Canonical Ubuntu Pro Client Input Validation and Injection Vulnerability Allowing Arbitrary Code Execution
Vulnerability
A vulnerability allowing input validation and injection has been identified in Canonical Ubuntu Pro Client (formerly Ubuntu Advantage Tools). This issue arises because the client creates APT source files using data from the contract server response, specifically the directives.suites[] and directives.aptURL fields. The client employs Python's str.format() method to generate these files without proper escaping, validation, or filtering of newline characters. As a result, a malicious or altered contract response containing embedded newline characters can inject arbitrary, attacker-controlled Debian configuration lines into root-owned APT sources. When this vulnerability is exploited in conjunction with the unvalidated additionalPackages[] field— which is directly passed to a root-executed apt-get install command—an attacker who can manipulate the contract response can force the client to download and install malicious packages. This chain of events ultimately leads to arbitrary code execution with root privileges on the affected system. This vulnerability affects all supported Ubuntu Server releases and is automatically included by default on cloud provider Ubuntu Pro images.
Impact
Exploitation of this vulnerability allows for arbitrary code execution with root privileges on the affected system.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
