[Bug dynamic-link/34360] Harden dynamic-loader resolution of $ORIGIN DST for setuid/setgid binaries

fweimer at redhat dot com sourceware-bugzilla@sourceware.org
Tue Jul 7 11:52:55 GMT 2026


https://sourceware.org/bugzilla/show_bug.cgi?id=34360

Florian Weimer <fweimer at redhat dot com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |fweimer at redhat dot com

--- Comment #3 from Florian Weimer <fweimer at redhat dot com> ---
Has this be categorized correctly? If the secure directory check can be
bypassed by hard-linking a valid binary into a subdirectory of /tmp, that looks
like a security bug to me. Running with fs.protected_hardlinks is not a
required kernel configuration for glibc, after all.

-- 
You are receiving this mail because:
You are on the CC list for the bug.


More information about the Glibc-bugs mailing list