Skip to content

Commit 3f05eed

Browse files
committed
fix: restrict ruby gem update task to ubuntu and handle failures gracefully
**Changed:** - Clarified in documentation that vulnerable ruby gem dependencies are updated only on Ubuntu, as Kali handles CVE patches via apt - Limited the gem update task to Ubuntu by adding a distribution check and explicitly excluding Kali - Added `failed_when: false` to the gem update task to prevent task failure if the update process is killed or encounters issues - Expanded documentation and task comments to explain the rationale behind these changes and the memory limitations during gem updates
1 parent 2753390 commit 3f05eed

2 files changed

Lines changed: 9 additions & 5 deletions

File tree

‎ansible/roles/lateral_movement_tools/README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -118,7 +118,7 @@ Install and configure lateral movement and credential extraction tools for Ares
118118
- **Create symlink for ffitarget.h in standard include path** (ansible.builtin.file) - Conditional
119119
- **Install rubyzip gem for evil-winrm dependency** (community.general.gem) - Conditional
120120
- **Install evil-winrm gem (Ubuntu only, Kali uses apt)** (community.general.gem) - Conditional
121-
- **Update vulnerable ruby gem dependencies (per-gem to bound memory)** (ansible.builtin.command) - Conditional
121+
- **Update vulnerable ruby gem dependencies (Ubuntu only - Kali patches via apt)** (ansible.builtin.command) - Conditional
122122
- **Install pth-toolkit (Kali only - may not be available in all repos)** (ansible.builtin.apt) - Conditional
123123
- **Warn if pth-toolkit installation failed** (ansible.builtin.debug) - Conditional
124124
- **Install Impacket from source for lateral movement tools** (ansible.builtin.include_tasks) - Conditional

‎ansible/roles/lateral_movement_tools/tasks/linux.yml‎

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -229,13 +229,16 @@
229229
- ansible_facts['distribution'] != 'Kali'
230230
- lateral_movement_tools_install_evil_winrm
231231

232-
# Per-gem loop (not `gem update a b c d e`) to avoid OOM kill (rc=-9) during
233-
# parallel native-extension compile on the AMI build instance. `--no-document`
234-
# skips rdoc/ri generation, which is the heaviest memory hog.
235-
- name: Update vulnerable ruby gem dependencies (per-gem to bound memory)
232+
# `gem update` is skipped on Kali: evil-winrm ships via apt and Kali tracks
233+
# CVE patches for net-imap/rexml/uri/zlib through its `ruby-*` debs. On
234+
# AMI builders, `gem update` here also tends to SIGKILL (rc=-9) inside the
235+
# Image Builder runner regardless of `--no-document`, so we keep it
236+
# best-effort with `failed_when: false` and limit it to non-Kali Debian.
237+
- name: Update vulnerable ruby gem dependencies (Ubuntu only - Kali patches via apt)
236238
ansible.builtin.command: gem update --no-document {{ item }}
237239
become: true
238240
changed_when: true
241+
failed_when: false
239242
loop:
240243
- net-imap
241244
- resolv
@@ -244,6 +247,7 @@
244247
- zlib
245248
when:
246249
- ansible_facts['os_family'] == 'Debian'
250+
- ansible_facts['distribution'] != 'Kali'
247251
- lateral_movement_tools_install_evil_winrm
248252

249253
- name: Install pth-toolkit (Kali only - may not be available in all repos)

0 commit comments

Comments
 (0)