Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S932589AbVI3T11 (ORCPT ); Fri, 30 Sep 2005 15:27:27 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S932591AbVI3T11 (ORCPT ); Fri, 30 Sep 2005 15:27:27 -0400 Received: from smtp.osdl.org ([65.172.181.4]:19078 "EHLO smtp.osdl.org") by vger.kernel.org with ESMTP id S932592AbVI3T10 (ORCPT ); Fri, 30 Sep 2005 15:27:26 -0400 Date: Fri, 30 Sep 2005 12:27:04 -0700 (PDT) From: Linus Torvalds To: Chris Wright cc: Harald Welte , Sergey Vlasov , linux-usb-devel@lists.sourceforge.net, linux-kernel@vger.kernel.org, security@linux.kernel.org, vendor-sec@lst.de Subject: Re: [linux-usb-devel] Re: [Security] [vendor-sec] [BUG/PATCH/RFC] Oops while completing async USB via usbdevio In-Reply-To: <20050930184433.GF16352@shell0.pdx.osdl.net> Message-ID: References: <20050925151330.GL731@sunbeam.de.gnumonks.org> <20050927160029.GA20466@master.mivlgu.local> <20050927165206.GB20466@master.mivlgu.local> <20050930104749.GN4168@sunbeam.de.gnumonks.org> <20050930184433.GF16352@shell0.pdx.osdl.net> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 707 Lines: 19 On Fri, 30 Sep 2005, Chris Wright wrote: > > Sorry, I missed the thread up to this, but this looks fundamentally > broken. The kill_proc_info_as_uid() idea is not sufficient because more > than uid/euid are needed for permission check. There's capabilities and > security labels. Not for this particular USB use, there isn't. Since you can only send a signal to yourself anyway, the uid/euid check is just testing that you're still who you were. Linus - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/