Re: Hardening debugfs (Was Re: [PATCH] debugfs: more tightlyrestrict default mount mode)

From: Theodore Ts'o
Date: Tue Aug 28 2012 - 11:02:51 EST


On Tue, Aug 28, 2012 at 07:55:58AM -0700, Ben Hutchings wrote:
>
> The problems are apparently larger than specific modules:
> http://lists.linux-foundation.org/pipermail/ksummit-2012-discuss/2012-July/000894.html
>

Sure, but most of those problems require root access, or physical
access to the hardware. And a number of the "can oops the kernel"
assume module disappears out from under the open file descriptor, so
(a) that's a problem that can be fixed, and (b) if we can suppress a
random device driver from having its debugfs directory appear by
default, it certainly helps things.

- Ted
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/