Re: [Coverity] Untrusted user data in kernel

From: James Morris
Date: Fri Dec 17 2004 - 01:46:54 EST

On Fri, 17 Dec 2004, Patrick McHardy wrote:

> James Morris wrote:
> >This at least needs CAP_NET_ADMIN.
> >
> It is already checked in do_ip6t_set_ctl(). Otherwise anyone could
> replace iptables rules :)

That's what I meant, you need the capability to do anything bad :-)

- James
James Morris

To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at
Please read the FAQ at