Miklos Szeredi
02c6be615f
vfs: fix permission checking in sys_utimensat
...
If utimensat() is called with both times set to UTIME_NOW or one of them to
UTIME_NOW and the other to UTIME_OMIT, then it will update the file time
without any permission checking.
I don't think this can be used for anything other than a local DoS, but could
be quite bewildering at that (e.g. "Why was that large source tree rebuilt
when I didn't modify anything???")
This affects all kernels from 2.6.22, when the utimensat() syscall was
introduced.
Fix by doing the same permission checking as for the "times == NULL" case.
Thanks to Michael Kerrisk, whose utimensat-non-conformances-and-fixes.patch in
-mm also fixes this (and breaks other stuff), only he didn't realize the
security implications of this bug.
Signed-off-by: Miklos Szeredi <mszeredi@suse.cz>
Cc: Ulrich Drepper <drepper@redhat.com>
Cc: Michael Kerrisk <mtk-manpages@gmx.net>
Cc: <stable@kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2008-05-01 08:03:59 -07:00
..
2008-04-25 09:23:25 -04:00
2008-04-30 08:29:54 -07:00
2008-04-30 08:29:51 -07:00
2008-04-30 08:29:54 -07:00
2008-02-08 09:22:40 -08:00
2008-04-30 08:29:54 -07:00
2008-04-29 08:05:59 -07:00
2008-04-30 08:29:54 -07:00
2008-04-29 08:06:18 -07:00
2008-04-29 08:06:04 -07:00
2008-04-30 08:29:54 -07:00
2008-04-18 22:16:44 -04:00
2008-04-30 16:52:47 -07:00
2008-04-30 08:29:48 -07:00
2008-04-30 08:29:54 -07:00
2008-04-29 08:06:25 -07:00
2008-04-02 15:28:19 -07:00
2008-04-30 08:29:54 -07:00
2008-04-28 08:58:43 -07:00
2008-04-29 22:01:27 -04:00
2008-04-29 22:01:18 -04:00
2008-04-30 08:29:54 -07:00
2008-04-29 08:06:00 -07:00
2008-04-30 08:29:51 -07:00
2008-04-30 08:29:54 -07:00
2008-04-30 08:29:52 -07:00
2008-04-30 08:29:52 -07:00
2008-02-05 09:44:30 -08:00
2008-02-08 09:22:40 -08:00
2008-03-19 06:42:18 -04:00
2008-04-30 08:29:50 -07:00
2008-04-30 08:29:33 -07:00
2008-04-28 08:58:45 -07:00
2008-04-29 08:06:20 -07:00
2008-04-30 08:29:54 -07:00
2008-04-29 08:06:18 -07:00
2008-04-30 08:29:54 -07:00
2008-02-07 08:42:28 -08:00
2008-04-30 08:29:54 -07:00
2008-04-29 08:06:28 -07:00
2008-04-30 08:29:49 -07:00
2008-04-30 08:29:54 -07:00
2007-10-18 14:37:31 -07:00
2008-04-30 08:29:54 -07:00
2008-04-30 08:29:50 -07:00
2008-02-07 08:42:29 -08:00
2008-04-30 08:29:54 -07:00
2008-04-30 08:29:50 -07:00
2008-02-07 08:42:28 -08:00
2008-04-30 08:29:50 -07:00
2008-04-30 08:29:51 -07:00
2008-03-19 18:53:36 -07:00
2008-04-30 08:29:54 -07:00
2008-04-30 16:52:46 -07:00
2008-04-30 08:29:52 -07:00
2008-04-30 08:29:54 -07:00
2008-04-28 08:58:45 -07:00
2008-04-30 08:29:54 -07:00
2008-04-30 07:53:50 -07:00
2008-04-30 08:29:53 -07:00
2008-03-19 06:54:05 -04:00
2007-10-18 14:37:22 -07:00
2008-02-07 08:42:26 -08:00
2008-04-29 08:06:04 -07:00
2008-04-29 08:06:05 -07:00
2008-04-29 08:06:16 -07:00
2008-04-29 08:06:04 -07:00
2008-04-29 08:06:17 -07:00
2008-04-29 08:06:04 -07:00
2008-04-29 08:06:04 -07:00
2008-04-25 09:23:53 -04:00
2008-04-29 09:50:34 +02:00
2008-02-19 10:04:00 +01:00
2008-04-30 08:29:54 -07:00
2008-04-29 08:06:01 -07:00
2008-01-30 13:31:46 +01:00
2008-04-30 08:29:47 -07:00
2008-04-30 08:29:37 -07:00
2008-04-23 00:04:38 -04:00
2008-02-14 21:17:09 -08:00
2008-02-05 09:44:13 -08:00
2008-04-30 20:09:00 -07:00
2008-04-28 08:58:33 -07:00
2008-04-29 08:06:05 -07:00
2008-02-06 10:41:03 -08:00
2008-04-30 08:29:37 -07:00
2008-04-30 08:29:38 -07:00
2008-04-25 09:24:05 -04:00
2007-05-21 09:18:19 -07:00
2008-04-19 00:29:28 -04:00
2008-02-06 10:41:06 -08:00
2007-05-08 11:15:01 -07:00
2008-04-29 08:06:00 -07:00
2007-07-17 12:00:03 -07:00
2008-04-29 08:06:06 -07:00
2008-04-29 08:06:25 -07:00
2008-02-06 10:41:07 -08:00
2008-04-21 23:11:01 -04:00
2008-04-29 08:06:00 -07:00
2008-01-28 11:38:15 +01:00
2008-04-30 13:38:47 +02:00
2008-04-29 08:06:01 -07:00
2008-02-05 09:44:13 -08:00
2008-04-25 15:49:46 -07:00
2008-01-30 13:31:46 +01:00
2008-04-15 19:35:41 -07:00
2008-03-03 10:47:13 -08:00
2008-04-29 08:06:09 -07:00
2008-04-30 08:29:54 -07:00
2008-02-14 21:13:33 -08:00
2008-04-28 08:58:23 -07:00
2008-04-22 19:54:57 -04:00
2008-04-23 00:05:09 -04:00
2008-04-23 00:05:09 -04:00
2008-04-28 08:58:32 -07:00
2008-04-30 08:29:51 -07:00
2008-04-28 08:58:33 -07:00
2008-04-22 15:17:11 -07:00
2007-12-06 17:39:54 -05:00
2008-04-30 08:29:37 -07:00
2008-04-23 00:04:38 -04:00
2008-04-11 08:06:44 -07:00
2008-04-29 09:48:15 +02:00
2007-02-19 14:21:50 -08:00
2008-02-14 21:13:33 -08:00
2008-04-29 08:06:00 -07:00
2008-04-29 08:06:06 -07:00
2008-04-29 08:06:01 -07:00
2008-05-01 08:03:59 -07:00
2007-02-14 08:09:54 -08:00
2008-04-29 08:06:06 -07:00