Popis
In the Linux kernel, the following vulnerability has been resolved: unshare: fix unshare_fs() handling There-s an unpleasant corner case in unshare(2), when we have a CLONE_NEWNS in flags and current->fs hadn-t been shared at all; in that case copy_mnt_ns() gets passed current->fs instead of a private copy, which causes interesting warts in proof of correctness] > I guess if private means fs->users == 1, the condition could still be true. Unfortunately, it-s worse than just a convoluted proof of correctness. Consider the case when we have CLONE_NEWCGROUP in addition to CLONE_NEWNS (and current->fs->users == 1). We pass current->fs to copy_mnt_ns(), all right. Suppose it succeeds and flips current->fs->{pwd,root} to corresponding locations in the new namespace. Now we proceed to copy_cgroup_ns(), which fails (e.g. with -ENOMEM). We call put_mnt_ns() on the namespace created by copy_mnt_ns(), it-s destroyed and its mount tree is dissolved, but... current->fs->root and current->fs->pwd ar...
- Zverejnené
- 2026-05-08 15:17:00
- Dotknuté verzie
- unknown
- Typ
- Core software
- Vektor
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Operačné systémy
- Linux