From patchwork Fri Jul 16 16:14:37 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Georgia Garcia X-Patchwork-Id: 1506250 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=none (no SPF record) smtp.mailfrom=lists.ubuntu.com (client-ip=91.189.94.19; helo=huckleberry.canonical.com; envelope-from=kernel-team-bounces@lists.ubuntu.com; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=canonical.com header.i=@canonical.com header.a=rsa-sha256 header.s=20210705 header.b=q85zrPNd; dkim-atps=neutral Received: from huckleberry.canonical.com (huckleberry.canonical.com [91.189.94.19]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4GRGXr1JPGz9sXM; Sat, 17 Jul 2021 02:14:51 +1000 (AEST) Received: from localhost ([127.0.0.1] helo=huckleberry.canonical.com) by huckleberry.canonical.com with esmtp (Exim 4.86_2) (envelope-from ) id 1m4QU8-0007qd-5n; Fri, 16 Jul 2021 16:14:44 +0000 Received: from smtp-relay-canonical-0.internal ([10.131.114.83] helo=smtp-relay-canonical-0.canonical.com) by huckleberry.canonical.com with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.86_2) (envelope-from ) id 1m4QU6-0007qW-IT for kernel-team@lists.ubuntu.com; Fri, 16 Jul 2021 16:14:42 +0000 Received: from mail-ej1-f70.google.com (mail-ej1-f70.google.com [209.85.218.70]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by smtp-relay-canonical-0.canonical.com (Postfix) with ESMTPS id 6DE48408AB for ; Fri, 16 Jul 2021 16:14:42 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=canonical.com; s=20210705; t=1626452082; bh=dYLA5wSMi8jl2LaoxkIPY5pzgKniQAKwdzWEyVqv0Rs=; h=From:To:Subject:Date:Message-Id:MIME-Version; b=q85zrPNdKH3bIp2bxDmuLp7yXujaUWXEkCUXA5mDiX4F/Tn9FtcUI682gDNd4VaNv kSanaxrUt2VyvIH02DqSIIfhs13bkP4W+fzNAhHHZh3lpbSKDZuo2s3UWY6uY9/Zqi yW7DIHxoSIYbpJTowanz4w5mmoiIfVNVSK23aeQ0wZ6gvMSl4u/guCulkrO4UChcq/ N9c8HnK5awEGj9te3yfJ9IcB9vgjH1d0ueaTYlW4QLlxNUuvv/88VSm7wWo6cNP6bx 50qNZ35sMXa3kJb8jND8tAKRVW2fEHfiA8pLXLeTaFKQDBCBsSxDB+sAvf048jlnEc iFoati5WogopA== Received: by mail-ej1-f70.google.com with SMTP id nc15-20020a1709071c0fb029052883e9de3eso3748337ejc.19 for ; Fri, 16 Jul 2021 09:14:42 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:subject:date:message-id:mime-version :content-transfer-encoding; bh=dYLA5wSMi8jl2LaoxkIPY5pzgKniQAKwdzWEyVqv0Rs=; b=jUnBcvlEuMQMxZ0sZxON0tIn2hrIuY56LnNWuYPkhmaH5lkpCuiv/oH1c48vLt89Hy v7XkWehgYpuB8Rjylpov4do09P/1Rdz2u2aTpOomyawg69nQBHdQ8+FLThiL8mfEMZx9 HOqKpYpO3bv8P7YeU9kODMFrCO1GJf4m1bN6WL6wjcBD4T3gemxBXX4qYTRVXovDrWmJ 4UvGaZYbSh9omD7VITDgZN9Ul0rKs+BYrwwTC7i7wAgqLCwGtXTFXCIaTmBrc+zp87Y1 Nv7mWfSAPGrouUTUrILTtZluXuaQ+dUxnRe8ZLyc9CpI8LoKFedN29PPYb7nfdRKEdkr wdmw== X-Gm-Message-State: AOAM533wNXpI++Pi6+B9mMndYgI0Kanc+7pTgX5/OuKoipWa+3eBO71Q 3pXRo2t+9i3jECRTe7DKSxE4cFP/C6BGkF7R9Ryhtz1pgST8zT22bmc/2OTbYzlBfOwJDiqoyGn SKR9pJ7chdvlLDwP4ZZLptAdnk4d1nbsUpR9gYsL98g== X-Received: by 2002:aa7:dbc3:: with SMTP id v3mr15968204edt.63.1626452081981; Fri, 16 Jul 2021 09:14:41 -0700 (PDT) X-Google-Smtp-Source: ABdhPJyN5LnrQZvGc0l65MBn8yJA7Ozlwb5WlcysUp9USTyIbT4ra5XXaEbzsJBmtJMXzyyybLf+Lg== X-Received: by 2002:aa7:dbc3:: with SMTP id v3mr15968183edt.63.1626452081783; Fri, 16 Jul 2021 09:14:41 -0700 (PDT) Received: from localhost ([2001:67c:1562:8007::aac:4557]) by smtp.gmail.com with ESMTPSA id dy8sm3945976edb.74.2021.07.16.09.14.40 for (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 16 Jul 2021 09:14:41 -0700 (PDT) From: Georgia Garcia To: kernel-team@lists.ubuntu.com Subject: [SRU][Bionic][PATCH 0/1] Fix ptrace read check (LP: 1890848) Date: Fri, 16 Jul 2021 13:14:37 -0300 Message-Id: <20210716161438.894779-1-georgia.garcia@canonical.com> X-Mailer: git-send-email 2.25.1 MIME-Version: 1.0 X-BeenThere: kernel-team@lists.ubuntu.com X-Mailman-Version: 2.1.20 Precedence: list List-Id: Kernel team discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: kernel-team-bounces@lists.ubuntu.com Sender: "kernel-team" BugLink: https://bugs.launchpad.net/bugs/1890848 SRU Justification: [Impact] Permission 'ptrace trace' is required to readlink() /proc/*/ns/*, when only 'ptrace read' should be required according to 'man namespaces': "Permission to dereference or read (readlink(2)) these symbolic links is governed by a ptrace access mode PTRACE_MODE_READ_FSCREDS check; see ptrace(2)." [Fix] Upstream commit 338d0be437ef10e247a35aed83dbab182cf406a2 fixes ptrace read check. [Test Plan] BugLink contains the source of a binary that reproduces the issue. In summary, it executes readlink() on /proc/*/ns/*. There's also a policy that has only 'ptrace read' permission. When the bug is fixed, execution is allowed. [Where problems could occur] The regression can be considered as low, since it's lowering the number of permissions required. Existing policies that already contain the permission 'ptrace trace' and 'ptrace read' will have a broader policy than required. John Johansen (1): apparmor: fix ptrace read check security/apparmor/lsm.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) Acked-by: Guilherme G. Piccoli Acked-by: Tim Gardner