DM-Crypt Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [dm-crypt] An observation
@ 2012-11-27 17:25 Bhushan Jain
  2012-11-27 17:49 ` Milan Broz
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Bhushan Jain @ 2012-11-27 17:25 UTC (permalink / raw)
  To: dm-crypt@saout.de

Hello Developers,

I am a student at Stony Brook University researching system security.
I noticed that the only reason dmcrypt-get-device (from eject package) needs setuid privilege is to read the major:minor numbers (unless I have missed something).
A lot of distributions (Ubuntu, Fedora, etc.) are trying to avoid use of the setuid bit because it can potentially introduce a privilege escalation attack vector.
I think the same thing could be accomplished by exporting the major:minor device numbers through a proc file, and then eliminate the need for dmcrypt-get-device.
I would be happy to send you a patch that does this, if there is interest.  Any comments/thoughts?

Thanks,
Bhushan Jain
PhD student,
Computer Science,
Stony Brook University

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2013-07-10  3:21 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-11-27 17:25 [dm-crypt] An observation Bhushan Jain
2012-11-27 17:49 ` Milan Broz
2012-11-27 18:29 ` Javier Juan Martínez Cabezón
2013-07-10  2:10 ` Karl O. Pinc
2013-07-10  3:15   ` Bhushan Jain

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox