7 ms·
> Routine unix sockets are just some file in /tmp which an attacker could likewise open by racing against the daemon in the same way. So put the socket in /run
by adrianmonk 2y ago
> Routine unix sockets are just some file in /tmp which an attacker could likewise open by racing against the daemon in the same way.
So put the socket in /run instead of /tmp?
I'm no expert, but this appears to be where they belong, and it appears to solve the problem. From https://refspecs.linuxfoundation.org/FHS_3.0/fhs/ch03s15.html https://refspecs.linuxfoundation.org/FHS_3.0/fhs/ch03s15.htm... : "System programs that maintain transient UNIX-domain sockets must place them in this directory or an appropriate subdirectory as outlined above." ... "/run should not be writable for unprivileged users; it is a major security problem if any user can write in this directory."
- ajross 2y agoPutting them in /run if you're not already root requires a little extra software be written though. Locking down a TCP socket isn't much harder. I'm not saying "don't use Unix domain sockets", I'm saying that treating this bug as the result of technology choice is bad security analysis.
- Zardoz84 2y agoThe real problem is the buggy parser, and that is enabled by default, even if you aren't showing anything related to the GPU or launched the daemon.
- adrianmonk 2y ago> if you're not already root Hmm, good point. I think we made opposite assumptions about that. If the daemon does run as a root, then no extra software is required. For Unix domain sockets, you can trivially create your socket in /run, and for TCP, you can trivially use a port below 1024. If it doesn't, then some extra software or configuration is required in either case. I tried looking it up, and I think it does run as root[1]. But I also found that the daemon uses a Python library to get GPU stats, and root might or might not be required depending on how the GPU software is configured[2]. So it could have gone either way. --- [1] That's how I read this: https://github.com/Atoptool/atop/blob/master/atopgpu.service https://github.com/Atoptool/atop/blob/master/atopgpu.service [2] See https://github.com/gpuopenanalytics/pynvml/issues/19 https://github.com/gpuopenanalytics/pynvml/issues/19