[BRLTTY] Lacking privilege separation on Linux regarding the brltty service user

2023-12-13 Thread matthias . gerstner
Hello list, I am a security engineer with the SUSE Linux security team. We have been approached with worries about the "brltty" service user being a member of the "root" group in the packaging of brltty on openSUSE Tumbleweed. Taking a closer look it turns out that brltty uses the following

Re: [BRLTTY] Lacking privilege separation on Linux regarding the brltty service user

2023-12-13 Thread Samuel Thibault
Hello, matthias.gerst...@suse.de, le mer. 13 déc. 2023 15:06:16 +0100, a ecrit: > - root: > - for USB I/O via USBFS (using the devices in /dev/bus/usb/). > - for creating virtual devices via the uinput device. > - cap_sys_admin: For injecting input characters typed on a braille