The higher ptrace restriction levels should be blocking even PTRACE_TRACEME requests. The comments in the LSM documentation are misleading about when the checks happen (the parent does not go through security_ptrace_access_check() on a PTRACE_TRACEME call). Signed-off-by: Kees Cook <keescook@chromium.org> Cc: stable@vger.kernel.org # 3.5.x and later Signed-off-by: James Morris <james.l.morris@oracle.com> |
||
|---|---|---|
| .. | ||
| 00-INDEX | ||
| apparmor.txt | ||
| credentials.txt | ||
| keys-ecryptfs.txt | ||
| keys-request-key.txt | ||
| keys-trusted-encrypted.txt | ||
| keys.txt | ||
| LSM.txt | ||
| SELinux.txt | ||
| Smack.txt | ||
| tomoyo.txt | ||
| Yama.txt | ||