Tejun Heo
8a887060af
cgroup: Use open-time cgroup namespace for process migration perm checks
...
commit e57457641613fef0d147ede8bd6a3047df588b95 upstream.
cgroup process migration permission checks are performed at write time as
whether a given operation is allowed or not is dependent on the content of
the write - the PID. This currently uses current's cgroup namespace which is
a potential security weakness as it may allow scenarios where a less
privileged process tricks a more privileged one into writing into a fd that
it created.
This patch makes cgroup remember the cgroup namespace at the time of open
and uses it for migration permission checks instad of current's. Note that
this only applies to cgroup2 as cgroup1 doesn't have namespace support.
This also fixes a use-after-free bug on cgroupns reported in
https://lore.kernel.org/r/00000000000048c15c05d0083397@google.com
Note that backporting this fix also requires the preceding patch.
Reported-by: "Eric W. Biederman" <ebiederm@xmission.com>
Suggested-by: Linus Torvalds <torvalds@linuxfoundation.org>
Cc: Michal Koutný <mkoutny@suse.com>
Cc: Oleg Nesterov <oleg@redhat.com>
Reviewed-by: Michal Koutný <mkoutny@suse.com>
Reported-by: syzbot+50f5cf33a284ce738b62@syzkaller.appspotmail.com
Link: https://lore.kernel.org/r/00000000000048c15c05d0083397@google.com
Fixes: 5136f6365c ("cgroup: implement "nsdelegate" mount option")
Signed-off-by: Tejun Heo <tj@kernel.org>
[mkoutny: v5.10: duplicate ns check in procs/threads write handler, adjust context]
Signed-off-by: Michal Koutný <mkoutny@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[OP: backport to v5.4: drop changes to cgroup_attach_permissions() and
cgroup_css_set_fork(), adjust cgroup_procs_write_permission() calls]
Signed-off-by: Ovidiu Panait <ovidiu.panait@windriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-15 14:18:41 +02:00
..
bpf
bpf: Add kconfig knob for disabling unpriv bpf by default
2022-02-16 12:52:49 +01:00
cgroup
cgroup: Use open-time cgroup namespace for process migration perm checks
2022-04-15 14:18:41 +02:00
configs
debug
kdb: Make memory allocations more robust
2021-03-04 10:26:10 +01:00
dma
dma-debug: fix return value of __setup handlers
2022-04-15 14:18:18 +02:00
events
perf/core: Fix address filter parser for multiple filters
2022-04-15 14:18:06 +02:00
gcov
gcov: re-fix clang-11+ support
2021-04-14 08:24:10 +02:00
irq
genirq/timings: Fix error return code in irq_timings_test_irqs()
2021-09-15 09:47:29 +02:00
livepatch
locking
locking/lockdep: Avoid RCU-induced noinstr fail
2021-11-17 09:48:28 +01:00
power
PM: suspend: fix return value of __setup handler
2022-04-15 14:18:05 +02:00
printk
printk: fix return value of printk.devkmsg __setup handler
2022-04-15 14:18:08 +02:00
rcu
rcu: Don't deboost before reporting expedited quiescent state
2022-03-28 08:46:48 +02:00
sched
sched/debug: Remove mpol_get/put and task_lock/unlock from sched_show_numa
2022-04-15 14:18:06 +02:00
time
timekeeping: Really make sure wall_to_monotonic isn't positive
2021-12-22 09:29:39 +01:00
trace
tracing: Ensure trace buffer is at least 4096 bytes large
2022-03-16 13:21:47 +01:00
.gitignore
kbuild: update config_data.gz only when the content of .config is changed
2021-05-11 14:04:16 +02:00
acct.c
async.c
Revert "module, async: async_synchronize_full() on module init iff async is used"
2022-02-23 11:59:56 +01:00
audit.c
audit: improve audit queue handling when "audit=1" on cmdline
2022-02-08 18:24:26 +01:00
audit.h
audit: log AUDIT_TIME_* records only from rules
2022-04-15 14:18:04 +02:00
audit_fsnotify.c
audit_tree.c
audit: move put_tree() to avoid trim_trees refcount underflow and UAF
2021-09-03 10:08:16 +02:00
audit_watch.c
audit: CONFIG_CHANGE don't log internal bookkeeping as an event
2020-10-01 13:17:32 +02:00
auditfilter.c
auditsc.c
audit: log AUDIT_TIME_* records only from rules
2022-04-15 14:18:04 +02:00
backtracetest.c
bounds.c
capability.c
compat.c
configs.c
context_tracking.c
cpu.c
cpu/hotplug: Cure the cpusets trainwreck
2021-07-19 08:53:15 +02:00
cpu_pm.c
crash_core.c
crash_dump.c
cred.c
delayacct.c
dma.c
exec_domain.c
exit.c
don't dump the threads that had been already exiting when zapped.
