Messages in this thread |  | | Date | Sun, 23 Sep 2012 07:30:38 +0100 | | From | Al Viro <> | | Subject | Re: [PATCH 3/4] devpts: Make the newinstance option historical |
| |
On Sat, Sep 22, 2012 at 10:59:04PM -0700, Eric W. Biederman wrote:
> The test: > >> + if (filp->f_vfsmnt->mnt_root == filp->f_dentry) > kicks in and no redirection is performed.
Umm... OK, after the first round of recursion. Unless you bind /something/pts on /something. Or simply create a symlink. Hell, if static /dev is on the same fs as /tmp, it can even be done by unpriveleged attacker - mkdir /tmp/pts ln /dev/ptmx /tmp ln -s /tmp/ptmx /tmp/pts/ptmx exec </tmp/ptmx and enjoy the stack overflow in kernel mode. It's not particulary common setup, of course, but I think it demonstrates that you are playing with fire...
|  |