summary refs log tree commit diff stats
path: root/util/qemu-timer.c
diff options
context:
space:
mode:
authorMiklos Szeredi <mszeredi@redhat.com>2020-04-29 14:47:33 +0200
committerDr. David Alan Gilbert <dgilbert@redhat.com>2020-05-01 18:46:54 +0100
commit397ae982f4df46e7d4b2625c431062c9146f3b83 (patch)
tree7b22232304db1e20f9f9c47b5636e9590331f39d /util/qemu-timer.c
parent8c1d353d107b4fc344e27f2f08ea7fa25de2eea2 (diff)
downloadfocaccia-qemu-397ae982f4df46e7d4b2625c431062c9146f3b83.tar.gz
focaccia-qemu-397ae982f4df46e7d4b2625c431062c9146f3b83.zip
virtiofsd: jail lo->proc_self_fd
While it's not possible to escape the proc filesystem through
lo->proc_self_fd, it is possible to escape to the root of the proc
filesystem itself through "../..".

Use a temporary mount for opening lo->proc_self_fd, that has it's root at
/proc/self/fd/, preventing access to the ancestor directories.

Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Message-Id: <20200429124733.22488-1-mszeredi@redhat.com>
Reviewed-by: Stefan Hajnoczi <stefanha@redhat.com>
Signed-off-by: Dr. David Alan Gilbert <dgilbert@redhat.com>
Diffstat (limited to 'util/qemu-timer.c')
0 files changed, 0 insertions, 0 deletions