Re: [PATCH 3/4] devpts: Make the newinstance option historical

From: Al Viro
Date: Sun Sep 23 2012 - 02:31:41 EST


On Sat, Sep 22, 2012 at 10:59:04PM -0700, Eric W. Biederman wrote:

> The test:
> >> + if (filp->f_vfsmnt->mnt_root == filp->f_dentry)
> kicks in and no redirection is performed.

Umm... OK, after the first round of recursion. Unless you bind /something/pts
on /something. Or simply create a symlink. Hell, if static /dev is on the
same fs as /tmp, it can even be done by unpriveleged attacker -
mkdir /tmp/pts
ln /dev/ptmx /tmp
ln -s /tmp/ptmx /tmp/pts/ptmx
exec </tmp/ptmx
and enjoy the stack overflow in kernel mode. It's not particulary common
setup, of course, but I think it demonstrates that you are playing with
fire...
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/