), so values
an attacker had previously stored (host names, comments, plugin
output) executed as script when a user viewed the page.
.
Render the response as text inside a <pre> element instead.
.
Released in Nagios Core 4.5.14. Reported by Zach Hanley of Horizon3.ai.
See upstream's
disclosure at https://www.nagios.com/security-disclosures/nagios-
core/4-5-14/ .
Emmett Kapsner <ekapsner@nagios.com> no debian upstream, https://github.com/NagiosEnterprises/nagioscore/commit/acd2365e816dda4a8dce61709f8d3a3b4ab04a6f
101_CVE-2026-48553.patch CVE-2026-48553: authenticated RCE via custom-variable macro injection. Custom variable macros ($_HOST.../$_SERVICE.../$_CONTACT...) were
expanded into command lines without the illegal-character filtering
applied to other untrusted macros, so shell metacharacters stored in a
custom variable -- reachable through the Nagios Remote Data Processor
in a non-default configuration -- ran as the nagios user.
.
Always set STRIP_ILLEGAL_MACRO_CHARS when expanding a custom macro.
.
Released in Nagios Core 4.5.13. Reported by Gabriel "Texugo" Rodrigues.
See upstream's
disclosure at https://www.nagios.com/security-disclosures/nagios-
core/4-5-13/ .
Emmett Kapsner <ekapsner@nagios.com> no debian upstream, https://github.com/NagiosEnterprises/nagioscore/commit/0b68220529d461c9fba198a904049ea332bdb1da
102_CVE-2026-48554.patch CVE-2026-48554: authenticated RCE via NOTIFICATION macro substitution. The $NOTIFICATIONAUTHOR$, $NOTIFICATIONAUTHORNAME$,
$NOTIFICATIONAUTHORALIAS$ and $NOTIFICATIONCOMMENT$ macros were
substituted unfiltered, so an author or comment submitted through
cmd.cgi's com_data parameter could inject shell metacharacters into a
notification command.
.
Give them the same STRIP_ILLEGAL_MACRO_CHARS and ESCAPE_MACRO_CHARS
treatment as the other operator-supplied macros.
.
Released in Nagios Core 4.5.14. Reported by Zach Hanley of Horizon3.ai.
See upstream's
disclosure at https://www.nagios.com/security-disclosures/nagios-
core/4-5-14/ .
Emmett Kapsner <ekapsner@nagios.com> no debian upstream, https://github.com/NagiosEnterprises/nagioscore/commit/1d1f65390dae0bdff05da4ccba4b2db58c0f0d8e

All known versions for source package 'nagios4'

Links