{"id":103807,"date":"2022-04-17T21:36:41","date_gmt":"2022-04-17T19:36:41","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-swhkd-menedzhere-goryachih-klavish-dlya-wayland"},"modified":"2022-04-17T21:36:41","modified_gmt":"2022-04-17T19:36:41","slug":"uyazvimosti-v-swhkd-menedzhere-goryachih-klavish-dlya-wayland","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-swhkd-menedzhere-goryachih-klavish-dlya-wayland","title":{"rendered":"Vulnerabilit\u00e0 in swhkd, gestore delle scorciatoie per Wayland","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In swhkd (Simple Wayland HotKey Daemon) a series of vulnerabilities have been identified, caused by improper handling of temporary files, command-line parameters, and Unix sockets. The program is written in Rust and processes hotkey presses in environments based on the Wayland protocol (functionally compatible with the configuration file process analogous to sxhkd, used in X11 environments).     <\/p>\n<p>The package includes an unprivileged process swhks that executes actions for hotkeys, and a background process swhkd that runs with root privileges and interacts with input devices at the uinput API level. A Unix socket is used to facilitate interaction between swhks and swhkd. With Polkit rules, any local user is granted the ability to launch the process \/usr\/bin\/swhkd with root privileges and pass arbitrary parameters to it.    <\/p>\n<p>Vulnerabilit\u00e0 identificate:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2022-27815 \u2014 salvataggio del PID del processo in un file con un nome prevedibile e in una directory scrivibile da altri utenti (\/tmp\/swhkd.pid). Qualsiasi utente pu\u00f2 creare il file \/tmp\/swhkd.pid e inserirvi il PID di un processo esistente, impedendo il lancio di swhkd. In assenza di protezione contro la creazione di collegamenti simbolici in \/tmp, la vulnerabilit\u00e0 pu\u00f2 essere sfruttata per creare o sovrascrivere file in qualsiasi directory del sistema (il PID viene scritto nel file) o per visualizzare il contenuto di qualsiasi file nel sistema (swhkd stampa su stdout tutto il contenuto del file PID). \u00c8 interessante notare che nella patch rilasciata, il file PID \u00e8 stato spostato non nella directory \/run, ma in \/etc (\/etc\/swhkd\/runtime\/swhkd_{uid}.pid), dove anch'esso non dovrebbe trovarsi.\n<li class=\"l\"> CVE-2022-27814 \u2014 manipolando il parametro della riga di comando \u2018-c\u2019, utilizzato per specificare il file di configurazione, \u00e8 possibile determinare l'esistenza di qualsiasi file nel sistema. Ad esempio, per controllare \/root\/.somefile si pu\u00f2 eseguire \u2018pkexec \/usr\/bin\/swhkd -d -c \/root\/.somefile\u2019 e se il file \u00e8 assente verr\u00e0 emesso un errore \u2018\/root\/.somefile doesn\u2019t exist\u2019. Come per la prima vulnerabilit\u00e0, la correzione del problema \u00e8 sconcertante \u2014 la risoluzione della questione consiste nel fatto che ora per leggere il file di configurazione viene avviata un'utility esterna \u2018cat\u2019 (\u2018Command::new(\u2018\/bin\/cat\u2019).arg(path).output()\u2019).\n<li class=\"l\"> CVE-2022-27819 \u2014 il problema \u00e8 anche collegato all'uso dell'opzione \u2018-c\u2019, tramite la quale il file di configurazione viene completamente caricato e analizzato senza verificare la dimensione e il tipo del file. Ad esempio, per provocare un denial of service esaurendo la memoria disponibile e creando input\/output parassitari, si pu\u00f2 specificare durante l'avvio un dispositivo a blocchi (\u2018pkexec \/usr\/bin\/swhkd -d -c \/dev\/sda\u2019) o un dispositivo a caratteri che emette un flusso continuo di dati. Il problema \u00e8 stato risolto azzerando i privilegi prima di aprire il file, ma la correzione non \u00e8 stata completa, poich\u00e9 viene azzerato solo l'identificatore utente (UID), mentre l'identificatore di gruppo (GID) rimane lo stesso.\n<li class=\"l\"> CVE-2022-27818 \u2014 per creare un socket Unix viene utilizzato il file \/tmp\/swhkd.sock, creato in una directory pubblica scrivibile, il che porta a problemi simili alla prima vulnerabilit\u00e0 (qualunque utente pu\u00f2 creare \/tmp\/swhkd.sock e generare o intercettare eventi di pressione dei tasti).\n<li class=\"l\"> CVE-2022-27817 \u2014 gli eventi di input vengono ricevuti da tutti i dispositivi e in tutte le sessioni, cio\u00e8 un utente da un'altra sessione Wayland o dalla console pu\u00f2 intercettare gli eventi quando altri utenti premono tasti di scelta rapida.\n<li class=\"l\"> CVE-2022-27816 \u2014 il processo swhks, come swhkd, utilizza il file PID \/tmp\/swhks.pid in una directory pubblica scrivibile (\/tmp). Il problema \u00e8 simile alla prima vulnerabilit\u00e0, ma meno grave, poich\u00e9 swhks viene eseguito sotto un utente non privilegiato.      <\/ul>\n<p>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=57032\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 swhkd (Simple Wayland HotKey Daemon) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0441\u0435\u0440\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0432\u044b\u0437\u0432\u0430\u043d\u043d\u044b\u0445 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u043e\u0439 \u0441 \u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 \u0444\u0430\u0439\u043b\u0430\u043c\u0438, \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430\u043c\u0438 \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438 \u0438 unix-\u0441\u043e\u043a\u0435\u0442\u0430\u043c\u0438. \u041f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0430 \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Rust \u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0443 \u043d\u0430\u0436\u0430\u0442\u0438\u044f \u0433\u043e\u0440\u044f\u0447\u0438\u0445 \u043a\u043b\u0430\u0432\u0438\u0448 \u0432 \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f\u0445 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 Wayland (\u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u044b\u0439 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u0444\u0430\u0439\u043b\u043e\u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u0430\u043d\u0430\u043b\u043e\u0433 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 sxhkd, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u0433\u043e \u0432 \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f\u0445 \u043d\u0430 \u0431\u0430\u0437\u0435 X11). \u0412 \u0441\u043e\u0441\u0442\u0430\u0432 \u043f\u0430\u043a\u0435\u0442\u0430 \u0432\u0445\u043e\u0434\u0438\u0442 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-103807","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 swhkd (Simple Wayland HotKey Daemon) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0441\u0435\u0440\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0432\u044b\u0437\u0432\u0430\u043d\u043d\u044b\u0445 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u043e\u0439 \u0441 \u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 \u0444\u0430\u0439\u043b\u0430\u043c\u0438, \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430\u043c\u0438 \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438 \u0438 unix-\u0441\u043e\u043a\u0435\u0442\u0430\u043c\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-swhkd-menedzhere-goryachih-klavish-dlya-wayland\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 swhkd, \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440\u0435 \u0433\u043e\u0440\u044f\u0447\u0438\u0445 \u043a\u043b\u0430\u0432\u0438\u0448 \u0434\u043b\u044f Wayland | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 swhkd (Simple Wayland HotKey Daemon) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0441\u0435\u0440\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0432\u044b\u0437\u0432\u0430\u043d\u043d\u044b\u0445 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u043e\u0439 \u0441 \u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 \u0444\u0430\u0439\u043b\u0430\u043c\u0438, \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430\u043c\u0438 \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438 \u0438 unix-\u0441\u043e\u043a\u0435\u0442\u0430\u043c\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-swhkd-menedzhere-goryachih-klavish-dlya-wayland\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-04-17T19:36:41+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-04-17T19:36:41+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vulnerabilit\u00e0 in swhkd, gestore delle scorciatoie da tastiera per Wayland | ProHoster","description":"Nel swhkd (Simple Wayland HotKey Daemon) \u00e8 stata scoperta una serie di vulnerabilit\u00e0 causate da un'errata gestione dei file temporanei, dei parametri della riga di comando e dei socket unix.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-swhkd-menedzhere-goryachih-klavish-dlya-wayland","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 swhkd, \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440\u0435 \u0433\u043e\u0440\u044f\u0447\u0438\u0445 \u043a\u043b\u0430\u0432\u0438\u0448 \u0434\u043b\u044f Wayland | ProHoster","og:description":"\u0412 swhkd (Simple Wayland HotKey Daemon) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0441\u0435\u0440\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0432\u044b\u0437\u0432\u0430\u043d\u043d\u044b\u0445 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u043e\u0439 \u0441 \u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 \u0444\u0430\u0439\u043b\u0430\u043c\u0438, \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430\u043c\u0438 \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438 \u0438 unix-\u0441\u043e\u043a\u0435\u0442\u0430\u043c\u0438.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-swhkd-menedzhere-goryachih-klavish-dlya-wayland","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-04-17T19:36:41+00:00","article:modified_time":"2022-04-17T19:36:41+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"103807","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-25 10:28:44","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-04-17 19:37:39","updated":"2026-01-25 10:28:44","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/103807","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=103807"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/103807\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=103807"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=103807"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=103807"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}