Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1560289
| From | Greg KH <gregkh@linuxfoundation.org> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH 2/3] Make static usermode helper binaries constant |
| Date | 2017-01-17 08:20 +0100 |
| Message-ID | <t0wdH-41a-3@gated-at.bofh.it> (permalink) |
| References | <t0iDL-30L-3@gated-at.bofh.it> <t0iNr-34Q-13@gated-at.bofh.it> <t0n0K-6iP-35@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Mon, Jan 16, 2017 at 04:25:55PM -0500, J. Bruce Fields wrote:
> On Mon, Jan 16, 2017 at 05:50:31PM +0100, Greg KH wrote:
> > From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
> >
> > There are a number of usermode helper binaries that are "hard coded" in
> > the kernel today, so mark them as "const" to make it harder for someone
> > to change where the variables point to.
> >
> ...
> > --- a/drivers/pnp/pnpbios/core.c
> > +++ b/drivers/pnp/pnpbios/core.c
> > @@ -98,6 +98,7 @@ static struct completion unload_sem;
> > */
> > static int pnp_dock_event(int dock, struct pnp_docking_station_info *info)
> > {
> > + static char const sbin_pnpbios[] = "/sbin/pnpbios";
> > char *argv[3], **envp, *buf, *scratch;
> > int i = 0, value;
> >
> > @@ -112,7 +113,7 @@ static int pnp_dock_event(int dock, struct pnp_docking_station_info *info)
> > * integrated into the driver core and use the usual infrastructure
> > * like sysfs and uevents
> > */
> > - argv[0] = "/sbin/pnpbios";
> > + argv[0] = (char *)sbin_pnpbios;
>
> So here and elsewhere, can attackers write to argv[0] instead of to the
> memory where the string lives?
Yes, they could, it would be a very "tight" race to do that (have to
write after the assignment and before the call_usermodehelper_exec()
runs). However, the kernel does not run argv[0], it just passes it to
the binary you specify in path, so for this example, the correct program
would still be run by the kernel.
But, if you do worry about this type of attack, then enable the option I
created in patch 3/3 here, which will funnel all calls into a single
userspace binary where you can then filter on argv[0] to see if you want
to run the binary or not to prevent this type of attack.
> Apologies if I'm rehashing earlier discussion, I did a quick search of
> archives but could easily have missed something.
No problem at all, hopefully I've explained it better now.
thanks,
greg k-h
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 0/4] make call_usermodehelper a bit more "safe" Greg KH <gregkh@linuxfoundation.org> - 2017-01-16 17:50 +0100
[PATCH 2/3] Make static usermode helper binaries constant Greg KH <gregkh@linuxfoundation.org> - 2017-01-16 18:00 +0100
Re: [PATCH 2/3] Make static usermode helper binaries constant "J. Bruce Fields" <bfields@fieldses.org> - 2017-01-16 22:30 +0100
Re: [PATCH 2/3] Make static usermode helper binaries constant Greg KH <gregkh@linuxfoundation.org> - 2017-01-17 08:20 +0100
Re: [PATCH 2/3] Make static usermode helper binaries constant "J. Bruce Fields" <bfields@fieldses.org> - 2017-01-17 16:20 +0100
Re: [PATCH 2/3] Make static usermode helper binaries constant Greg KH <gregkh@linuxfoundation.org> - 2017-01-17 16:30 +0100
Re: [kernel-hardening] Re: [PATCH 2/3] Make static usermode helper binaries constant Greg KH <gregkh@linuxfoundation.org> - 2017-01-19 13:10 +0100
Re: [kernel-hardening] Re: [PATCH 2/3] Make static usermode helper binaries constant "J. Bruce Fields" <bfields@fieldses.org> - 2017-01-19 17:30 +0100
Re: [PATCH 2/3] Make static usermode helper binaries constant Jeff Layton <jlayton@poochiereds.net> - 2017-01-17 16:50 +0100
Re: [PATCH 2/3] Make static usermode helper binaries constant Greg KH <gregkh@linuxfoundation.org> - 2017-01-17 17:00 +0100
Re: [PATCH 2/3] Make static usermode helper binaries constant Jeff Layton <jlayton@poochiereds.net> - 2017-01-17 17:10 +0100
Re: [PATCH 2/3] Make static usermode helper binaries constant Greg KH <gregkh@linuxfoundation.org> - 2017-01-17 17:20 +0100
[PATCH 1/3] kmod: make usermodehelper path a const string Greg KH <gregkh@linuxfoundation.org> - 2017-01-16 18:00 +0100
Re: [PATCH 0/4] make call_usermodehelper a bit more "safe" Greg KH <gregkh@linuxfoundation.org> - 2017-01-16 18:00 +0100
[PATCH 3/3] Introduce STATIC_USERMODEHELPER to mediate call_usermodehelper() Greg KH <gregkh@linuxfoundation.org> - 2017-01-16 18:00 +0100
Re: [PATCH 3/3] Introduce STATIC_USERMODEHELPER to mediate call_usermodehelper() Jeff Layton <jlayton@poochiereds.net> - 2017-01-17 17:30 +0100
Re: [PATCH 3/3] Introduce STATIC_USERMODEHELPER to mediate call_usermodehelper() Greg KH <gregkh@linuxfoundation.org> - 2017-01-17 17:40 +0100
Re: [PATCH 3/3] Introduce STATIC_USERMODEHELPER to mediate call_usermodehelper() Jeff Layton <jlayton@poochiereds.net> - 2017-01-17 18:00 +0100
Re: [PATCH 0/4] make call_usermodehelper a bit more "safe" Kees Cook <keescook@chromium.org> - 2017-01-17 18:30 +0100
csiph-web