Conversation
The MITRE ATT&CK and D3FEND loaders cached their downloaded data through diskcache.Cache, which pickles values by default. Anything able to write into the cache directory could then execute code the next time a rule referenced the data, via CVE-2025-69872 (GHSA-w8v5-vhqr-4h9v). diskcache 5.6.3 is unmaintained and no patched release exists. Add sigma.data.cache.JsonFileCache, a small key-value store that keeps one JSON document per key, and use it in both loaders. Values are deserialized with json only, so a tampered entry can at worst yield inert data or a parse failure, which is treated as a miss. Entries are keyed by a SHA-256 digest so any key stays inside the cache directory, and each write goes through a temporary file and os.replace so a reader never observes a partial document. clear() also removes the files of the former store so an upgrade does not strand a stale database. This drops diskcache and diskcache-stubs.
expanduser() consults HOME on POSIX but USERPROFILE on Windows, so the test failed on the Windows leg of the CI matrix.
Member
|
I don't see the criticality of the issue here that justifies a full implementation of a custom caching implementation. The cache is located in safe temporary locations and the exploitation implies that an attacker has write access to the libraries execution environment, which likely implies also code execution capabilities. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
sigma.data.mitre_attackandsigma.data.mitre_d3fendcached their downloaded data throughdiskcache.Cache, which pickles values by default. Anyone able to write into the cache directory could therefore execute code the next time a rule referenced the data:The default cache directory is
~/.cache/pysigma/, created with mode0o755, so it is not a hardened location either.Change
Adds
sigma.data.cache.JsonFileCache, a small key-value store holding one JSON document per key, and uses it in both loaders. It has no dependency outside the standard library.json.dumps/json.load, so a tampered entry can at worst produce inert data or a parse failure, which is treated as a miss. No deserialization of attacker-chosen types.set()writes to a temporary file in the cache directory thenos.replace()s it into place, so a concurrent reader never observes a partial document and an interrupted write leaves no usable garbage.sha256(key)[:32] + ".json", so any key stays inside the cache directory.0o700(re-chmoded even when it already exists, sincemkdir(exist_ok=True)leaves the mode alone), entries0o600.clear()also removes the former store'scache.db,cache.db-wal,cache.db-shmandcache.db-journal, so an upgrade does not strand a stale database nobody will ever open again.diskcacheanddiskcache-stubsare dropped frompyproject.tomlandpoetry.lock.API
get,set,discard,clearandclosemirror the small part of thediskcache.Cachesurface the loaders actually used, so the loaders' behaviour is unchanged.close()is a no-op, kept for compatibility. A leading~is expanded.Tests
tests/test_data_cache.py— round-trip, key containment and collision resistance, atomic write and cleanup on failure, corruption handling, permissions, cross-process reuse, concurrent writers, and a guard that the module andpyproject.tomlno longer mentiondiskcache.tests/test_mitre_data_loading.py— exercises both loaders against local fixture files: parsing, cache write, serving from disk with the source deleted and the network forbidden,clear_cache()/set_url()/set_cache_dir()behaviour, and recovery from a tampered entry.The permission tests are skipped on Windows, where POSIX modes are not meaningful; the CI matrix also covers macOS.
Full suite:
1707 passed, 1 skipped.mypy(strict) reports the same 3 pre-existingunused-ignoreerrors and no new ones.