Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #79665

Re: HFS/HFS+ are insecure

Path csiph.com!fu-berlin.de!bofh.it!news.nic.it!robomod
From Matthew Garrett <mjg59@srcf.ucam.org>
Newsgroups linux.debian.devel, linux.debian.kernel, linux.debian.bugs.dist
Subject Re: HFS/HFS+ are insecure
Date Fri, 21 Jul 2023 19:40:04 +0200
Message-ID <GU2gH-1MGS-19@gated-at.bofh.it> (permalink)
References <GTG6t-1z5m-11@gated-at.bofh.it> <GTG6t-1z5m-13@gated-at.bofh.it> <GTG6t-1z5m-15@gated-at.bofh.it> <GTG6t-1z5m-17@gated-at.bofh.it> <GTG6t-1z5m-19@gated-at.bofh.it> <GTG6t-1z5m-21@gated-at.bofh.it> <GTG6t-1z5m-23@gated-at.bofh.it> <GTG6t-1z5m-31@gated-at.bofh.it> <GTTGp-1HxK-3@gated-at.bofh.it> <GTU9r-1HIa-5@gated-at.bofh.it>
X-Mailbox-Line From debian-devel-request@lists.debian.org Fri Jul 21 17:36:00 2023
Old-Return-Path <mjg59@codon.org.uk>
X-Amavis-Spam-Status No, score=-6.66 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, FOURLA=0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.25, LDO_WHITELIST=-5, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=unavailable autolearn_force=no
X-Policyd-Weight using cached result; rate: -4.6
X-Greylist delayed 33326 seconds by postgrey-1.36 at bendel; Fri, 21 Jul 2023 17:35:41 UTC
MIME-Version 1.0
Content-Type text/plain; charset=us-ascii
Content-Disposition inline
User-Agent Mutt/1.10.1 (2018-07-13)
X-Mailing-List <debian-devel@lists.debian.org> archive/latest/356638
List-ID <debian-devel.lists.debian.org>
List-URL <https://lists.debian.org/debian-devel/>
List-Archive https://lists.debian.org/msgid-search/20230721173536.GA26591@srcf.ucam.org
Approved robomod@news.nic.it
Lines 23
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Fri, 21 Jul 2023 18:35:36 +0100
X-Original-Message-ID <20230721173536.GA26591@srcf.ucam.org>
X-Original-References <2575F983-D170-4B79-A6BA-912D4ED2CC73@dubeyko.com> <46F233BB-E587-4F2B-AA62-898EB46C9DCE@dubeyko.com> <Y7bw7X1Y5KtmPF5s@casper.infradead.org> <50D6A66B-D994-48F4-9EBA-360E57A37BBE@dubeyko.com> <CACT4Y+aJb4u+KPAF7629YDb2tB2geZrQm5sFR3M+r2P1rgicwQ@mail.gmail.com> <ZLlvII/jMPTT32ef@casper.infradead.org> <2d0bd58fb757e7771d13f82050a546ec5f7be8de.camel@physik.fu-berlin.de> <ZLl1PLU938klkucC@bongo.bofh.it> <20230721082012.GA19433@srcf.ucam.org> <ZLpIC6moiUdmca3y@bongo.bofh.it>
Xref csiph.com linux.debian.devel:108707 linux.debian.kernel:79665 linux.debian.bugs.dist:1155185

Cross-posted to 3 groups.

Show key headers only | View raw


On Fri, Jul 21, 2023 at 10:55:39AM +0200, Marco d'Itri wrote:

> Unless somebody has a better idea then then my plan is to ship in the 
> next upload of kmod a file in /etc/modprobe.d/ which uses the blacklist 
> directive to prevent automatically loading some file system modules.

I think this would break any existing fstab entries that reference hfs 
and hfsplus, and the convenient way to integrate Linux boot with x86 
Macs is certainly to have an hfsplus EFI partition so this may be a 
legitimate use-case. It also means that anyone who has a need to use one 
of these filesystems in a static manner is vulnerable to automount 
attacks using them.

Completely untested, but I think something along the lines of:

SUBSYSTEM!="block", GOTO="udisks_insecure_fs_end"
ENV{ID_FS_TYPE}=="hfs", ENV{UDISKS_AUTO}="0"
ENV{ID_FS_TYPE}=="hfsplus", ENV{UDISKS_AUTO}="0"
LABEL="udisks_insecure_fs_end"

in a udev fragment should work? Any static fstab or mount units should 
still work, but it should disable udisks automounting regardless of the 
desktop agent involved, even if the fs modules are already loaded.

Back to linux.debian.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#1041552: HFS/HFS+ are insecure Marco d'Itri <md@Linux.IT> - 2023-07-20 20:10 +0200
  Re: HFS/HFS+ are insecure Marco d'Itri <md@Linux.IT> - 2023-07-21 11:00 +0200
    Re: HFS/HFS+ are insecure Magissia <debianlist@magissia.com> - 2023-07-21 11:10 +0200
    Re: HFS/HFS+ are insecure Martin Steigerwald <martin@lichtvoll.de> - 2023-07-21 12:10 +0200
    Re: HFS/HFS+ are insecure Bastien Roucariès <rouca@debian.org> - 2023-07-21 13:00 +0200
      Re: HFS/HFS+ are insecure Bastien Roucariès <rouca@debian.org> - 2023-07-21 13:10 +0200
    Re: HFS/HFS+ are insecure Matthew Garrett <mjg59@srcf.ucam.org> - 2023-07-21 19:40 +0200
      Re: HFS/HFS+ are insecure Ben Hutchings <ben@decadent.org.uk> - 2023-07-23 02:40 +0200
  Processed: Re: HFS/HFS+ are insecure "Debian Bug Tracking System" <owner@bugs.debian.org> - 2023-08-27 02:40 +0200
  Bug#1041552: HFS/HFS+ are insecure Marco d'Itri <md@Linux.IT> - 2023-08-27 02:40 +0200

csiph-web