From mboxrd@z Thu Jan 1 00:00:00 1970 From: Kay Sievers Date: Fri, 21 Aug 2009 11:59:17 +0000 Subject: Re: [security] Race condition in udev Message-Id: List-Id: References: <20090821102407.GA29609@florz.florz.dyndns.org> In-Reply-To: <20090821102407.GA29609@florz.florz.dyndns.org> MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: linux-hotplug@vger.kernel.org On Fri, Aug 21, 2009 at 13:25, Florian Zumbiehl wrote: >> On Fri, Aug 21, 2009 at 12:24, Florian Zumbiehl wrote: >> > reading some of the source of udev, I noticed what I would suspect to be a >> > race condition with security implications, namely that device nodes >> > are first mknod()/chmod()ed with the permission mask that they're supposed >> > to have at the end, but potentially at this point applying to the >> > wrong owner and group, before then being chown()ed to the correct >> > owner and group. >> >> The device node is owned by root, what's the problem here? > > at least after the (first) chown() it potentially isn't owned by root, so > your statement in that form is false. The mknod() already happens with the configured mode, so after the chown() we already have the configured permissions/ownership set. Kay