Bug 653250
Summary: | kernel: restrict unprivileged access to kernel syslog [rhel-5.6] | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 5 | Reporter: | Eugene Teo (Security Response) <eteo> |
Component: | kernel | Assignee: | Frantisek Hrbata <fhrbata> |
Status: | CLOSED ERRATA | QA Contact: | Mike Gahagan <mgahagan> |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | 5.6 | CC: | cww, dhoward, jarod, jpirko, lwang, plyons |
Target Milestone: | rc | Keywords: | ZStream |
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | 653245 | Environment: | |
Last Closed: | 2011-01-13 22:00:55 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 653245, 653252, 653254 | ||
Bug Blocks: | 658886 |
Description
Eugene Teo (Security Response)
2010-11-15 04:19:42 UTC
This request was evaluated by Red Hat Product Management for inclusion in a Red Hat Enterprise Linux maintenance release. Product Management has requested further review of this request by Red Hat Engineering, for potential inclusion in a Red Hat Enterprise Linux Update release for currently deployed products. This request is not yet committed for inclusion in an Update release. in kernel-2.6.18-236.el5 You can download this test kernel (or newer) from http://people.redhat.com/jwilson/el5 Detailed testing feedback is always welcomed. confirmed setting dmesg_restrict to 1 will block dmesg log viewing as a user while still allowing root to run dmesg. [m@localhost ~]$ dmesg klogctl: Operation not permitted [m@localhost ~]$ cat /proc/sys/kernel/dmesg_restrict 1 [m@localhost ~]$ [m@localhost ~]$ cat /proc/sys/kernel/dmesg_restrict 0 [m@localhost ~]$ dmesg | head -n 2 Linux version 2.6.18-236.el5 (mockbuild.bos.redhat.com) (gcc version 4.1.2 20080704 (Red Hat 4.1.2-48)) #1 SMP Mon Dec 6 18:41:54 EST 2010 Command line: ro root=/dev/VolGroup00/LogVol00 rhgb quiet An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on therefore solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2011-0017.html |