** Information type changed from Private to Public ** Description changed:
[Description] - Avoid symlink-based pidfile clobbering by opening the pidfile with - O_NOFOLLOW and validating it with fstat() before locking/writing. - - The daemon currently uses a fixed pidfile path under /tmp. A local - unprivileged user can pre-create a symlink at that path and cause a - root-run daemon instance to write into an attacker-chosen file. + Avoid symlink-based pidfile clobbering by opening the pidfile with + O_NOFOLLOW and validating it with fstat() before locking/writing. + + The daemon currently uses a fixed pidfile path under /tmp. A local + unprivileged user can pre-create a symlink at that path and cause a + root-run daemon instance to write into an attacker-chosen file. [Hardware Information] - Architecture: - Intel / AMD (x86_64) - Platform(s): - Platform-Independent - Date HW is expected at Canonical: - - Component(s): - Tools-Power + Architecture: + Intel / AMD (x86_64) + Platform(s): + Platform-Independent + Date HW is expected at Canonical: + + Component(s): + Tools-Power [Software Information] - Target Version: - 26.04 - Target Kernel: - 7.2 - Commit IDs: - 607af438e643 tools/power/x86/intel-speed-select: Harden daemon pidfile open - External Links: - + Target Version: + 26.04 + Target Kernel: + Landed in kernel 7.2, request backport to 7.0 + Commit IDs: + 607af438e643 tools/power/x86/intel-speed-select: Harden daemon pidfile open + External Links: [Business Justification] - [Testing guidance] - [External ID] - LFE-18859 + LFE-18859 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2165801 Title: tools: power: ISST: Fix intel-speed-select daemon pid file handling To manage notifications about this bug go to: https://bugs.launchpad.net/intel/+bug/2165801/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
