All of lore.kernel.org
 help / color / mirror / Atom feed
From: yalin wang <yalin.wang2010@gmail.com>
To: Kees Cook <keescook@chromium.org>
Cc: Andrew Morton <akpm@linux-foundation.org>,
	Jan Kara <jack@suse.cz>, Willy Tarreau <w@1wt.eu>,
	"Eric W. Biederman" <ebiederm@xmission.com>,
	"Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>,
	Oleg Nesterov <oleg@redhat.com>, Rik van Riel <riel@redhat.com>,
	Chen Gang <gang.chen.5i5j@gmail.com>,
	Davidlohr Bueso <dave@stgolabs.net>,
	Andrea Arcangeli <aarcange@redhat.com>,
	linux-mm@kvack.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v2] clear file privilege bits when mmap writing
Date: Thu, 3 Dec 2015 17:45:06 -0800	[thread overview]
Message-ID: <B4520E53-6DD9-44D7-A064-9F405FBAA793@gmail.com> (raw)
In-Reply-To: <20151203000342.GA30015@www.outflux.net>


> On Dec 2, 2015, at 16:03, Kees Cook <keescook@chromium.org> wrote:
> 
> Normally, when a user can modify a file that has setuid or setgid bits,
> those bits are cleared when they are not the file owner or a member
> of the group. This is enforced when using write and truncate but not
> when writing to a shared mmap on the file. This could allow the file
> writer to gain privileges by changing a binary without losing the
> setuid/setgid/caps bits.
> 
> Changing the bits requires holding inode->i_mutex, so it cannot be done
> during the page fault (due to mmap_sem being held during the fault).
> Instead, clear the bits if PROT_WRITE is being used at mmap time.
> 
> Signed-off-by: Kees Cook <keescook@chromium.org>
> Cc: stable@vger.kernel.org
> —

is this means mprotect() sys call also need add this check?
mprotect() can change to PROT_WRITE, then it can write to a 
read only map again , also a secure hole here .

Thanks


WARNING: multiple messages have this Message-ID (diff)
From: yalin wang <yalin.wang2010@gmail.com>
To: Kees Cook <keescook@chromium.org>
Cc: Andrew Morton <akpm@linux-foundation.org>,
	Jan Kara <jack@suse.cz>, Willy Tarreau <w@1wt.eu>,
	"Eric W. Biederman" <ebiederm@xmission.com>,
	"Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>,
	Oleg Nesterov <oleg@redhat.com>, Rik van Riel <riel@redhat.com>,
	Chen Gang <gang.chen.5i5j@gmail.com>,
	Davidlohr Bueso <dave@stgolabs.net>,
	Andrea Arcangeli <aarcange@redhat.com>,
	linux-mm@kvack.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v2] clear file privilege bits when mmap writing
Date: Thu, 3 Dec 2015 17:45:06 -0800	[thread overview]
Message-ID: <B4520E53-6DD9-44D7-A064-9F405FBAA793@gmail.com> (raw)
In-Reply-To: <20151203000342.GA30015@www.outflux.net>


> On Dec 2, 2015, at 16:03, Kees Cook <keescook@chromium.org> wrote:
> 
> Normally, when a user can modify a file that has setuid or setgid bits,
> those bits are cleared when they are not the file owner or a member
> of the group. This is enforced when using write and truncate but not
> when writing to a shared mmap on the file. This could allow the file
> writer to gain privileges by changing a binary without losing the
> setuid/setgid/caps bits.
> 
> Changing the bits requires holding inode->i_mutex, so it cannot be done
> during the page fault (due to mmap_sem being held during the fault).
> Instead, clear the bits if PROT_WRITE is being used at mmap time.
> 
> Signed-off-by: Kees Cook <keescook@chromium.org>
> Cc: stable@vger.kernel.org
> —

is this means mprotect() sys call also need add this check?
mprotect() can change to PROT_WRITE, then it can write to a 
read only map again , also a secure hole here .

Thanks

--
To unsubscribe, send a message with 'unsubscribe linux-mm' in
the body to majordomo@kvack.org.  For more info on Linux MM,
see: http://www.linux-mm.org/ .
Don't email: <a href=mailto:"dont@kvack.org"> email@kvack.org </a>

  parent reply	other threads:[~2015-12-04  1:45 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-12-03  0:03 [PATCH v2] fs: clear file privilege bits when mmap writing Kees Cook
2015-12-03  0:18 ` Andrew Morton
2015-12-03  0:18   ` Andrew Morton
2015-12-03 16:07   ` Kees Cook
2015-12-03 16:07     ` Kees Cook
2015-12-03 18:19   ` Kees Cook
2015-12-03 18:19     ` Kees Cook
2015-12-04  1:45 ` yalin wang [this message]
2015-12-04  1:45   ` [PATCH v2] " yalin wang
2015-12-07 22:42   ` Kees Cook
2015-12-07 22:42     ` Kees Cook
2015-12-08  0:40     ` Kees Cook
2015-12-08  0:40       ` Kees Cook
2015-12-09  8:26       ` Jan Kara
2015-12-09  8:26         ` Jan Kara
2015-12-09 22:52         ` Kees Cook
2015-12-09 22:52           ` Kees Cook

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=B4520E53-6DD9-44D7-A064-9F405FBAA793@gmail.com \
    --to=yalin.wang2010@gmail.com \
    --cc=aarcange@redhat.com \
    --cc=akpm@linux-foundation.org \
    --cc=dave@stgolabs.net \
    --cc=ebiederm@xmission.com \
    --cc=gang.chen.5i5j@gmail.com \
    --cc=jack@suse.cz \
    --cc=keescook@chromium.org \
    --cc=kirill.shutemov@linux.intel.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=oleg@redhat.com \
    --cc=riel@redhat.com \
    --cc=w@1wt.eu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.