mirror of
https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-9.git
synced 2026-09-09 00:08:12 +08:00
tools/power/x86/intel-speed-select: Harden daemon pidfile open
JIRA: https://issues.redhat.com/browse/RHEL-192479 commit 607af438e6430893a822964c841a1994b33acccc Author: Ali Ahmet MEMIS <dev@unknownbbqr.xyz> Date: Sun Apr 26 08:09:28 2026 -0700 tools/power/x86/intel-speed-select: Harden daemon pidfile open Avoid symlink-based pidfile clobbering by opening the pidfile with O_NOFOLLOW and validating it with fstat() before locking/writing. The daemon currently uses a fixed pidfile path under /tmp. A local unprivileged user can pre-create a symlink at that path and cause a root-run daemon instance to write into an attacker-chosen file. Fixes: 7fd786dfbd2c ("tools/power/x86/intel-speed-select: OOB daemon mode") Signed-off-by: Ali Ahmet MEMIS <dev@unknownbbqr.xyz> Signed-off-by: Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com> Cc: stable@kernel.org (cherry picked from commit 607af438e6430893a822964c841a1994b33acccc) Assisted-by: Patchpal Signed-off-by: David Arcari <darcari@redhat.com>
This commit is contained in:
@@ -148,6 +148,7 @@ static void daemonize(char *rundir, char *pidfile)
|
||||
{
|
||||
int pid, sid, i;
|
||||
char str[10];
|
||||
struct stat st;
|
||||
struct sigaction sig_actions;
|
||||
sigset_t sig_set;
|
||||
int ret;
|
||||
@@ -200,11 +201,17 @@ static void daemonize(char *rundir, char *pidfile)
|
||||
if (ret == -1)
|
||||
exit(EXIT_FAILURE);
|
||||
|
||||
pid_file_handle = open(pidfile, O_RDWR | O_CREAT, 0600);
|
||||
pid_file_handle = open(pidfile, O_RDWR | O_CREAT | O_NOFOLLOW, 0600);
|
||||
if (pid_file_handle == -1) {
|
||||
/* Couldn't open lock file */
|
||||
exit(1);
|
||||
}
|
||||
|
||||
if (fstat(pid_file_handle, &st) == -1)
|
||||
exit(1);
|
||||
|
||||
if (!S_ISREG(st.st_mode))
|
||||
exit(1);
|
||||
/* Try to lock file */
|
||||
#ifdef LOCKF_SUPPORT
|
||||
if (lockf(pid_file_handle, F_TLOCK, 0) == -1) {
|
||||
|
||||
Reference in New Issue
Block a user