Bug 128124 - procfs chmod as any user
procfs chmod as any user
Product: Fedora
Classification: Fedora
Component: kernel (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Dave Jones
Brian Brock
: Security
Depends On:
  Show dependency treegraph
Reported: 2004-07-18 16:33 EDT by Chuck Berg
Modified: 2015-01-04 17:08 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2004-11-26 23:42:36 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Chuck Berg 2004-07-18 16:33:17 EDT
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7) Gecko/20040616

Description of problem:
Over two weeks ago, a serious locally exploitable security hole was
found in the kernel. See here: http://lkml.org/lkml/2004/7/3/61

A normal user can chmod most files in /proc.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
charm:~$ uname -r
charm:~$ id -u
charm:~$ chmod a+w /proc/sysrq-trigger
charm:~$ ls -l /proc/sysrq-trigger
--w--w--w-  1 root root 0 Jul 18 16:26 /proc/sysrq-trigger
charm:~$ echo / > /proc/sysrq-trigger
charm:~$ dmesg | tail -1
SysRq : HELP : loglevel0-8 reBoot tErm kIll saK showMem powerOff
showPc unRaw Sync showTasks Unmount

Actual Results:  chmod succeeds

Expected Results:  chmod fails

Additional info:
Comment 1 Dave Jones 2004-10-25 19:26:02 EDT
this got fixed in mainline, did it make it into the 521 update for FC2 ?
I'll be doing a 2.6.9 based FC2 update soon.

Note You need to log in before you can comment on or make changes to this bug.