[PATCH] decnet: Disable auto-loading as mitigation against local exploits
authorBen Hutchings <ben@decadent.org.uk>
Sat, 20 Nov 2010 02:24:55 +0000 (02:24 +0000)
committerSalvatore Bonaccorso <carnil@debian.org>
Tue, 18 Jan 2022 21:31:03 +0000 (21:31 +0000)
commit8471b181f0f1278d1da04f6bb6293f3f37fc8d3e
treed5b67163a3b5a7b8002f3d09cfef1cf3e8fcf693
parent4cd8c82cef863a3b4feb7b8c3502dfcd7bdaa8d5
[PATCH] decnet: Disable auto-loading as mitigation against local exploits

Forwarded: not-needed

Recent review has revealed several bugs in obscure protocol
implementations that can be exploited by local users for denial of
service or privilege escalation.  We can mitigate the effect of any
remaining vulnerabilities in such protocols by preventing unprivileged
users from loading the modules, so that they are only exploitable on
systems where the administrator has chosen to load the protocol.

The 'decnet' protocol is unmaintained and of mostly historical
interest, and the user-space support package 'dnet-common' loads the
module explicitly.  Therefore disable auto-loading.

Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Gbp-Pq: Topic debian
Gbp-Pq: Name decnet-Disable-auto-loading-as-mitigation-against-lo.patch
net/decnet/af_decnet.c