Another Linux capabilities hole found
Posted Apr 16, 2009 14:45 UTC (Thu) by
bfields (subscriber, #19510)
In reply to:
Another Linux capabilities hole found by Cyberax
Parent article:
Another Linux capabilities hole found
Also, note the problem here was on the *server* side, not the client. And the question of why the server is in the kernel is also interesting, but irrelevant in this case since the userspace server was equally affected by this bug--the userspace server uses setfsuid(), which uses the same mask bits as the in-kernel nfsd is using.
(
Log in to post comments)