Thread (11 messages) 11 messages, 6 authors, 2018-10-01

Leaking Path in XFS's ioctl interface(missing LSM check)

From: jmorris@namei.org (James Morris)
Date: 2018-09-27 21:23:52
Also in: linux-xfs, lkml

On Thu, 27 Sep 2018, Dave Chinner wrote:
Sure, but there are so many CAP_SYS_ADMIN-only ioctls in the kernel
that have no LSM coverage that this is not an isolated problem that
people setting up such systems have to deal with. 
I could be missing something here, but all ioctls are mediated by LSM at a 
high level (security_file_ioctl). Some problematic ones are singled out at 
that point by LSMs for special handling.


-- 
James Morris
[off-list ref]
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help