From: Thadeu Lima de Souza Cascardo Date: Wed, 22 Sep 2021 11:56:56 +0000 (-0300) Subject: Bluetooth: hci_ldisc: require CAP_NET_ADMIN to attach N_HCI ldisc X-Git-Tag: v5.16-rc1~159^2~279^2~21 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=c05731d0c6bd9a625e27ea5c5157ebf1303229e0;p=thirdparty%2Flinux.git Bluetooth: hci_ldisc: require CAP_NET_ADMIN to attach N_HCI ldisc Any unprivileged user can attach N_HCI ldisc and send packets coming from a virtual controller by using PTYs. Require initial namespace CAP_NET_ADMIN to do that. Signed-off-by: Thadeu Lima de Souza Cascardo Signed-off-by: Marcel Holtmann --- diff --git a/drivers/bluetooth/hci_ldisc.c b/drivers/bluetooth/hci_ldisc.c index 5ed2cfa7da1d9..5e32e4d5367af 100644 --- a/drivers/bluetooth/hci_ldisc.c +++ b/drivers/bluetooth/hci_ldisc.c @@ -479,6 +479,9 @@ static int hci_uart_tty_open(struct tty_struct *tty) BT_DBG("tty %p", tty); + if (!capable(CAP_NET_ADMIN)) + return -EPERM; + /* Error if the tty has no write op instead of leaving an exploitable * hole */