Nixpkgs security tracker

Try the new UI
Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 1 week, 5 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]

In the Linux kernel, the following vulnerability has been resolved: sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] cad_pid is global, and kill_cad_pid() is only used in the root namespace. However, due to pid_table_root_permissions(), a non-root user can unshare pid/user namespaces and modify it from the child namespace. This makes no sense and is simply wrong. Move it to kern_reboot_table[] where it logically belongs; this ensures that only GLOBAL_ROOT_UID can read/modify this sysctl. Note that this patch doesn't preserve "#ifdef CONFIG_PROC_SYSCTL" around the "cad_pid"; CONFIG_PROC_SYSCTL selects CONFIG_SYSCTL, so it is always set when kern_reboot_table[] is compiled.

Affected products

Linux
  • <e8527de7fea191fda704792a56081f9009aeec37
  • =<*
  • =<7.2.*
  • <7170ca01623b399c97f2ae9d3e228badc1f25ea3
  • <6.17
  • =<6.18.*
  • ==6.17
  • <a09bc4eaa67e1a72df3b6d0beb3afeef1e1fdfcd