Thread (4 messages) 4 messages, 4 authors, 2018-09-26

leaking path in android binder: set_nice

From: gregkh@linuxfoundation.org (Greg KH)
Date: 2018-09-25 17:38:16
Also in: lkml

On Tue, Sep 25, 2018 at 01:27:11PM -0400, Tong Zhang wrote:
Kernel Version: 4.18.5

Problem Description:

When setting nice value, it is checked by LSM function security_task_setnice().
see kernel/sched/core.c:3972 SYSCALL_DEFINE1(nice, int, increment)

We discovered a leaking path in android binder which allows using binder?s interface to change 
a process?s nice value. This path is leaked from being monitored by LSM.
see drivers/android/binder.c:1107 binder_set_nice.
Can you please submit a patch for this to get the proper credit for
finding and fixing this?

thanks,

greg k-h
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help