[PATCH] Ignore LD_POINTER_GUARD for set-user-ID/set-group-ID binaries.

Mike Frysinger vapier@gentoo.org
Sun Oct 11 00:11:00 GMT 2015


On 09 Oct 2015 21:59, Carlos O'Donell wrote:
> On 10/08/2015 04:44 AM, Florian Weimer wrote:
> > On 09/05/2015 06:39 PM, Hector Marco-Gisbert wrote:
> >> A weakness in the dynamic loader have been found, Glibc prior to
> >> 2.22.90 are affected. The issue is that the LD_POINTER_GUARD in the
> >> environment is not sanitized allowing local attackers easily to bypass
> >> the pointer guarding protection on set-user-ID and set-group-ID
> >> programs. 
> >>
> >> Details of the weakness:
> >> http://hmarco.org/bugs/glibc_ptr_mangle_weakness.html
> >>
> >> This patch prevents to disable the pointer guarding protection for
> >> set-user-ID/set-group-ID programs.
> >>
> >> For example, executing "LD_POINTER_GUARD=0 /bin/ping" does not disable
> >> the pointer guarding protection unless it is directly executed by root
> >> (rUID==eUID).
> > 
> > Does anyone actually use LD_POINTER_GUARD for debugging?  Maybe we can
> > simply retire the environment variable instead.
> 
> I vote we remove it. It has long since passed the point of usefullness.
> With a proper tunables infrastructure we would have added it in one release
> while we tested things, and then removed it one or two releases later.

sounds fine to me.  punt it and be done.
-mike
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: Digital signature
URL: <http://sourceware.org/pipermail/libc-alpha/attachments/20151011/e289e002/attachment.sig>


More information about the Libc-alpha mailing list