Thread (12 messages) read the whole thread 12 messages, 4 authors, 2024-05-21

Re: [PATCH v6 0/3] implement OA2_CRED_INHERIT flag for openat2()

From: stsp <hidden>
Date: 2024-05-07 09:02:21
Also in: linux-fsdevel, lkml

07.05.2024 10:50, Aleksa Sarai пишет:
If you are a privileged process which plans to change users,
Not privileged at all.
But I think what you say is still possible
with userns?

A new attack I just thought of while writing this mail is that because
there is no RESOLVE_NO_XDEV requirement, it should be possible for the
process to get an arbitrary write primitive by creating a new
userns+mountns and then bind-mounting / underneath the directory.
Doesn't this need a write perm to a
directory? In his case this is not a threat,
because you are not supposed to have a
write perm to that dir. OA2_CRED_INHERIT
is the only way to write.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help