Re: [PATCH 3/4] devpts: Make the newinstance option historical

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sat, Sep 22, 2012 at 10:59:04PM -0700, Eric W. Biederman wrote:

> The test:
> >> +	if (filp->f_vfsmnt->mnt_root == filp->f_dentry)
> kicks in and no redirection is performed.

Umm...  OK, after the first round of recursion.  Unless you bind /something/pts
on /something.  Or simply create a symlink.  Hell, if static /dev is on the
same fs as /tmp, it can even be done by unpriveleged attacker -
mkdir /tmp/pts
ln /dev/ptmx /tmp
ln -s /tmp/ptmx /tmp/pts/ptmx
exec </tmp/ptmx
and enjoy the stack overflow in kernel mode.  It's not particulary common
setup, of course, but I think it demonstrates that you are playing with
fire...
_______________________________________________
Containers mailing list
Containers@xxxxxxxxxxxxxxxxxxxxxxxxxx
https://lists.linuxfoundation.org/mailman/listinfo/containers


[Index of Archives]     [Cgroups]     [Netdev]     [Linux Wireless]     [Kernel Newbies]     [Security]     [Linux for Hams]     [Netfilter]     [Bugtraq]     [Yosemite Forum]     [MIPS Linux]     [ARM Linux]     [Linux RAID]     [Linux Admin]     [Samba]

  Powered by Linux