Re: [PATCH] virtiofsd: prevent opening of special files (CVE-2020-35517)

2021-01-21 Thread alex--- via
Excerpts from Laszlo Ersek's message of January 21, 2021 10:32 am: > Assuming a benign / trusted guest, is there going to be an override for > this? > > Asked differently -- if we don't want to set up a separate block device > on the host, to contain the filesystem that is mounted as the shared >

Re: [PATCH] virtiofsd: prevent opening of special files (CVE-2020-35517)

2021-01-21 Thread alex--- via
Excerpts from Stefan Hajnoczi's message of January 21, 2021 9:44 am: > A well-behaved FUSE client does not attempt to open special files with > FUSE_OPEN because they are handled on the client side (e.g. device nodes > are handled by client-side device drivers). > > The check to prevent virtiofsd