netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH 0/5] Raw socket cleanups
@ 2019-09-20  7:35 Greg Kroah-Hartman
  2019-09-20  7:35 ` [PATCH 1/5] mISDN: enforce CAP_NET_RAW for raw sockets Greg Kroah-Hartman
                   ` (5 more replies)
  0 siblings, 6 replies; 9+ messages in thread
From: Greg Kroah-Hartman @ 2019-09-20  7:35 UTC (permalink / raw)
  To: netdev
  Cc: isdn, jreuter, ralf, alex.aring, stefan, orinimron123,
	Greg Kroah-Hartman

Ori Nimron pointed out that there are a number of places in the kernel
where you can create a raw socket, without having to have the
CAP_NET_RAW permission.

To resolve this, here's a short patch series to test these odd and old
protocols for this permission before allowing the creation to succeed

All patches are currently against the net tree.

thanks,

greg k-h

Ori Nimron (5):
  mISDN: enforce CAP_NET_RAW for raw sockets
  appletalk: enforce CAP_NET_RAW for raw sockets
  ax25: enforce CAP_NET_RAW for raw sockets
  ieee802154: enforce CAP_NET_RAW for raw sockets
  nfc: enforce CAP_NET_RAW for raw sockets

 drivers/isdn/mISDN/socket.c | 2 ++
 net/appletalk/ddp.c         | 5 +++++
 net/ax25/af_ax25.c          | 2 ++
 net/ieee802154/socket.c     | 3 +++
 net/nfc/llcp_sock.c         | 7 +++++--
 5 files changed, 17 insertions(+), 2 deletions(-)

-- 
2.23.0


^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2019-09-24 14:38 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-09-20  7:35 [PATCH 0/5] Raw socket cleanups Greg Kroah-Hartman
2019-09-20  7:35 ` [PATCH 1/5] mISDN: enforce CAP_NET_RAW for raw sockets Greg Kroah-Hartman
2019-09-20  7:35 ` [PATCH 2/5] appletalk: " Greg Kroah-Hartman
2019-09-20  7:35 ` [PATCH 3/5] ax25: " Greg Kroah-Hartman
2019-09-20  7:35 ` [PATCH 4/5] ieee802154: " Greg Kroah-Hartman
2019-09-21 11:58   ` Stefan Schmidt
2019-09-21 12:30     ` Greg Kroah-Hartman
2019-09-20  7:35 ` [PATCH 5/5] nfc: " Greg Kroah-Hartman
2019-09-24 14:38 ` [PATCH 0/5] Raw socket cleanups David Miller

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).