Thread (11 messages) 11 messages, 2 authors, 2016-08-09

Re: [PATCH 5/5] fs: Avoid premature clearing of capabilities

From: Christoph Hellwig <hch@infradead.org>
Date: 2016-08-09 08:29:15
Also in: ceph-devel, linux-fsdevel

On Wed, Aug 03, 2016 at 01:28:09PM +0200, Jan Kara wrote:
Currently, notify_change() clears capabilities or IMA attributes by
calling security_inode_killpriv() before calling into ->setattr. Thus it
happens before any other permission checks in inode_change_ok() and user
is thus allowed to trigger clearing of capabilities or IMA attributes
for any file he can look up e.g. by calling chown for that file. This is
unexpected and can lead to user DoSing a system.

Fix the problem by calling security_inode_killpriv() at the end of
inode_change_ok() instead of from notify_change(). At that moment we are
sure user has permissions to do the requested change.
Looks fine,

Reviewed-by: Christoph Hellwig <hch@lst.de>

_______________________________________________
xfs mailing list
xfs@oss.sgi.com
http://oss.sgi.com/mailman/listinfo/xfs
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help