]> git.karo-electronics.de Git - karo-tx-linux.git/commitdiff
Reset current->pdeath_signal on SUID binary execution (CVE-2007-3848)
authorMarcel Holtmann <marcel@holtmann.org>
Sat, 6 Oct 2007 22:03:26 +0000 (00:03 +0200)
committerAdrian Bunk <bunk@kernel.org>
Sat, 6 Oct 2007 22:03:26 +0000 (00:03 +0200)
This fixes a vulnerability in the "parent process death signal"
implementation discoverd by Wojciech Purczynski of COSEINC PTE Ltd.
and iSEC Security Research.

http://marc.info/?l=bugtraq&m=118711306802632&w=2

Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
Signed-off-by: Adrian Bunk <bunk@kernel.org>
fs/exec.c

index 0b515ac531348650a59c61c8de6b362953b7bea7..91a36b27ec914fda0201d986203e3b405a16ec66 100644 (file)
--- a/fs/exec.c
+++ b/fs/exec.c
@@ -891,9 +891,12 @@ int flush_old_exec(struct linux_binprm * bprm)
         */
        current->mm->task_size = TASK_SIZE;
 
-       if (bprm->e_uid != current->euid || bprm->e_gid != current->egid || 
-           file_permission(bprm->file, MAY_READ) ||
-           (bprm->interp_flags & BINPRM_FLAGS_ENFORCE_NONDUMP)) {
+       if (bprm->e_uid != current->euid || bprm->e_gid != current->egid) {
+               suid_keys(current);
+               current->mm->dumpable = suid_dumpable;
+               current->pdeath_signal = 0;
+       } else if (file_permission(bprm->file, MAY_READ) ||
+                       (bprm->interp_flags & BINPRM_FLAGS_ENFORCE_NONDUMP)) {
                suid_keys(current);
                current->mm->dumpable = suid_dumpable;
        }
@@ -991,8 +994,10 @@ void compute_creds(struct linux_binprm *bprm)
 {
        int unsafe;
 
-       if (bprm->e_uid != current->uid)
+       if (bprm->e_uid != current->uid) {
                suid_keys(current);
+               current->pdeath_signal = 0;
+       }
        exec_keys(current);
 
        task_lock(current);