From mboxrd@z Thu Jan 1 00:00:00 1970 From: Kay Sievers Date: Sat, 29 Aug 2009 14:15:06 +0000 Subject: Re: [security] Race condition in udev Message-Id: List-Id: References: <20090821102407.GA29609@florz.florz.dyndns.org> In-Reply-To: <20090821102407.GA29609@florz.florz.dyndns.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 8bit To: linux-hotplug@vger.kernel.org On Fri, Aug 28, 2009 at 19:34, Florian Zumbiehl wrote: >> below you find a patch that should fix the specific issue - I just am >> not sure that it interacts nicely with the rest of udev. Also, I haven't >> tried it, not even compiled it. > > here is another patch for basically the same problem in > util_unlink_secure(), same disclaimer applies. > > Florian > > diff --git a/libudev/libudev-util-private.c b/libudev/libudev-util-private.c > index 3641b36..28008c5 100644 > --- a/libudev/libudev-util-private.c > +++ b/libudev/libudev-util-private.c > @@ -102,6 +102,10 @@ int util_unlink_secure(struct udev *udev, const char *filename) >  { >        int retval; > > +       retval = chmod(filename, 0000); > +       if (retval) > +               err(udev, "chmod(%s, 0000) failed: %m\n", filename); > + >        retval = chown(filename, 0, 0); >        if (retval) >                err(udev, "chown(%s, 0, 0) failed: %m\n", filename); We need only one chmod() here. I changed the order. Thanks, Kay