Re: static USERMODEHELPER_PATH

2023-01-10 Thread Lennart Poettering
On Mo, 09.01.23 15:18, Simo Sorce (s...@redhat.com) wrote: > If I remember correctly the claim was that umh is robust if the user > space fails and just terminates. As then the kernel know user space is > gone, whether it got the data it needed or not and can stop waiting. > > While messages may

Re: static USERMODEHELPER_PATH

2023-01-09 Thread Simo Sorce
On Fri, 2023-01-06 at 18:21 +0100, Lennart Poettering wrote: > On Fr, 06.01.23 10:10, Steve Grubb (sgr...@redhat.com) wrote: > > > Hello, > > > > On Friday, January 6, 2023 9:33:12 AM EST Lennart Poettering wrote: > > > On Do, 05.01.23 20:17, Steve Grubb (sgr...@redhat.com) wrote: > > > > I work

Re: static USERMODEHELPER_PATH

2023-01-06 Thread Lennart Poettering
On Fr, 06.01.23 10:10, Steve Grubb (sgr...@redhat.com) wrote: > Hello, > > On Friday, January 6, 2023 9:33:12 AM EST Lennart Poettering wrote: > > On Do, 05.01.23 20:17, Steve Grubb (sgr...@redhat.com) wrote: > > > I work on RHEL security problems. I have been looking into a number of > > >

Re: static USERMODEHELPER_PATH

2023-01-06 Thread Steve Grubb
Hello, On Friday, January 6, 2023 10:10:21 AM EST Steve Grubb wrote: > One approach to solving this is to use selinux policy. I was informed > overnight that policy 38.2-1 should now enforce kernel transitions to > specific helper applications. So, maybe this is solved well enough? I can verify

Re: static USERMODEHELPER_PATH

2023-01-06 Thread Steve Grubb
Hello, On Friday, January 6, 2023 9:33:12 AM EST Lennart Poettering wrote: > On Do, 05.01.23 20:17, Steve Grubb (sgr...@redhat.com) wrote: > > I work on RHEL security problems. I have been looking into a number of > > exploits and I think we have a problem that has an easy fix. We are not > >

Re: static USERMODEHELPER_PATH

2023-01-06 Thread Lennart Poettering
On Do, 05.01.23 20:17, Steve Grubb (sgr...@redhat.com) wrote: > Hello, > > I work on RHEL security problems. I have been looking into a number of > exploits and I think we have a problem that has an easy fix. We are not using > the CONFIG_STATIC_USERMODEHELPER_PATH kernel config option. There are

Re: static USERMODEHELPER_PATH

2023-01-05 Thread Ian Kent
On 6/1/23 10:12, Steve Grubb wrote: Hello, I want to add some missing information... On Thursday, January 5, 2023 8:43:34 PM EST Ian Kent wrote: On 6/1/23 09:17, Steve Grubb wrote: I work on RHEL security problems. I have been looking into a number of exploits and I think we have a problem

Re: static USERMODEHELPER_PATH

2023-01-05 Thread Steve Grubb
Hello, I want to add some missing information... On Thursday, January 5, 2023 8:43:34 PM EST Ian Kent wrote: > On 6/1/23 09:17, Steve Grubb wrote: > > I work on RHEL security problems. I have been looking into a number of > > exploits and I think we have a problem that has an easy fix. Here's

Re: static USERMODEHELPER_PATH

2023-01-05 Thread Ian Kent
On 6/1/23 09:17, Steve Grubb wrote: Hello, I work on RHEL security problems. I have been looking into a number of exploits and I think we have a problem that has an easy fix. We are not using the CONFIG_STATIC_USERMODEHELPER_PATH kernel config option. There are a number of exploits that

static USERMODEHELPER_PATH

2023-01-05 Thread Steve Grubb
Hello, I work on RHEL security problems. I have been looking into a number of exploits and I think we have a problem that has an easy fix. We are not using the CONFIG_STATIC_USERMODEHELPER_PATH kernel config option. There are a number of exploits that overwrite the path to modprobe and then