Skip to content

linux: std::process, insecure dropping of ancillary groups #88716

Description

@bnoordhuis

Commit 22ddcd1 made libstd drops ancillary groups when uid == 0:

if libc::getuid() == 0 && self.get_groups().is_none() {
cvt(libc::setgroups(0, ptr::null()))?;
}

Before that it unconditionally dropped group membership.

The new logic is wrong on Linux: it doesn't account for processes whose uid != 0 but have the CAP_SETGID capability.

Such processes can and should drop ancillary groups, otherwise child processes inherit permissions they otherwise wouldn't have.

Suggested change:

if self.get_groups().is_none() {
    let _ = libc::setgroups(0, ptr::null()); // or return unless EPERM
}

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

A-processArea: `std::process` and `std::env`C-bugCategory: This is a bug.O-linuxOperating system: LinuxO-unixOperating system: Unix-likeT-libsRelevant to the library team, which will review and decide on the PR/issue.disposition-mergeThis issue / PR is in PFCP or FCP with a disposition to merge it.finished-final-comment-periodThe final comment period is finished for this PR / Issue.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions