Received: by 2002:a05:6a11:4021:0:0:0:0 with SMTP id ky33csp402997pxb; Wed, 22 Sep 2021 05:00:02 -0700 (PDT) X-Google-Smtp-Source: ABdhPJwsxR9Qb/YKLz0u8AjDu4+MopElCtrSZV/2fU/HC+prZNCLYwA8G8z1cvv3XbpbeMrTl3F6 X-Received: by 2002:a05:6e02:ecd:: with SMTP id i13mr25123644ilk.143.1632312002111; Wed, 22 Sep 2021 05:00:02 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1632312002; cv=none; d=google.com; s=arc-20160816; b=OkK6iGLqGkUhJp50gAUY0TELjTztysyIK6Od+3S+oRFTSZGBZQjvoL8m4aArMJp099 DMPCpw+L3WnpmO6uzWlkp1v464DQE5KatXmLDIDabJuQJw1BzgCd6H5yA7lJAF0oQVKw bYjCPKbYjL6bPA04G5aI4lwy7dU3WkljRsSXfJBuAU6j4xmESWLUK/FUPRQdPwcxUWfo SGz8oT+hW8whtBNZX7UZp/KEpfvklHjlZuz1pXylMb6alti7afbJdX9HdiVbM4MYfjxo 5bphCa+tK34Y3Q/TE/YCp9xbO/HpF7XyHadSovOTBktZlixFJrJgdRB/vHji635b8VVL Eodw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:from:dkim-signature; bh=oQNtx4Pz+fTUuURfnHGtu9bs1jMnEIeoOCyz8TjXMNk=; b=MpUQbIuPZ8QvsjN6vxFLubg6Nn3r/oZ9cFdBNKjcSVdMQH0oriyzxJEyhjP426b3ec C5yUJzLvid8fyBh8RpvLqPtJiSWkPyHLeF/k9ZWw2gXlxFVmhbWBvknVvhZ4Nkn9kEiw 7AkmRdAeCaSY0/oNcek7yLhuAXWM4Zj9vk9Kq6X5JS9a4+Ou9zQxM5SO8j9ssbzHywaJ n2jZ7rm1Wav7ydpRfOplwwS3AMfijY7GXLiRO1ts/L0VTjziLbxxXlwg0CrZAAwiTpO5 EAkA/YwCEXv3Lj8euSvPs8x3BEEn63Z+rRtizGW+thCL6cV2Ev2WI5yXt6Kvu634Ios5 4rng== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@canonical.com header.s=20210705 header.b="a8vg/pQa"; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=canonical.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id q7si2562168ilu.111.2021.09.22.04.59.31; Wed, 22 Sep 2021 05:00:02 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@canonical.com header.s=20210705 header.b="a8vg/pQa"; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=canonical.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S235869AbhIVL7a (ORCPT + 99 others); Wed, 22 Sep 2021 07:59:30 -0400 Received: from smtp-relay-canonical-1.canonical.com ([185.125.188.121]:50374 "EHLO smtp-relay-canonical-1.canonical.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S235860AbhIVL73 (ORCPT ); Wed, 22 Sep 2021 07:59:29 -0400 Received: from localhost.localdomain (1.general.cascardo.us.vpn [10.172.70.58]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by smtp-relay-canonical-1.canonical.com (Postfix) with ESMTPSA id 050AC412AC; Wed, 22 Sep 2021 11:57:56 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=canonical.com; s=20210705; t=1632311878; bh=oQNtx4Pz+fTUuURfnHGtu9bs1jMnEIeoOCyz8TjXMNk=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=a8vg/pQaavufWoMpUCKs29M/DOwjnv/Jn9LzTfUFp1xpswMA3SOV51RrkiJOZbdRD HXZs9hpxHBVvijUUdRd5SPPTUW/waGByRSaUFNKvN423VKHqkElcApWsj9qDzpAZNj /4F2iemRuFU/NNpE5SILqVWfBC2Tmn1UKqFo0+eSE3FwTBYVjWXrFZwBK3Eu0AA98C DpTuX8kzjzqRbIO9B7lx+W644+Kj7VmNxNb2GtaOWh9thk05Vq5KCBeamA3/qnjULQ STSrTpUi5i71Ab2/jKRQ1c6vEK5p20kiy5d9K4HQe0JyOhQPzzchpaHvmVkt8mJQav OvGRyUFC6cDuQ== From: Thadeu Lima de Souza Cascardo To: linux-bluetooth@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Marcel Holtmann , Johan Hedberg , Luiz Augusto von Dentz , Thadeu Lima de Souza Cascardo Subject: [PATCH] Bluetooth: hci_ldisc: require CAP_NET_ADMIN to attach N_HCI ldisc Date: Wed, 22 Sep 2021 08:56:56 -0300 Message-Id: <20210922115656.97723-1-cascardo@canonical.com> X-Mailer: git-send-email 2.30.2 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Precedence: bulk List-ID: X-Mailing-List: linux-bluetooth@vger.kernel.org Any unprivileged user can attach N_HCI ldisc and send packets coming from a virtual controller by using PTYs. Require initial namespace CAP_NET_ADMIN to do that. Signed-off-by: Thadeu Lima de Souza Cascardo --- drivers/bluetooth/hci_ldisc.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/bluetooth/hci_ldisc.c b/drivers/bluetooth/hci_ldisc.c index 5ed2cfa7da1d..5e32e4d5367a 100644 --- a/drivers/bluetooth/hci_ldisc.c +++ b/drivers/bluetooth/hci_ldisc.c @@ -479,6 +479,9 @@ static int hci_uart_tty_open(struct tty_struct *tty) BT_DBG("tty %p", tty); + if (!capable(CAP_NET_ADMIN)) + return -EPERM; + /* Error if the tty has no write op instead of leaving an exploitable * hole */ -- 2.30.2