From 81694f2b91bc4780006fb2ebe69c403cd850b85d Mon Sep 17 00:00:00 2001 From: Greg Kroah-Hartman Date: Wed, 10 Apr 2024 21:10:46 +0200 Subject: [PATCH] 5.10-stable patches added patches: tty-n_gsm-require-cap_net_admin-to-attach-n_gsm0710-ldisc.patch --- queue-5.10/series | 1 + ..._net_admin-to-attach-n_gsm0710-ldisc.patch | 34 +++++++++++++++++++ 2 files changed, 35 insertions(+) create mode 100644 queue-5.10/tty-n_gsm-require-cap_net_admin-to-attach-n_gsm0710-ldisc.patch diff --git a/queue-5.10/series b/queue-5.10/series index c734c6652a..b1f8851e76 100644 --- a/queue-5.10/series +++ b/queue-5.10/series @@ -282,3 +282,4 @@ fbmon-prevent-division-by-zero-in-fb_videomode_from_.patch netfilter-nf_tables-release-batch-on-table-validatio.patch netfilter-nf_tables-release-mutex-after-nft_gc_seq_e.patch netfilter-nf_tables-discard-table-flag-update-with-p.patch +tty-n_gsm-require-cap_net_admin-to-attach-n_gsm0710-ldisc.patch diff --git a/queue-5.10/tty-n_gsm-require-cap_net_admin-to-attach-n_gsm0710-ldisc.patch b/queue-5.10/tty-n_gsm-require-cap_net_admin-to-attach-n_gsm0710-ldisc.patch new file mode 100644 index 0000000000..fac7a3a4cf --- /dev/null +++ b/queue-5.10/tty-n_gsm-require-cap_net_admin-to-attach-n_gsm0710-ldisc.patch @@ -0,0 +1,34 @@ +From 67c37756898a5a6b2941a13ae7260c89b54e0d88 Mon Sep 17 00:00:00 2001 +From: Thadeu Lima de Souza Cascardo +Date: Mon, 31 Jul 2023 15:59:42 -0300 +Subject: tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc + +From: Thadeu Lima de Souza Cascardo + +commit 67c37756898a5a6b2941a13ae7260c89b54e0d88 upstream. + +Any unprivileged user can attach N_GSM0710 ldisc, but it requires +CAP_NET_ADMIN to create a GSM network anyway. + +Require initial namespace CAP_NET_ADMIN to do that. + +Signed-off-by: Thadeu Lima de Souza Cascardo +Link: https://lore.kernel.org/r/20230731185942.279611-1-cascardo@canonical.com +From: Salvatore Bonaccorso +Signed-off-by: Greg Kroah-Hartman +--- + drivers/tty/n_gsm.c | 3 +++ + 1 file changed, 3 insertions(+) + +--- a/drivers/tty/n_gsm.c ++++ b/drivers/tty/n_gsm.c +@@ -2661,6 +2661,9 @@ static int gsmld_open(struct tty_struct + { + struct gsm_mux *gsm; + ++ if (!capable(CAP_NET_ADMIN)) ++ return -EPERM; ++ + if (tty->ops->write == NULL) + return -EINVAL; + -- 2.39.2