diff options
author | Henrique de Moraes Holschuh <hmh@hmh.eng.br> | 2010-02-25 20:22:22 -0500 |
---|---|---|
committer | Henrique de Moraes Holschuh <hmh@hmh.eng.br> | 2010-02-25 20:22:22 -0500 |
commit | b525c06cdbd8a3963f0173ccd23f9147d4c384b5 (patch) | |
tree | 025b22fda39fc7a42061ab25a908abe3ae757d3b /drivers/platform/x86/Kconfig | |
parent | 08fedfc903c78e380b0baa7b57c52d367794d0a5 (diff) |
thinkpad-acpi: lock down video output state access
Given the right combination of ThinkPad and X.org, just reading the
video output control state is enough to hard-crash X.org.
Until the day I somehow find out a model or BIOS cut date to not
provide this feature to ThinkPads that can do video switching through
X RandR, change permissions so that only processes with CAP_SYS_ADMIN
can access any sort of video output control state.
This bug could be considered a local DoS I suppose, as it allows any
non-privledged local user to cause some versions of X.org to
hard-crash some ThinkPads.
Reported-by: Jidanni <jidanni@jidanni.org>
Signed-off-by: Henrique de Moraes Holschuh <hmh@hmh.eng.br>
Cc: stable@kernel.org
Diffstat (limited to 'drivers/platform/x86/Kconfig')
-rw-r--r-- | drivers/platform/x86/Kconfig | 10 |
1 files changed, 8 insertions, 2 deletions
diff --git a/drivers/platform/x86/Kconfig b/drivers/platform/x86/Kconfig index f526e735c5ab..11fce79b61d1 100644 --- a/drivers/platform/x86/Kconfig +++ b/drivers/platform/x86/Kconfig | |||
@@ -319,9 +319,15 @@ config THINKPAD_ACPI_VIDEO | |||
319 | server running, phase of the moon, and the current mood of | 319 | server running, phase of the moon, and the current mood of |
320 | Schroedinger's cat. If you can use X.org's RandR to control | 320 | Schroedinger's cat. If you can use X.org's RandR to control |
321 | your ThinkPad's video output ports instead of this feature, | 321 | your ThinkPad's video output ports instead of this feature, |
322 | don't think twice: do it and say N here to save some memory. | 322 | don't think twice: do it and say N here to save memory and avoid |
323 | bad interactions with X.org. | ||
323 | 324 | ||
324 | If you are not sure, say Y here. | 325 | NOTE: access to this feature is limited to processes with the |
326 | CAP_SYS_ADMIN capability, to avoid local DoS issues in platforms | ||
327 | where it interacts badly with X.org. | ||
328 | |||
329 | If you are not sure, say Y here but do try to check if you could | ||
330 | be using X.org RandR instead. | ||
325 | 331 | ||
326 | config THINKPAD_ACPI_HOTKEY_POLL | 332 | config THINKPAD_ACPI_HOTKEY_POLL |
327 | bool "Support NVRAM polling for hot keys" | 333 | bool "Support NVRAM polling for hot keys" |