HomeFreeBSD

Imagine situation where a security problem is found in setuid binary.

Description

Imagine situation where a security problem is found in setuid binary.
User upgrades his system to fix the problem, but if he has any ZFS snapshots
for the file system which contains problematic binary, any user can mount the
snapshot and execute vulnerable binary.

Prevent this from happening by always mounting snapshots with setuid turned off.

MFC after: 2 weeks

Details

Provenance
pjdAuthored on May 31 2011, 7:02 AM
Parents
rG7c017a713e2f: Correctly check MAC running status before disabling TX/RX MACs.
Branches
Unknown
Tags
Unknown

Event Timeline