Red Hat Bugzilla – Bug 665169
kexec: limit root to call kexec_load()
Last modified: 2011-05-23 16:32:44 EDT
sys_kexec_load currently checks CAP_SYS_BOOT. CAP_SYS_BOOT is also used to protect sys_boot. But these operations are not exactly the same. sys_boot is going to go back through the boot loader. kexec_load actually allows you to run any code you want in ring0. This is more like CAP_SYS_MODULE. This patch requires having both to use sys_kexec_load()
Triage assignment. If you feel this bug doesn't belong to you, or that it cannot be handled in a timely fashion, please contact me for re-assignment
Patch(es) available on kernel-2.6.32-117.el6
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on therefore solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2011-0542.html