linux-stable/security
Wang Weiyang 73adc289cd device_cgroup: Roll back to original exceptions after copy failure
commit e68bfbd3b3 upstream.

When add the 'a *:* rwm' entry to devcgroup A's whitelist, at first A's
exceptions will be cleaned and A's behavior is changed to
DEVCG_DEFAULT_ALLOW. Then parent's exceptions will be copyed to A's
whitelist. If copy failure occurs, just return leaving A to grant
permissions to all devices. And A may grant more permissions than
parent.

Backup A's whitelist and recover original exceptions after copy
failure.

Cc: stable@vger.kernel.org
Fixes: 4cef7299b4 ("device_cgroup: add proper checking when changing default behavior")
Signed-off-by: Wang Weiyang <wangweiyang2@huawei.com>
Reviewed-by: Aristeu Rozanski <aris@redhat.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2023-01-07 12:07:37 +01:00
..
apparmor apparmor: enforce nullbyte at end of tag string 2019-07-10 09:55:29 +02:00
integrity ima: Fix misuse of dereference of pointer in template_desc_init_fields() 2023-01-07 12:07:16 +01:00
keys KEYS: trusted: Fix migratable=1 failing 2021-03-03 17:44:42 +01:00
loadpin
selinux selinux: fix inode_doinit_with_dentry() LABEL_INVALID error handling 2022-08-25 11:09:22 +02:00
smack security,selinux,smack: kill security_task_wait hook 2022-07-29 17:05:44 +02:00
tomoyo TOMOYO: fix __setup handlers return values 2022-04-20 09:06:35 +02:00
yama Yama: Check for pid death before checking ancestry 2019-01-23 08:10:54 +01:00
Kconfig KPTI: Rename to PAGE_TABLE_ISOLATION 2018-01-05 15:46:35 +01:00
Makefile
commoncap.c exec: Always set cap_ambient in cap_bprm_set_creds 2020-06-03 08:16:41 +02:00
device_cgroup.c device_cgroup: Roll back to original exceptions after copy failure 2023-01-07 12:07:37 +01:00
inode.c Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/viro/vfs 2016-10-10 20:16:43 -07:00
lsm_audit.c dump_common_audit_data(): fix racy accesses to ->d_name 2021-01-23 15:38:17 +01:00
min_addr.c
security.c security,selinux,smack: kill security_task_wait hook 2022-07-29 17:05:44 +02:00