From mboxrd@z Thu Jan 1 00:00:00 1970 From: Kay Sievers Date: Sat, 29 Aug 2009 14:32:05 +0000 Subject: Re: [security] Race condition in udev Message-Id: List-Id: References: <20090821102407.GA29609@florz.florz.dyndns.org> In-Reply-To: <20090821102407.GA29609@florz.florz.dyndns.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 8bit To: linux-hotplug@vger.kernel.org On Sat, Aug 29, 2009 at 16:20, Florian Zumbiehl wrote: >> > diff --git a/libudev/libudev-util-private.c b/libudev/libudev-util-private.c >> > index 3641b36..28008c5 100644 >> > --- a/libudev/libudev-util-private.c >> > +++ b/libudev/libudev-util-private.c >> > @@ -102,6 +102,10 @@ int util_unlink_secure(struct udev *udev, const char *filename) >> >  { >> >        int retval; >> > >> > +       retval = chmod(filename, 0000); >> > +       if (retval) >> > +               err(udev, "chmod(%s, 0000) failed: %m\n", filename); >> > + >> >        retval = chown(filename, 0, 0); >> >        if (retval) >> >                err(udev, "chown(%s, 0, 0) failed: %m\n", filename); >> >> We need only one chmod() here. I changed the order. > > no, you need both. In the case that the device belonged to non-root before, > the owner could do a chmod() in between the chmod() and chown() and thus > retain privileges on the device node. What about fchmod(), how's that handled in such case? Kay