Skip to content
  • Eric Paris's avatar
    [PATCH] arch filter lists with < or > should not be accepted · 4b8a311b
    Eric Paris authored
    
    
    Currently the kernel audit system represents arch's as numbers and will
    gladly accept comparisons between archs using >, <, >=, <= when the only
    thing that makes sense is = or !=.  I'm told that the next revision of
    auditctl will do this checking but this will provide enforcement in the
    kernel even for old userspace.  A simple command to show the issue would
    be to run
    
    auditctl -d entry,always -F arch>i686 -S chmod
    
    with this patch the kernel will reject this with -EINVAL
    
    Please comment/ack/nak as soon as possible.
    
    -Eric
    
     kernel/auditfilter.c |    9 ++++++++-
     1 file changed, 8 insertions(+), 1 deletion(-)
    
    Signed-off-by: default avatarAl Viro <viro@zeniv.linux.org.uk>
    4b8a311b