[LTP] [PATCH v2 2/2] syscalls/request_key04: new test for request_key() permission check bug

Petr Vorel pvorel@suse.cz
Wed Jan 10 12:12:30 CET 2018


> From: Eric Biggers <ebiggers@google.com>

> Add a test for a bug that allowed the request_key() system call to be
> used to add a key to a keyring using only Search permission.  This bug
> was assigned CVE-2017-17807.

> Signed-off-by: Eric Biggers <ebiggers@google.com>
> ---

LGTM both commits.
BTW it might be worth to define SAFE_KEYCTL().


Kind regards,
Petr


More information about the ltp mailing list