linux-kernel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [2.6.16/18 patch] security/seclvl.c: fix time wrap (CVE-2005-4352)
@ 2006-11-15 16:01 Adrian Bunk
  0 siblings, 0 replies; only message in thread
From: Adrian Bunk @ 2006-11-15 16:01 UTC (permalink / raw)
  To: Chris Wright, Michael Halcrow; +Cc: linux-kernel, stable

initlvl=2 in seclvl gives the guarantee
"Cannot decrement the system time".

But it was possible to set the time to the maximum unixtime value 
(19 Jan 2038) resulting in a wrap to the minimum value.

This patch fixes this by disallowing setting the time to any date
after 2031 with initlvl=2.

This patch does not apply to kernel 2.6.19 since the seclvl module was 
already removed in this kernel.

Signed-off-by: Adrian Bunk <bunk@stusta.de>

--- linux-2.6.16.32/security/seclvl.c.old	2006-11-15 13:58:05.000000000 +0100
+++ linux-2.6.16.32/security/seclvl.c	2006-11-15 16:41:51.000000000 +0100
@@ -381,6 +381,8 @@ static int seclvl_settime(struct timespe
 				      current->group_leader->pid);
 			return -EPERM;
 		}		/* if attempt to decrement time */
+		if (tv->tv_sec > 1924988400)	/* disallow dates after 2030) */
+			return -EPERM;		/* CVE-2005-4352 */
 	}			/* if seclvl > 1 */
 	return 0;
 }

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2006-11-15 16:01 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-11-15 16:01 [2.6.16/18 patch] security/seclvl.c: fix time wrap (CVE-2005-4352) Adrian Bunk

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).