Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

snap: reject layouts to /lib/{firmware,modules} #6649

Merged
merged 1 commit into from
Mar 26, 2019

Conversation

zyga
Copy link
Collaborator

@zyga zyga commented Mar 26, 2019

Using a layout on /lib/firmware might allow an application to trick the
kernel into loading a firmware blob modified by the attacker. Similar
operation may happen in /lib/modules where the kernel may load a module
on demand.

Signed-off-by: Zygmunt Krynicki me@zygoon.pl

Using a layout on /lib/firmware might allow an application to trick the
kernel into loading a firmware blob modified by the attacker. Similar
operation may happen in /lib/modules where the kernel may load a module
on demand.

Signed-off-by: Zygmunt Krynicki <me@zygoon.pl>
Copy link
Contributor

@mvo5 mvo5 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for this one

@zyga zyga added this to In progress in SUSE Security Audit via automation Mar 26, 2019
Copy link
Collaborator

@bboozzoo bboozzoo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great catch!

@pedronis pedronis self-requested a review March 26, 2019 10:41
Copy link
Collaborator

@pedronis pedronis left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you

@mvo5 mvo5 merged commit cf7b22a into snapcore:master Mar 26, 2019
SUSE Security Audit automation moved this from In progress to Done Mar 26, 2019
@zyga zyga deleted the fix/layout-blacklist branch March 26, 2019 15:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
4 participants