Re: Chroot bug

From: Jan Engelhardt
Date: Tue Sep 25 2007 - 11:48:57 EST

On Sep 26 2007 01:11, David Newall wrote:
> Jan Engelhardt wrote:
>> On Sep 26 2007 00:40, David Newall wrote:
>> > Miloslav Semler pointed out that a root process can chdir("..") out of its
>> > chroot.
>> So what? Just do this: chdir into the root after chroot.
> I don't think so. His exploit just got me all the way out of a chroot within a
> chroot within a chroot, inclusive of lots of chdirs.

Close all fds that point to directories outside the root ;-)

To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at
Please read the FAQ at