public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH] kernel/time: Make /proc/timer_list mode 0400
@ 2010-11-17 17:08 Marcus Meissner
  2010-11-17 17:18 ` Peter Zijlstra
  0 siblings, 1 reply; 10+ messages in thread
From: Marcus Meissner @ 2010-11-17 17:08 UTC (permalink / raw)
  To: tglx, mingo, a.p.zijlstra, akpm, rusty, torvalds; +Cc: linux-kernel

Hi,

/proc/timer_list contains kernel addresses, like e.g.:
 #0: <c000000001404158>, tick_sched_timer, S:01, .tick_nohz_restart_sched_tick, swapper/0
 ...

Avoid leaking them to user space to make writing kernel exploits a bit harder.

(I currently cannot think of a userland tool that uses this, this is
likely pretty much root-only.)

Ciao, Marcus

Signed-off-by: Marcus Meissner <meissner@suse.de>
---
 kernel/time/timer_list.c |    2 +-
 1 files changed, 1 insertions(+), 1 deletions(-)

diff --git a/kernel/time/timer_list.c b/kernel/time/timer_list.c
index ab8f5e3..5ae1ce3 100644
--- a/kernel/time/timer_list.c
+++ b/kernel/time/timer_list.c
@@ -293,7 +293,7 @@ static int __init init_timer_list_procfs(void)
 {
 	struct proc_dir_entry *pe;
 
-	pe = proc_create("timer_list", 0444, NULL, &timer_list_fops);
+	pe = proc_create("timer_list", 0400, NULL, &timer_list_fops);
 	if (!pe)
 		return -ENOMEM;
 	return 0;
-- 
1.7.1


^ permalink raw reply related	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2010-11-30 19:22 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-11-17 17:08 [PATCH] kernel/time: Make /proc/timer_list mode 0400 Marcus Meissner
2010-11-17 17:18 ` Peter Zijlstra
2010-11-17 17:21   ` Marcus Meissner
2010-11-17 17:33     ` Peter Zijlstra
2010-11-30 19:21     ` Pavel Machek
2010-11-17 20:30   ` Andrew Morton
2010-11-17 20:37     ` Thomas Gleixner
2010-11-18  8:12       ` Ingo Molnar
2010-11-18  8:28         ` Eric Dumazet
2010-11-30 19:22         ` Pavel Machek

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox