diff options
author | Tom Marshall <tdm.code@gmail.com> | 2017-04-28 22:46:37 +0000 |
---|---|---|
committer | Andreas Blaesius <skate4life@gmx.de> | 2017-06-07 15:23:16 +0000 |
commit | 6bd3eaad59ab6a02de1387a341b56bcf49fc1998 (patch) | |
tree | d7d103a91ab70451c8bf6f466519848f0efa4595 /firmware/radeon | |
parent | 111f43bf5162b3160c2c46fb06651094a3e00f26 (diff) | |
download | kernel_samsung_tuna-6bd3eaad59ab6a02de1387a341b56bcf49fc1998.tar.gz kernel_samsung_tuna-6bd3eaad59ab6a02de1387a341b56bcf49fc1998.tar.bz2 kernel_samsung_tuna-6bd3eaad59ab6a02de1387a341b56bcf49fc1998.zip |
kernel: Only expose su when daemon is running
It has been claimed that the PG implementation of 'su' has security
vulnerabilities even when disabled. Unfortunately, the people that
find these vulnerabilities often like to keep them private so they
can profit from exploits while leaving users exposed to malicious
hackers.
In order to reduce the attack surface for vulnerabilites, it is
therefore necessary to make 'su' completely inaccessible when it
is not in use (except by the root and system users).
Change-Id: Ia7d50ba46c3d932c2b0ca5fc8e9ec69ec9045f85
Adapted from https://review.lineageos.org/#/c/170648
Used @stargo's PF_SU/PF_FREEZER_NOSIG overlap fix
Signed-off-by: D. Andrei Măceș <dmaces@nd.edu>
Diffstat (limited to 'firmware/radeon')
0 files changed, 0 insertions, 0 deletions