No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Alfred Piccioni 3dd76bebcd lsm: new security_file_ioctl_compat() hook
commit f1bb47a31dff6d4b34fb14e99850860ee74bb003 upstream.

Some ioctl commands do not require ioctl permission, but are routed to
other permissions such as FILE_GETATTR or FILE_SETATTR. This routing is
done by comparing the ioctl cmd to a set of 64-bit flags (FS_IOC_*).

However, if a 32-bit process is running on a 64-bit kernel, it emits
32-bit flags (FS_IOC32_*) for certain ioctl operations. These flags are
being checked erroneously, which leads to these ioctl operations being
routed to the ioctl permission, rather than the correct file
permissions.

This was also noted in a RED-PEN finding from a while back -
"/* RED-PEN how should LSM module know it's handling 32bit? */".

This patch introduces a new hook, security_file_ioctl_compat(), that is
called from the compat ioctl syscall. All current LSMs have been changed
to support this hook.

Reviewing the three places where we are currently using
security_file_ioctl(), it appears that only SELinux needs a dedicated
compat change; TOMOYO and SMACK appear to be functional without any
change.

Cc: stable@vger.kernel.org
Fixes: 0b24dcb7f2 ("Revert "selinux: simplify ioctl checking"")
Signed-off-by: Alfred Piccioni <alpic@google.com>
Reviewed-by: Stephen Smalley <stephen.smalley.work@gmail.com>
[PM: subject tweak, line length fixes, and alignment corrections]
Signed-off-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Eric Biggers <ebiggers@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-23 08:25:15 +01:00
arch mips: Fix max_mapnr being uninitialized on early stages 2024-02-23 08:25:13 +01:00
block blk-mq: fix IO hang from sbitmap wakeup race 2024-02-23 08:25:03 +01:00
certs
crypto crypto: api - Disallow identical driver names 2024-02-23 08:24:48 +01:00
Documentation net: sysfs: Fix /sys/class/net/<iface> path 2024-02-23 08:25:05 +01:00
drivers drm/msm/dsi: Enable runtime PM 2024-02-23 08:25:14 +01:00
fs lsm: new security_file_ioctl_compat() hook 2024-02-23 08:25:15 +01:00
include lsm: new security_file_ioctl_compat() hook 2024-02-23 08:25:15 +01:00
init rootfs: Fix support for rootfstype= when root= is given 2024-01-25 14:34:30 -08:00
ipc ipc/sem: Fix dangling sem_array access in semtimedop race 2022-12-08 11:23:06 +01:00
kernel sched/membarrier: reduce the ability to hammer on sys_membarrier 2024-02-23 08:25:14 +01:00
lib ida: Fix crash in ida_free when the bitmap is empty 2024-01-25 14:34:21 -08:00
LICENSES
mm mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again 2024-02-23 08:25:10 +01:00
net net: prevent mss overflow in skb_segment() 2024-02-23 08:25:14 +01:00
samples samples/bpf: Fix buffer overflow in tcp_basertt 2023-07-27 08:37:07 +02:00
scripts kbuild: Fix changing ELF file type for output of gen_btf for big endian 2024-02-23 08:25:10 +01:00
security lsm: new security_file_ioctl_compat() hook 2024-02-23 08:25:15 +01:00
sound ALSA: hda/conexant: Add quirk for SWS JS201D 2024-02-23 08:25:12 +01:00
tools selftests: net: avoid just another constant wait 2024-02-23 08:25:06 +01:00
usr
virt KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache 2024-02-23 08:25:14 +01:00
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS iio: stx104: Move to addac subdirectory 2023-08-30 16:27:12 +02:00
Makefile Linux 5.4.268 2024-01-25 14:34:33 -08:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.