On Sep 25 2007 18:19, Miloslav Semler wrote: >> > > So what? Just do this: chdir into the root after chroot. >> > > >> > I don't think so. His exploit just got me all the way out of a chroot >> > within a >> > chroot within a chroot, inclusive of lots of chdirs. >> > >> >> Close all fds that point to directories outside the root ;-) >> > This does not help. Let's try: > chroot somewhere > mkdir foo > fd = open / > chroot foo ('fd' implicitly closed and chdir to /foo) > fchdir fd -EINVAL > chdir ".." /../ => / > .... > chdir ".." > chroot "." > so you are in root. so we remain in chroot. - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to [email protected] More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
- Follow-Ups:
- Re: Chroot bug
- From: Miloslav Semler <[email protected]>
- Re: Chroot bug
- References:
- Re: sys_chroot+sys_fchdir Fix
- From: "Philipp Marek" <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: Philipp Marek <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: Bill Davidsen <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: "Serge E. Hallyn" <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: "Serge E. Hallyn" <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: "Serge E. Hallyn" <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <[email protected]>
- Chroot bug (was: sys_chroot+sys_fchdir Fix)
- From: David Newall <[email protected]>
- Re: Chroot bug (was: sys_chroot+sys_fchdir Fix)
- From: Jan Engelhardt <[email protected]>
- Re: Chroot bug
- From: David Newall <[email protected]>
- Re: Chroot bug
- From: Jan Engelhardt <[email protected]>
- Re: Chroot bug
- From: Miloslav Semler <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- Prev by Date: Re: Xen kernel 2.6.23-rc7 bug at xen_mc_flush (arch/i386/xen/multicalls.c:68)
- Next by Date: Re: [PATCH 1/1] Kernel compile bug in 2.6.22.6/7 {maybe more} ARM/StrongARM
- Previous by thread: Re: Chroot bug
- Next by thread: Re: Chroot bug
- Index(es):