lp:~terrykrudd/ubuntu/+source/linux/+git/xenial
- Get this repository:
-
git clone
https://git.launchpad.net/~terrykrudd/ubuntu/+source/linux/+git/xenial
Branches
Name | Last Modified | Last Commit |
---|---|---|
cranky-review | 2018-11-23 23:09:04 UTC |
mount: Don't allow copying MNT_UNBINDABLE|MNT_LOCKED mounts
Author:
Eric W. Biederman
mount: Don't allow copying MNT_UNBINDABLE| BugLink: https:/ Jonathan Calmels from NVIDIA reported that he's able to bypass the Reproducer: # As an unprivileged user, unshare user namespace and mount namespace # Confirm the path is still not accessible # Make /sys recursively unbindable and private # Recursively bind-mount the rest of /sys over to /mnnt # Access our hidden /sys/device as an unprivileged user Solve this by teaching copy_tree to fail if a mount turns out to be Cc: stable@ |
crank-review | 2018-11-21 17:12:30 UTC |
mount: Don't allow copying MNT_UNBINDABLE|MNT_LOCKED mounts
Author:
Eric W. Biederman
mount: Don't allow copying MNT_UNBINDABLE| BugLink: https:/ Jonathan Calmels from NVIDIA reported that he's able to bypass the Reproducer: # As an unprivileged user, unshare user namespace and mount namespace # Confirm the path is still not accessible # Make /sys recursively unbindable and private # Recursively bind-mount the rest of /sys over to /mnnt # Access our hidden /sys/device as an unprivileged user Solve this by teaching copy_tree to fail if a mount turns out to be Cc: stable@ |
1 → 2 of 2 results | First • Previous • Next • Last |