Would this look like possible fix:
-allow if (current->uid == child->euid)...
+allow if (current->uid == child->euid &&
cap_issubset(child->cap_permitted, current->cap_permitted)...
-Topi
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/