Re: [patch 1/2] c/r: prctl: Add ability to set newmm_struct::exe_file

From: Andrew Morton
Date: Mon Mar 19 2012 - 18:46:48 EST


On Mon, 19 Mar 2012 23:41:36 +0100
richard -rw- weinberger <richard.weinberger@xxxxxxxxx> wrote:

> On Mon, Mar 19, 2012 at 11:39 PM, Cyrill Gorcunov <gorcunov@xxxxxxxxxx> wrote:
> > On Mon, Mar 19, 2012 at 03:15:07PM -0700, Andrew Morton wrote:
> > ...
> >> >
> >> > Also this action is one-shot only. For security reason
> >> > we don't allow to change the symlink several times.
> >>
> >> What is this mysterious "security reason"?
> >>
> >
> > Oh, sorry I should have included Matt's comment here

Please send a patch with the updated changelog and improved comment?

> >
> > Actually I liked multi-shot version more but Matt arguments convinced
> > me that one-short fashion is more "secure" in terms of overall kernel
> > state and potential transitions/changes of this /proc/pid/exe symlink.
> >
> > At least with one-shot version the admin may be sure that the symlink
> > is never changed more than once, ever.
> >
>
> And changing it once does not harm security?
> I'm sure that rootkit writers will like this feature...

Well, let's discuss this more completely. In what ways could an
attacker use this? How serious is the problem? What actions can be
taken to lessen it? etcetera.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/