[Bug dynamic-link/34360] Harden dynamic-loader resolution of $ORIGIN DST for setuid/setgid binaries

fweimer at redhat dot com via Glibc-bugs <[email protected]> Tue, 07 Jul 2026 11:52:55 +0000
Newsgroups gmane.comp.lib.glibc.bugs
Message-ID <[email protected]/bugzilla/>
https://sourceware.org/bugzilla/show_bug.cgi?id=34360

Florian Weimer <fweimer at redhat dot com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |fweimer at redhat dot com

--- Comment #3 from Florian Weimer <fweimer at redhat dot com> ---
Has this be categorized correctly? If the secure directory check can be
bypassed by hard-linking a valid binary into a subdirectory of /tmp, that looks
like a security bug to me. Running with fs.protected_hardlinks is not a
required kernel configuration for glibc, after all.

-- 
You are receiving this mail because:
You are on the CC list for the bug.