On Wed, 3 Oct 2012 13:05:15 -0700 Kees Cook <k...@outflux.net> wrote:
> Hi Nick, > > 3.6 introduced link restrictions: > http://git.kernel.org/?p=linux/kernel/git/torvalds/linux.git;a=commitdiff;h=800179c9b8a1e796e441674776d11cd4c05d61d7 > > It sounds like you've got symlinks in a world-writable directory, and > you're following those symlinks across mis-matched uids. You can either > have the symlinks be owned by the directory owner, or you can turn off > symlink restrictions in sysctl: > > # echo 0 > /proc/sys/fs/protected_symlinks Quite honestly that should be pushed for 3.6.1 as a default - ASAP. Alan -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majord...@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/