[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Qemu-devel] [PULL 6/6] 9pfs: fix vulnerability in openat_dir() and loca
From: |
Greg Kurz |
Subject: |
[Qemu-devel] [PULL 6/6] 9pfs: fix vulnerability in openat_dir() and local_unlinkat_common() |
Date: |
Mon, 6 Mar 2017 18:54:10 +0100 |
We should pass O_NOFOLLOW otherwise openat() will follow symlinks and make
QEMU vulnerable.
While here, we also fix local_unlinkat_common() to use openat_dir() for
the same reasons (it was a leftover in the original patchset actually).
This fixes CVE-2016-9602.
Signed-off-by: Greg Kurz <address@hidden>
Reviewed-by: Daniel P. Berrange <address@hidden>
Reviewed-by: Eric Blake <address@hidden>
---
hw/9pfs/9p-local.c | 2 +-
hw/9pfs/9p-util.h | 3 ++-
2 files changed, 3 insertions(+), 2 deletions(-)
diff --git a/hw/9pfs/9p-local.c b/hw/9pfs/9p-local.c
index 0ca4c94ee4a8..45e9a1f9b0ca 100644
--- a/hw/9pfs/9p-local.c
+++ b/hw/9pfs/9p-local.c
@@ -960,7 +960,7 @@ static int local_unlinkat_common(FsContext *ctx, int dirfd,
const char *name,
if (flags == AT_REMOVEDIR) {
int fd;
- fd = openat(dirfd, name, O_RDONLY | O_DIRECTORY | O_PATH);
+ fd = openat_dir(dirfd, name);
if (fd == -1) {
goto err_out;
}
diff --git a/hw/9pfs/9p-util.h b/hw/9pfs/9p-util.h
index cb7b2072d3ac..517027c52032 100644
--- a/hw/9pfs/9p-util.h
+++ b/hw/9pfs/9p-util.h
@@ -27,7 +27,8 @@ static inline int openat_dir(int dirfd, const char *name)
#else
#define OPENAT_DIR_O_PATH 0
#endif
- return openat(dirfd, name, O_DIRECTORY | O_RDONLY | OPENAT_DIR_O_PATH);
+ return openat(dirfd, name,
+ O_DIRECTORY | O_RDONLY | O_NOFOLLOW | OPENAT_DIR_O_PATH);
}
static inline int openat_file(int dirfd, const char *name, int flags,
--
2.7.4
- [Qemu-devel] [PULL 0/6] 9pfs fixes for 2.9 2017-03-06, Greg Kurz, 2017/03/06
- [Qemu-devel] [PULL 1/6] 9pfs: fix bogus fd check in local_remove(), Greg Kurz, 2017/03/06
- [Qemu-devel] [PULL 2/6] 9pfs: fix fd leak in local_opendir(), Greg Kurz, 2017/03/06
- [Qemu-devel] [PULL 3/6] 9pfs: fail local_statfs() earlier, Greg Kurz, 2017/03/06
- [Qemu-devel] [PULL 5/6] 9pfs: fix O_PATH build break with older glibc versions, Greg Kurz, 2017/03/06
- [Qemu-devel] [PULL 4/6] 9pfs: don't use AT_EMPTY_PATH in local_set_cred_passthrough(), Greg Kurz, 2017/03/06
- [Qemu-devel] [PULL 6/6] 9pfs: fix vulnerability in openat_dir() and local_unlinkat_common(),
Greg Kurz <=
- Re: [Qemu-devel] [PULL 0/6] 9pfs fixes for 2.9 2017-03-06, Mark Cave-Ayland, 2017/03/06
- Re: [Qemu-devel] [PULL 0/6] 9pfs fixes for 2.9 2017-03-06, Peter Maydell, 2017/03/07