From: Seth Forshee Date: Tue, 26 Apr 2016 19:36:24 +0000 (-0500) Subject: cred: Reject inodes with invalid ids in set_create_file_as() X-Git-Tag: v4.7.4~54 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=f949290512332cb4519d1a8ee34a461121043307;p=thirdparty%2Fkernel%2Fstable.git cred: Reject inodes with invalid ids in set_create_file_as() commit 5f65e5ca286126a60f62c8421b77c2018a482b8a upstream. Using INVALID_[UG]ID for the LSM file creation context doesn't make sense, so return an error if the inode passed to set_create_file_as() has an invalid id. Signed-off-by: Seth Forshee Acked-by: Serge Hallyn Signed-off-by: Eric W. Biederman Signed-off-by: Greg Kroah-Hartman --- diff --git a/kernel/cred.c b/kernel/cred.c index 0c0cd8a622852..5f264fb5737dc 100644 --- a/kernel/cred.c +++ b/kernel/cred.c @@ -689,6 +689,8 @@ EXPORT_SYMBOL(set_security_override_from_ctx); */ int set_create_files_as(struct cred *new, struct inode *inode) { + if (!uid_valid(inode->i_uid) || !gid_valid(inode->i_gid)) + return -EINVAL; new->fsuid = inode->i_uid; new->fsgid = inode->i_gid; return security_kernel_create_files_as(new, inode);