|
|
Log in / Subscribe / Register

setgid hardening

From:  Andy Lutomirski <luto-AT-kernel.org>
To:  security-AT-kernel.org
Subject:  [PATCH 0/2] setgid hardening
Date:  Wed, 25 Jan 2017 13:06:50 -0800
Message-ID:  <cover.1485377903.git.luto@kernel.org>
Cc:  Konstantin Khlebnikov <koct9i-AT-gmail.com>, Alexander Viro <viro-AT-zeniv.linux.org.uk>, Kees Cook <keescook-AT-chromium.org>, Willy Tarreau <w-AT-1wt.eu>, "linux-mm-AT-kvack.org" <linux-mm-AT-kvack.org>, Andrew Morton <akpm-AT-linux-foundation.org>, yalin wang <yalin.wang2010-AT-gmail.com>, Linux Kernel Mailing List <linux-kernel-AT-vger.kernel.org>, Jan Kara <jack-AT-suse.cz>, Linux FS Devel <linux-fsdevel-AT-vger.kernel.org>, Andy Lutomirski <luto-AT-kernel.org>

The kernel has some dangerous behavior involving the creation and
modification of setgid executables.  These issues aren't kernel
security bugs per se, but they have been used to turn various
filesystem permission oddities into reliably privilege escalation
exploits.

See http://www.halfdog.net/Security/2015/SetgidDirectoryPrivi...
for a nice writeup.

Let's fix them for real.

Andy Lutomirski (2):
  fs: Check f_cred instead of current's creds in should_remove_suid()
  fs: Harden against open(..., O_CREAT, 02777) in a setgid directory

 fs/inode.c         | 37 ++++++++++++++++++++++++++++++-------
 fs/internal.h      |  2 +-
 fs/ocfs2/file.c    |  4 ++--
 fs/open.c          |  2 +-
 include/linux/fs.h |  2 +-
 5 files changed, 35 insertions(+), 12 deletions(-)

-- 
2.9.3



Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds