From mboxrd@z Thu Jan 1 00:00:00 1970 From: Robby Workman Date: Tue, 25 Aug 2009 18:04:17 +0000 Subject: Re: [security] Race condition in udev Message-Id: <20090825130417.5918ebf3@liberty.rlwhome.lan> MIME-Version: 1 Content-Type: multipart/mixed; boundary="Sig_/3X2wb=_0aFphGi03Kr/1Bql" List-Id: References: <20090821102407.GA29609@florz.florz.dyndns.org> In-Reply-To: <20090821102407.GA29609@florz.florz.dyndns.org> To: linux-hotplug@vger.kernel.org --Sig_/3X2wb=_0aFphGi03Kr/1Bql Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: quoted-printable On Tue, 25 Aug 2009 10:42:49 -0700 Greg KH wrote: > On Tue, Aug 25, 2009 at 07:31:30PM +0200, Florian Zumbiehl wrote: > > Assumption: > >=20 > > /dev/foo is configured to be owned by user root, group users, mode > > 0646. The attacker tries to open /dev/foo for writing as a user > > that's not root, not a member of the group root, but a member of > > the group users. > >=20 > > The Trace: > >=20 > > action | owner | group | mode | > > open(O_WRONLY)? > > ----------------------------+-------+-------+---------+----------------- > > mknod(/dev/foo) | root | root | 0644(?) | no > > chmod(/dev/foo,0646) | root | root | 0646 | yes > > chown(/dev/foo,root,users) | root | users | 0646 | no >=20 > Are there any current device nodes that get set to this kind of "odd" > permissions with the current udev ruleset? Even if there are, I still don't see how it's a bug in udev. If you have a rule that configures a device with world-writable permissions, why does it matter which group owns the device? -RW --Sig_/3X2wb=_0aFphGi03Kr/1Bql Content-Type: application/pgp-signature; name=signature.asc Content-Disposition: attachment; filename=signature.asc -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.12 (GNU/Linux) iEYEARECAAYFAkqUJ6UACgkQvGy9tf6lsvvj7ACgpAYcM7q5OgPNWfpZPm6/NEJL UlgAnR+hljymYdodkrsVmm2DkjHYcO+3 =3wP9 -----END PGP SIGNATURE----- --Sig_/3X2wb=_0aFphGi03Kr/1Bql--