LWN.net's Journal
 
[Most Recent Entries] [Calendar View]

Friday, February 21st, 2020

    Time Event
    2:03p
    Security updates for Friday
    Security updates have been issued by CentOS (openjpeg2), Debian (cloud-init, jackson-databind, and python-reportlab), Red Hat (ksh, python-pillow, systemd, and thunderbird), Slackware (proftpd), SUSE (java-1_7_0-ibm, nodejs10, and nodejs12), and Ubuntu (ppp and squid, squid3).
    5:37p
    [$] CAP_PERFMON — and new capabilities in general
    The perf_event_open()
    system call is a complicated beast, requiring a fair amount of study to
    master. This call also has some interesting security implications: it can
    be used to obtain a lot of information about the running system, and the
    complexity of the underlying implementation has made it more than usually
    prone to unpleasant bugs. In current kernels, the security controls around
    perf_event_open() are simple, though: if you have the
    CAP_SYS_ADMIN capability, perf_event_open() is available
    to you (though the system administrator can make it available without any
    privilege at all). Some
    current work to create a new capability for the perf events subsystem would
    seem to make sense, raising the question of why adding new capabilities
    isn't done more often.

    << Previous Day 2020/02/21
    [Calendar]
    Next Day >>

LWN.net   About LJ.Rossia.org