posix_acl: Clear SGID bit when setting file permissions
authorJan Kara <jack@suse.cz>
Mon, 19 Sep 2016 15:39:09 +0000 (17:39 +0200)
committerManish Tuteja <mtuteja@nvidia.com>
Mon, 17 Apr 2017 23:56:04 +0000 (16:56 -0700)
commit8c4970d07a0cacb45e9b571b25800ea972a6f9d7
tree6eb65a1058fe7c5af0db03835613a7ddae2c0745
parentbdf94e85be19fd3b91669427343d6fde4177fb83
posix_acl: Clear SGID bit when setting file permissions

When file permissions are modified via chmod(2) and the user is not in
the owning group or capable of CAP_FSETID, the setgid bit is cleared in
inode_change_ok().  Setting a POSIX ACL via setxattr(2) sets the file
permissions as well as the new ACL, but doesn't clear the setgid bit in
a similar way; this allows to bypass the check in chmod(2).  Fix that.

Bug 1887273
Bug 200288656

Change-Id: I513706c5a9f674517a340fc797fb1de6aa0c4a3f
References: CVE-2016-7097
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Jeff Layton <jlayton@redhat.com>
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
Signed-off-by: Gagan Grover <ggrover@nvidia.com>
Reviewed-on: http://git-master/r/1458111
(cherry picked from commit f6ad7afd14a181e0e2a5734242a65c1200d5ba3b)
Reviewed-on: http://git-master/r/1459849
(cherry picked from commit 9e810f23f710b3019107c4e898f009a2d45e5fde)
Reviewed-on: http://git-master/r/1463479
GVS: Gerrit_Virtual_Submit
Reviewed-by: Manish Tuteja <mtuteja@nvidia.com>
12 files changed:
fs/9p/acl.c
fs/btrfs/acl.c
fs/ext2/acl.c
fs/ext4/acl.c
fs/f2fs/acl.c
fs/gfs2/acl.c
fs/jffs2/acl.c
fs/ocfs2/acl.c
fs/posix_acl.c
fs/reiserfs/xattr_acl.c
fs/xfs/xfs_acl.c
include/linux/posix_acl.h