Thread (5 messages) flat view 5 messages, 3 authors, 2022-09-29

Re: [PATCH v1] ksmbd: Fix user namespace mapping

From: Namjae Jeon <linkinjeon@kernel.org>
Date: 2022-09-29 12:38:16
Also in: linux-cifs, linux-fsdevel, lkml, stable

2022-09-29 19:04 GMT+09:00, Mickaël Salaün [off-list ref]:
A kernel daemon should not rely on the current thread, which is unknown
and might be malicious.  Before this security fix,
ksmbd_override_fsids() didn't correctly override FS UID/GID which means
that arbitrary user space threads could trick the kernel to impersonate
arbitrary users or groups for file system access checks, leading to
file system access bypass.

This was found while investigating truncate support for Landlock:
https://lore.kernel.org/r/CAKYAXd8fpMJ7guizOjHgxEyyjoUwPsx3jLOPZP=wPYcbhkVXqA@mail.gmail.com (local)

Fixes: e2f34481b24d ("cifsd: add server-side procedures for SMB3")
Cc: Hyunchul Lee <hyc.lee@gmail.com>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: Steve French <redacted>
Cc: stable@vger.kernel.org
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Link: https://lore.kernel.org/r/20220929100447.108468-1-mic@digikod.net (local)
Acked-by: Namjae Jeon <linkinjeon@kernel.org>

Thanks!
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help