![oss-sec logo](/images/oss-sec-logo.png)
oss-sec mailing list archives
Re: pt_chown timeline, CVE request [was: Access to /dev/pts devices via pt_chown and user namespaces]
From: Aurelien Jarno <aurelien () aurel32 net>
Date: Sun, 28 Feb 2016 16:23:44 +0100
On 2016-02-28 15:53, Jann Horn wrote:
As others figured out in the private bug discussion, pt_chown is already not installed as setuid binary by glibc anymore. That it is present in Debian and Ubuntu is because of a distro patch in Debian, which Debian applied to work around the bug that the
To be correct, it's not really a patch, but rather a configure option.
"[PATCH] devpts: Sensible /dev/ptmx & force newinstance" patch is supposed to fix. So with a fix for that issue applied, Debian and Ubuntu should be able to just drop the distro patch, fixing the vuln by removing pt_chown.
Note that in the meantime we have developed an alternative workaround on the glibc side, which allows to not break systems with multiple /dev/pts mounts, though the result is not POSIX compliant: https://sourceware.org/git/?p=glibc.git;a=commit;h=77356912e83601fd0240d22fe4d960348b82b5c3 This commit is included in glibc 2.23, and on the Debian side we have backported it to glibc 2.21 and to 2.22, and pushed the result to the users. We have also backported it to 2.19 (Debian jessie), but not pushed it to users yet (it is in progress). Aurelien -- Aurelien Jarno GPG: 4096R/1DDD8C9B aurelien () aurel32 net http://www.aurel32.net
Attachment:
signature.asc
Description:
Current thread:
- Re: Access to /dev/pts devices via pt_chown and user namespaces, (continued)
- Re: Access to /dev/pts devices via pt_chown and user namespaces Solar Designer (Feb 23)
- Re: Access to /dev/pts devices via pt_chown and user namespaces Dmitry V. Levin (Feb 23)
- Re: Access to /dev/pts devices via pt_chown and user namespaces halfdog (Feb 23)
- Re: Access to /dev/pts devices via pt_chown and user namespaces Simon McVittie (Feb 23)
- Re: Access to /dev/pts devices via pt_chown and user namespaces Dmitry V. Levin (Feb 24)
- Re: Access to /dev/pts devices via pt_chown and user namespaces Serge Hallyn (Feb 24)
- Re: Access to /dev/pts devices via pt_chown and user namespaces Jakub Wilk (Feb 27)
- Re: Access to /dev/pts devices via pt_chown and user namespaces Dmitry V. Levin (Feb 23)
- Re: Access to /dev/pts devices via pt_chown and user namespaces Solar Designer (Feb 23)
- Re: Access to /dev/pts devices via pt_chown and user namespaces Alan Coopersmith (Feb 23)
- Re: pt_chown timeline, CVE request [was: Access to /dev/pts devices via pt_chown and user namespaces] Aurelien Jarno (Feb 28)