Security Hole?

Andrew Mileski (dmtech@magi.com)
Sun, 3 Mar 1996 16:03:43 -0500 (EST)


Wanted to get some EXPERT opinion on this...

I've noticed that the linux kernel allows anyone to freely
request/release IRQ, DMA, and I/O. Is this a security
hole, or am I missing something that only allows root to
do these things?

I was considering giving each resource region a uid, with
only root or the owner being allowed to change that region.
Originally I was going to use the devname, but this is not
secure enough, and things like the serial drivers might
not like that.

Is it necessary to add anything for security? Or should
the status quo be maintained?

-- Andrew E. Mileski --

-------------------------------------------------------
Located in Canada's Capital: Ottawa! (EST)
mailto:dmtech@magi.com http://www.magi.com/~dmtech/