From 3d3186c77b105cc14779ca145ea9bb60c8e2b27f Mon Sep 17 00:00:00 2001 From: Jiri Slaby Date: Apr 13 2024 09:55:41 +0000 Subject: tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc (bsc#1222619). --- diff --git a/patches.suse/tty-n_gsm-require-CAP_NET_ADMIN-to-attach-N_GSM0710-.patch b/patches.suse/tty-n_gsm-require-CAP_NET_ADMIN-to-attach-N_GSM0710-.patch new file mode 100644 index 0000000..453b5cd --- /dev/null +++ b/patches.suse/tty-n_gsm-require-CAP_NET_ADMIN-to-attach-N_GSM0710-.patch @@ -0,0 +1,32 @@ +From: Thadeu Lima de Souza Cascardo +Date: Mon, 31 Jul 2023 15:59:42 -0300 +Subject: tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc +Git-commit: 67c37756898a5a6b2941a13ae7260c89b54e0d88 +Patch-mainline: 6.6-rc1 +References: bsc#1222619 + +Any unprivileged user can attach N_GSM0710 ldisc, but it requires +CAP_NET_ADMIN to create a GSM network anyway. + +Require initial namespace CAP_NET_ADMIN to do that. + +Signed-off-by: Thadeu Lima de Souza Cascardo +Link: https://lore.kernel.org/r/20230731185942.279611-1-cascardo@canonical.com +Signed-off-by: Greg Kroah-Hartman +Signed-off-by: Jiri Slaby +--- + drivers/tty/n_gsm.c | 3 +++ + 1 file changed, 3 insertions(+) + +--- a/drivers/tty/n_gsm.c ++++ b/drivers/tty/n_gsm.c +@@ -2933,6 +2933,9 @@ static int gsmld_open(struct tty_struct + { + struct gsm_mux *gsm; + ++ if (!capable(CAP_NET_ADMIN)) ++ return -EPERM; ++ + if (tty->ops->write == NULL) + return -EINVAL; + diff --git a/series.conf b/series.conf index 916f764..eb835ba 100644 --- a/series.conf +++ b/series.conf @@ -43712,6 +43712,7 @@ patches.suse/USB-serial-option-add-FOXCONN-T99W368-T99W373-produc.patch patches.suse/serial-sprd-Assign-sprd_port-after-initialized-to-av.patch patches.suse/serial-sprd-Fix-DMA-buffer-leak-issue.patch + patches.suse/tty-n_gsm-require-CAP_NET_ADMIN-to-attach-N_GSM0710-.patch patches.suse/serial-tegra-handle-clk-prepare-error-in-tegra_uart_.patch patches.suse/serial-sc16is7xx-fix-broken-port-0-uart-init.patch patches.suse/serial-sc16is7xx-fix-bug-when-first-setting-GPIO-dir.patch