Blame SOURCES/0441-basic-fix-touch-creating-files-with-07777-mode.patch
|
|
803fb7 |
From 616db6ddcacd25e4c3a771cd317373971c9055ed Mon Sep 17 00:00:00 2001
|
|
|
803fb7 |
From: =?UTF-8?q?Mantas=20Mikul=C4=97nas?= <grawity@gmail.com>
|
|
|
803fb7 |
Date: Fri, 29 Jan 2016 23:36:08 +0200
|
|
|
803fb7 |
Subject: [PATCH] basic: fix touch() creating files with 07777 mode
|
|
|
803fb7 |
|
|
|
803fb7 |
mode_t is unsigned, so MODE_INVALID < 0 can never be true.
|
|
|
803fb7 |
|
|
|
803fb7 |
This fixes a possible DoS where any user could fill /run by writing to
|
|
|
803fb7 |
a world-writable /run/systemd/show-status.
|
|
|
803fb7 |
|
|
|
803fb7 |
Cherry-picked from: 06eeacb6fe029804f296b065b3ce91e796e1cd0e
|
|
|
803fb7 |
Resolves: #1416062
|
|
|
803fb7 |
---
|
|
|
803fb7 |
src/shared/util.c | 3 ++-
|
|
|
803fb7 |
1 file changed, 2 insertions(+), 1 deletion(-)
|
|
|
803fb7 |
|
|
|
803fb7 |
diff --git a/src/shared/util.c b/src/shared/util.c
|
|
|
803fb7 |
index 66729f70e..1070e32c4 100644
|
|
|
803fb7 |
--- a/src/shared/util.c
|
|
|
803fb7 |
+++ b/src/shared/util.c
|
|
|
803fb7 |
@@ -3908,7 +3908,8 @@ int touch_file(const char *path, bool parents, usec_t stamp, uid_t uid, gid_t gi
|
|
|
803fb7 |
if (parents)
|
|
|
803fb7 |
mkdir_parents(path, 0755);
|
|
|
803fb7 |
|
|
|
803fb7 |
- fd = open(path, O_WRONLY|O_CREAT|O_CLOEXEC|O_NOCTTY, mode > 0 ? mode : 0644);
|
|
|
803fb7 |
+ fd = open(path, O_WRONLY|O_CREAT|O_CLOEXEC|O_NOCTTY,
|
|
|
803fb7 |
+ (mode == 0 || mode == MODE_INVALID) ? 0644 : mode);
|
|
|
803fb7 |
if (fd < 0)
|
|
|
803fb7 |
return -errno;
|
|
|
803fb7 |
|