Skip to content
Unverified Commit 7e70cb96 authored by Paul Wise's avatar Paul Wise
Browse files

Handle older versions of the Linux kernel in a safer way

The Linux kernel does argument splitting after parameter expansion,
leading to an attacker on old kernels being able control the owner
variable, leading to the creation of bogus root-owned directories.

Fixes: https://bugs.debian.org/924398


Reported-by: Jakub Wilk's avatarJakub Wilk <jwilk@jwilk.net>
Reported-in: <20190312145043.jxjoj66kqssptolr@jwilk.net>
parent cd9ac9d4
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment