[Bug dynamic-link/34360] Harden dynamic-loader resolution of $ORIGIN DST for setuid/setgid binaries
fweimer at redhat dot com
sourceware-bugzilla@sourceware.org
Tue Jul 7 11:52:55 GMT 2026
https://sourceware.org/bugzilla/show_bug.cgi?id=34360
Florian Weimer <fweimer at redhat dot com> changed:
What |Removed |Added
----------------------------------------------------------------------------
CC| |fweimer at redhat dot com
--- Comment #3 from Florian Weimer <fweimer at redhat dot com> ---
Has this be categorized correctly? If the secure directory check can be
bypassed by hard-linking a valid binary into a subdirectory of /tmp, that looks
like a security bug to me. Running with fs.protected_hardlinks is not a
required kernel configuration for glibc, after all.
--
You are receiving this mail because:
You are on the CC list for the bug.
More information about the Glibc-bugs
mailing list