Thread (34 messages) 34 messages, 8 authors, 2011-09-19

Re: [kernel-hardening] Re: [RFC PATCH 2/2] mm: restrict access to /proc/slabinfo

From: Vasiliy Kulikov <hidden>
Date: 2011-09-18 17:05:49
Also in: lkml

Possibly related (same subject, not in this thread)

Hi Andrew,

On Wed, Sep 14, 2011 at 12:27 -0700, Kees Cook wrote:
On Sat, Sep 10, 2011 at 08:41:34PM +0400, Vasiliy Kulikov wrote:
quoted
Historically /proc/slabinfo has 0444 permissions and is accessible to
the world.  slabinfo contains rather private information related both to
the kernel and userspace tasks.  Depending on the situation, it might
reveal either private information per se or information useful to make
another targeted attack.  Some examples of what can be learned by
reading/watching for /proc/slabinfo entries:
...
World readable slabinfo simplifies kernel developers' job of debugging
kernel bugs (e.g. memleaks), but I believe it does more harm than
benefits.  For most users 0444 slabinfo is an unreasonable attack vector.

Signed-off-by: Vasiliy Kulikov <redacted>
Haven't had any mass complaints about the 0400 in Ubuntu (sorry Dave!), so
I'm obviously for it.

Reviewed-by: Kees Cook <redacted>
Looks like the members of the previous slabinfo discussion don't object
against the patch now and it got two other Reviewed-by responses.  Can
you merge it as-is or should I probably convince someone else?

Thanks,

-- 
Vasiliy Kulikov
http://www.openwall.com - bringing security into open computing environments

--
To unsubscribe, send a message with 'unsubscribe linux-mm' in
the body to majordomo@kvack.org.  For more info on Linux MM,
see: http://www.linux-mm.org/ .
Fight unfair telecom internet charges in Canada: sign http://stopthemeter.ca/
Don't email: <a href=mailto:"dont@kvack.org"> email@kvack.org </a>
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help