A local root vulnerability in glibc
A local root vulnerability in glibc
Posted Oct 5, 2023 19:54 UTC (Thu) by joib (subscriber, #8541)In reply to: A local root vulnerability in glibc by kreijack
Parent article: A local root vulnerability in glibc
please_give_me_root_capabilities_using_an_ipc(2) doesn't sound useful; to me it sounds like it would inherit all the problems of suid. AFAICT the idea behind this ipc approach would be that the process running with elevated privileges would start from a clean slate in its own environment.
There's also file capabilities, which are a sort of limited suid:
$ getcap /usr/{bin,sbin}/*
/usr/bin/mtr-packet cap_net_raw=ep
/usr/bin/ping cap_net_raw=ep
But, it does sound a bit silly if you'd need to do some IPC in order to run something like ping in a different clean context.
The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:
Note: you can avoid this step in the future by logging into your LWN account.
