forked from luck/tmp_suning_uos_patched
7303515ae4
When making access control choices from a file-based context, f_cred must be used instead of current_cred() to avoid confused deputy attacks where an open file may get passed to a more privileged process. Add a short paragraph to explicitly state the rationale. Cc: Jonathan Corbet <corbet@lwn.net> Cc: linux-doc@vger.kernel.org Signed-off-by: Kees Cook <keescook@chromium.org> Link: https://lore.kernel.org/r/202007031038.8833A35DE4@keescook Signed-off-by: Jonathan Corbet <corbet@lwn.net> |
||
---|---|---|
.. | ||
keys | ||
tpm | ||
credentials.rst | ||
digsig.rst | ||
IMA-templates.rst | ||
index.rst | ||
lsm-development.rst | ||
lsm.rst | ||
sak.rst | ||
SCTP.rst | ||
self-protection.rst | ||
siphash.rst |