CVE-2026-91142: Cockpit: integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ilp32 builds

Published May 18, 2026
·
Updated

A flaw was found in Cockpit. An integer overflow vulnerability in the dolastlog() function, specifically in the offset calculation for lastlog entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileged authenticated user with a specially provisioned large User ID (UID) can cause the computed offset to wrap around. This allows the user to perform unauthorized reads and writes to other users' lastlog records, potentially disclosing or altering sensitive login accounting information.

Other sources

AIONLYREPORT package: cockpit-356-1.el10 ------ Summary: Integer overflow in dolastlog() offset calculation can misaddress lastlog entries on ILP32 builds: a specially provisioned authenticated user can wrap the computed offset and cause cross-user reads and writes in legacy lastlog records during login accounting. Requirements to exploit: An authenticated account that can log in through Cockpit, a sufficiently large assigned UID to overflow uid sizeof(struct lastlog) on an ILP32 build, and a deployment where the cockpit-session path updates legacy /var/log/lastlog. Component affected: cockpit-356-1.el10, src/session/session-utils.c, dolastlog() in the cockpit-session login-accounting path Version affected: cockpit-356-1.el10; reachability is limited to ILP32 deployments where cockpit-session updates legacy /var/log/lastlog entries Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N - 3.6 (LOW) AV:L - Exploitation requires control of a locally provisioned account on the target system that is permitted to authenticate through Cockpit. AC:H - Exploitation additionally depends on uncommon but valid preconditions: an ILP32 build, legacy /var/log/lastlog handling being active, and a sufficiently large UID that causes wraparound. PR:L - The attacker needs a valid low-privilege account. UI:N - No separate victim interaction is required after the attacker authenticates. S:U - The impact remains within the same system scope that performs login accounting. C:L - A wrapped read can disclose another account's lastlog entry. I:L - A wrapped write can alter another account's lastlog entry, including the demonstrated UID 0 slot. A:N - The available evidence shows misaddressed login-accounting data, not direct service disruption. Impact: Low. Based on Red Hat severity guidance, this issue fits Low impact because exploitation depends on unlikely but technically valid circumstances and the demonstrated consequences are limited to confidentiality and integrity of legacy lastlog metadata. The available evidence does not show code execution, privilege escalation, or broader system compromise. Embargo: no Reason: The supported impact is low and configuration-dependent, and the issue is limited to lastlog record disclosure and tampering rather than system compromise. Acknowledgement: Aisle Research Vulnerability Details: In dolastlog(), the file offset used for both pread() and pwrite() is computed as uid sizeof entry without an overflow check or a guaranteed widened intermediate type. On ILP32 builds, that multiplication can wrap before being passed as an offt, redirecting access to a different user's slot in /var/log/lastlog. c r = pread (fd, &entry, sizeof entry, uid sizeof entry); ... r = pwrite (fd, &entry, sizeof entry, uid sizeof entry); For example, when sizeof(struct lastlog) = 292, uid = 1073741824 wraps the product to 0, which targets UID 0's record. The available evidence indicates this path is reached from utmplog() during authenticated cockpit-session login handling, so a successful login by a specially provisioned high-UID account can cause cross-user lastlog reads and writes in privileged session-accounting code. Steps to reproduce: 1. Use an ILP32 environment, such as a 32-bit userspace/build, where the uid sizeof entry multiplication is evaluated in 32-bit width. 2. Ensure Cockpit uses the cockpit-session login path and that /var/log/lastlog exists. 3. Create or identify an account with a UID that causes wraparound, such as 1073741824 when sizeof(struct lastlog) = 292. 4. Record the current UID 0 entry with lastlog -u 0. 5. Log in through Cockpit as the high-UID account. 6. Re-run lastlog -u 0 and observe that the UID 0 entry changed. 7. Optionally trace pread() and pwrite() in dolastlog() and confirm the wrapped offset, 0 in this example. Mitigation: If cockpit-356-1.el10 is deployed in an affected ILP32 configuration, avoid assigning unusually large UIDs to accounts that can authenticate through Cockpit, and restrict such accounts from the cockpit-session login path until a fix is available. Proposed Fix: Compute the lastlog offset once in checked offt space, reject overflow before I/O, and use the verified offset for both operations. diff diff --git a/src/session/session-utils.c b/src/session/session-utils.c index XXXXXXX..YYYYYYY 100644 — a/src/session/session-utils.c +++ b/src/session/session-utils.c @@ -6,6 +6,7 @@ #include "session-utils.h" #include "common/cockpitframe.h" +#include <limits.h> #include "common/cockpitjsonprint.h" #include "common/cockpitmemory.h" @@ -194,6 +195,18 @@ dolastlog (uidt uid, bool result = false; int fd = -1; ssizet r; + offt offset; + + if ((uintmaxt) uid > ((uintmaxt) OFFMAX / (uintmaxt) sizeof entry)) + { + warnx ("uid %u causes lastlog offset overflow", (unsigned) uid); + goto out; + } + + offset = (offt) uid (offt) sizeof entry; + if (offset < 0) + goto out; @@ -207,7 +220,7 @@ dolastlog (uidt uid, r = pread (fd, &entry, sizeof entry, uid sizeof entry); + r = pread (fd, &entry, sizeof entry, offset); @@ -277,7 +290,7 @@ dolastlog (uidt uid,

r = pwrite (fd, &entry, sizeof entry, uid sizeof entry); + r = pwrite (fd, &entry, sizeof entry, offset);

------ This report was generated using AI technology. Always review AI-generated content prior to use

— Red Hat

Affected Software

1 affected component
Cockpit cockpit-356-1.el10=cockpit-356-1.el10

Event History

May 18, 2026
Data Sourced
via Red Hat·04:06 AM
DescriptionSeverityAffected Software
Sep 18, 2026
CVE Published
via MITRE·04:44 PM
Data Sourced
via MITRE·04:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Exposure requires an ILP32 build and a deployment where the cockpit-session path updates the legacy /var/log/lastlog file. The affected component identified is Cockpit cockpit-356-1.el10.

2

What does an attacker need to exploit it?

The attacker needs a low-privileged authenticated account that can log in through Cockpit and a specially provisioned UID large enough to overflow the uid multiplied by sizeof(struct lastlog) offset calculation. No user interaction is required.

3

What could exploitation allow?

A successful offset wrap can misaddress legacy lastlog records, allowing unauthorized reads and writes to other users' login accounting entries. This may disclose or alter sensitive login accounting information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203