{"id":"GHSA-72w7-mf9g-733p","summary":"nono-py has proxy-only network fallback bypass on older Linux kernels","details":"## Summary\n\nOn Linux kernels that do not support Landlock network rules, `nono_py.sandboxed_exec()` could run `CapabilitySet.proxy_only(proxy)` without supervising the seccomp-notify proxy-only fallback returned by the Rust core.\n\nIn that configuration, a sandboxed child process could remove `HTTP_PROXY` / `HTTPS_PROXY` environment variables or use raw sockets and then open direct TCP connections that should have been denied by proxy-only policy.\n\nThe issue affects proxy-only enforcement. It does not mean that all nono-py network blocking is ineffective. ECS validation showed `caps.block_network()` denied regular TCP and ECS metadata TCP on the tested Linux 6.1 host.\n\n## Impact\n\nThe intended `proxy_only()` security property is:\n\n- child processes may connect only to the local nono proxy port\n- the proxy enforces host allowlists and metadata/link-local denial\n- direct TCP to any other target is denied\n\nBefore the fix, on kernels without Landlock `AccessNet`, the Python binding applied the sandbox and then executed the child, but did not install and supervise the proxy-only seccomp-notify fallback. A child could therefore bypass the proxy layer in that old-kernel path.\n\nThe highest-impact scenario is a sandboxed workload with access to cloud metadata discovery inputs, where direct TCP to a metadata endpoint could retrieve task or instance credentials after proxy environment variables are removed.\n\n## Affected Conditions\n\nThe issue requires all of the following:\n\n- Linux runtime.\n- Kernel without Landlock network support, such as Linux 6.1. Landlock network rules require Landlock ABI v4 / Linux 6.7 or newer.\n- `nono_py.sandboxed_exec()` is used.\n- The capability set uses `caps.proxy_only(proxy)`.\n- The child process removes or ignores proxy environment variables, or uses raw sockets.\n\nmacOS Seatbelt proxy-only enforcement is not affected by this Linux seccomp-notify fallback issue.\n\n## Affected Versions\n\nKnown affected builds include nono-py versions that expose and use `CapabilitySet.proxy_only()` through `sandboxed_exec()` before the supervised fallback fix in this working tree.\n\nEarlier versions that did not expose `CapabilitySet.proxy_only()` are not affected by this specific proxy-only enforcement bug, though they may have separate environment-inheritance risks if callers passed broad parent environment variables into sandboxed children.\n\n\n**CVSS Score Rationale**\n\n| Metric | Value | Rationale |\n|---|---|---|\n| **Attack Vector (AV)** | L — Local | Exploit is performed by a local process (unsetting env vars or opening raw sockets). Not remotely triggerable. |\n| **Attack Complexity (AC)** | H — High | All of the following must be true: Linux runtime; kernel \u003c 6.7 (no Landlock ABI v4); `sandboxed_exec()` used; capability set calls `proxy_only()`; child actively bypasses proxy env vars or uses raw sockets. |\n| **Privileges Required (PR)** | L — Low | Attacker is already executing code inside the sandbox — some user-level privilege is required to get there. |\n| **User Interaction (UI)** | N — None | No action from a user or operator is needed once the sandboxed child is running. |\n| **Scope (S)** | C — Changed | The exploit crosses the sandbox security boundary, allowing the child to reach network resources outside the defined policy scope. |\n| **Confidentiality (C)** | H — High | Highest-impact path: direct TCP to cloud metadata endpoint (169.254.169.254) yields IAM / task credentials. |\n| **Integrity (I)** | L — Low | Attacker can make arbitrary outbound requests; no direct data modification from the bypass itself, but lateral credential use creates indirect risk. |\n| **Availability (A)** | N — None | No denial-of-service impact described or implied. |\n\n---","modified":"2026-06-26T20:45:12.245070869Z","published":"2026-06-26T20:33:48Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-26T20:33:48Z","nvd_published_at":null,"cwe_ids":["CWE-693"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/always-further/nono-py/security/advisories/GHSA-72w7-mf9g-733p"},{"type":"WEB","url":"https://github.com/nolabs-ai/nono-py/commit/3e67dfa11cbe9514f315fdd36473680c318816d7"},{"type":"PACKAGE","url":"https://github.com/always-further/nono-py"}],"affected":[{"package":{"name":"nono-py","ecosystem":"PyPI","purl":"pkg:pypi/nono-py"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.9.0"},{"fixed":"0.10.1"}]}],"versions":["0.10.0","0.9.0","0.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-72w7-mf9g-733p/GHSA-72w7-mf9g-733p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N"}]}