Bug 505492 - kernel: agp: remove uid comparison as security check
Summary: kernel: agp: remove uid comparison as security check
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 505493 505494 505495 505496 505497 505498
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-06-12 05:23 UTC by Eugene Teo (Security Response)
Modified: 2016-06-10 22:31 UTC (History)
9 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2016-06-10 22:31:12 UTC
Embargoed:


Attachments (Terms of Use)
Upstream patch (1.03 KB, patch)
2009-06-12 05:25 UTC, Eugene Teo (Security Response)
no flags Details | Diff

Description Eugene Teo (Security Response) 2009-06-12 05:23:53 UTC
Description of problem:
In the face of containers and user namespaces, a uid==0 check for security is not safe. Switch to a capability check.

Upstream commit:
http://git.kernel.org/linus/62f29babbc60ab572d3cecda981931d3a66123d6

Comment 1 Eugene Teo (Security Response) 2009-06-12 05:25:02 UTC
Created attachment 347509 [details]
Upstream patch


Note You need to log in before you can comment on or make changes to this bug.