]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
5.10-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 10 Apr 2024 19:10:46 +0000 (21:10 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 10 Apr 2024 19:10:46 +0000 (21:10 +0200)
added patches:
tty-n_gsm-require-cap_net_admin-to-attach-n_gsm0710-ldisc.patch

queue-5.10/series
queue-5.10/tty-n_gsm-require-cap_net_admin-to-attach-n_gsm0710-ldisc.patch [new file with mode: 0644]

index c734c6652ab1ad534c81e92266587a08a30ff411..b1f8851e760884f64a1f3110fbcaa2e549c74c3b 100644 (file)
@@ -282,3 +282,4 @@ fbmon-prevent-division-by-zero-in-fb_videomode_from_.patch
 netfilter-nf_tables-release-batch-on-table-validatio.patch
 netfilter-nf_tables-release-mutex-after-nft_gc_seq_e.patch
 netfilter-nf_tables-discard-table-flag-update-with-p.patch
+tty-n_gsm-require-cap_net_admin-to-attach-n_gsm0710-ldisc.patch
diff --git a/queue-5.10/tty-n_gsm-require-cap_net_admin-to-attach-n_gsm0710-ldisc.patch b/queue-5.10/tty-n_gsm-require-cap_net_admin-to-attach-n_gsm0710-ldisc.patch
new file mode 100644 (file)
index 0000000..fac7a3a
--- /dev/null
@@ -0,0 +1,34 @@
+From 67c37756898a5a6b2941a13ae7260c89b54e0d88 Mon Sep 17 00:00:00 2001
+From: Thadeu Lima de Souza Cascardo <cascardo@canonical.com>
+Date: Mon, 31 Jul 2023 15:59:42 -0300
+Subject: tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc
+
+From: Thadeu Lima de Souza Cascardo <cascardo@canonical.com>
+
+commit 67c37756898a5a6b2941a13ae7260c89b54e0d88 upstream.
+
+Any unprivileged user can attach N_GSM0710 ldisc, but it requires
+CAP_NET_ADMIN to create a GSM network anyway.
+
+Require initial namespace CAP_NET_ADMIN to do that.
+
+Signed-off-by: Thadeu Lima de Souza Cascardo <cascardo@canonical.com>
+Link: https://lore.kernel.org/r/20230731185942.279611-1-cascardo@canonical.com
+From: Salvatore Bonaccorso <carnil@debian.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/tty/n_gsm.c |    3 +++
+ 1 file changed, 3 insertions(+)
+
+--- a/drivers/tty/n_gsm.c
++++ b/drivers/tty/n_gsm.c
+@@ -2661,6 +2661,9 @@ static int gsmld_open(struct tty_struct
+ {
+       struct gsm_mux *gsm;
++      if (!capable(CAP_NET_ADMIN))
++              return -EPERM;
++
+       if (tty->ops->write == NULL)
+               return -EINVAL;