Re: taskstats root only breaking iotop

From: Vasiliy Kulikov
Date: Sun Oct 02 2011 - 06:56:16 EST


(cc'ed kernel-hardening)

On Sun, Oct 02, 2011 at 12:22 +0200, Guillaume Chazarain wrote:
> On Sun, Oct 2, 2011 at 2:20 AM, Linus Torvalds
> <torvalds@xxxxxxxxxxxxxxxxxxxx> wrote:
> > So I don't see why you ask for it. What could possibly be a valid use-case?
>
> Right, kbyte granularity is enough.

It is not enough. In some border cases an attacker may still learn
private information given the counters with _arbitrary_ granularity:

http://www.openwall.com/lists/oss-security/2011/06/29/9


> And that's consistent with
> /proc/vmstat, which nobody is complaining about.

<jumping with a raised hand>Me, me, it was me!</jumping with a raised hand>

Seriously, most of procfs files were created with relaxed permissions in
old days when nobody thought about such infoleaks. Now it is much
harder to close all of them without breaking existing users.

http://www.openwall.com/lists/kernel-hardening/2011/07/28/1
http://www.openwall.com/lists/kernel-hardening/2011/09/27/3
http://www.openwall.com/lists/kernel-hardening/2011/09/19/24
http://www.openwall.com/lists/kernel-hardening/2011/09/21/2


Thanks,

--
Vasiliy Kulikov
http://www.openwall.com - bringing security into open computing environments
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/