netdev
[Top] [All Lists]

Re: [Coverity] Untrusted user data in kernel

To: Pavel Machek <pavel@xxxxxx>
Subject: Re: [Coverity] Untrusted user data in kernel
From: James Morris <jmorris@xxxxxxxxxx>
Date: Fri, 17 Dec 2004 10:38:46 -0500 (EST)
Cc: Bryan Fulton <bryan@xxxxxxxxxxxx>, <linux-kernel@xxxxxxxxxxxxxxx>, <netdev@xxxxxxxxxxx>, <netfilter-devel@xxxxxxxxxxxxxxxxxxx>
In-reply-to: <20041217151031.GA27170@xxxxxxxxxxxxxxxxxxxxxxxx>
Sender: netdev-bounce@xxxxxxxxxxx
On Fri, 17 Dec 2004, Pavel Machek wrote:

> Hi!
> 
> > This at least needs CAP_NET_ADMIN.
> 
> Hmm, but that means that CAP_NET_ADMIN implies all other capabilities,
> unless you fix this.

I'm not saying it doesn't need to be fixed, but that it is not exploitable 
by unprivileged users.


- James
-- 
James Morris
<jmorris@xxxxxxxxxx>



<Prev in Thread] Current Thread [Next in Thread>