Re: crypto loop bug

From: Alexander S A Kjeldaas (Alexander.Kjeldaas@fast.no)
Date: Mon Jul 31 2000 - 03:07:43 EST


On Fri, Jul 21, 2000 at 07:52:41PM +0200, Walter Hofmann wrote:
> I'm running 2.2.17pre12 with crypto patch 16.4.
>
> It seems that the decrypted data from a loop device is cached between
> destroys and new setups of loop devices. You cannot see this if you just
> mount the loop devices because mount seems unaffected, but fsck will
> show the error.
>
> Attached is an example session.
>
> This is a security problem because users can see decrypted data even
> after the loop device was destroyed (imagine a setuid application which
> allows users to mount their own encrypted file systems).
>

This looks like a bug in the loopback device. I hope someone can come
up with a fix for it - I don't know it well enough.

astor

-- 
Alexander Kjeldaas                Mail:  astor@fast.no
finger astor@master.kernel.org for OpenPGP key.

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Mon Jul 31 2000 - 21:00:32 EST