2020-11-18 19:20:31 +01:00
extable.c
fail_function.c
fail_function: Remove a redundant mutex unlock
2020-11-24 13:29:18 +01:00
fork.c
copy_process(): Move fd_install() out of sighand->siglock critical section
2022-02-23 12:00:00 +01:00
freezer.c
futex.c
mm, futex: fix shared futex pgoff on shmem huge page
2021-06-30 08:47:55 -04:00
gen_kheaders.sh
kbuild: add variables for compression tools
2020-09-03 11:27:10 +02:00
groups.c
hung_task.c
iomem.c
irq_work.c
jump_label.c
kallsyms.c
kallsyms: Refactor kallsyms_show_value() to take cred
2020-07-16 08:16:44 +02:00
kcmp.c
exec: Transform exec_update_mutex into a rw_semaphore
2021-01-09 13:44:55 +01:00
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kexec.c
kexec_core.c
kernel: kexec: remove the lock operation of system_transition_mutex
2021-02-03 23:25:56 +01:00
kexec_elf.c
kexec_file.c
kernel: kexec_file: fix error return code of kexec_calculate_store_digests()
2021-05-19 10:08:28 +02:00
kexec_internal.h
kheaders.c
kmod.c
kprobes.c
kprobes: Limit max data_size of the kretprobe instances
2021-12-08 09:01:10 +01:00
ksysfs.c
kthread.c
kthread: Fix PF_KTHREAD vs to_kthread() race
2021-09-12 08:56:39 +02:00
latencytop.c
Makefile
kbuild: update config_data.gz only when the content of .config is changed
2021-05-11 14:04:16 +02:00
module-internal.h
module.c
module/ftrace: handle patchable-function-entry
2022-02-23 11:59:56 +01:00
module_signature.c
module: harden ELF info handling
2021-04-07 14:47:38 +02:00
module_signing.c
module: harden ELF info handling
2021-04-07 14:47:38 +02:00
notifier.c
kernel/notifier.c: intercept duplicate registrations to avoid infinite loops
2020-10-01 13:17:23 +02:00
nsproxy.c
padata.c
panic.c
params.c
pid.c
pid_namespace.c
memcg: enable accounting for pids in nested pid namespaces
2021-09-22 12:26:37 +02:00
profile.c
profiling: fix shift-out-of-bounds bugs
2021-09-26 14:07:09 +02:00
ptrace.c
ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE
2022-04-15 14:17:58 +02:00
range.c
reboot.c
reboot: fix overflow parsing reboot cpu number
2020-11-18 19:20:30 +01:00
relay.c
kernel/relay.c: fix memleak on destroy relay channel
2020-08-26 10:40:51 +02:00
resource.c
rseq.c
seccomp.c
seccomp: Invalidate seccomp mode to catch death failures
2022-02-16 12:52:53 +01:00
signal.c
signal: Remove the bogus sigkill_pending in ptrace_stop
2021-11-17 09:48:24 +01:00
smp.c
smp: Fix smp_call_function_single_async prototype
2021-05-14 09:44:33 +02:00
smpboot.c
kthread: Extract KTHREAD_IS_PER_CPU
2021-02-07 15:35:49 +01:00
smpboot.h
softirq.c
stackleak.c
stacktrace.c
stop_machine.c
sys.c
prctl: allow to setup brk for et_dyn executables
2021-09-26 14:07:08 +02:00
sys_ni.c
sysctl-test.c
kernel/sysctl-test: Add null pointer test for sysctl.c:proc_dointvec()
2020-10-01 13:17:10 +02:00
sysctl.c
x86/speculation: Include unprivileged eBPF status in Spectre v2 mitigation reporting
2022-03-11 11:22:37 +01:00
sysctl_binary.c
task_work.c
taskstats.c
test_kprobes.c
torture.c
tracepoint.c
tracepoint: Add tracepoint_probe_register_may_exist() for BPF tracing
2021-07-14 16:53:08 +02:00
tsacct.c
taskstats: Cleanup the use of task->exit_code
2022-02-23 11:59:57 +01:00
ucount.c
uid16.c
uid16.h
umh.c
usermodehelper: reset umask to default before executing user process
2020-10-14 10:32:58 +02:00
up.c
smp: Fix smp_call_function_single_async prototype
2021-05-14 09:44:33 +02:00
user-return-notifier.c
user.c
user_namespace.c
utsname.c
utsname_sysctl.c
watchdog.c
watchdog_hld.c
workqueue.c
workqueue: Fix unbind_workers() VS wq_worker_running() race
2022-01-16 09:15:38 +01:00
workqueue_internal.h