From f64062b1f74ad5ee20a8a49aab2732efd0f7ce30 Mon Sep 17 00:00:00 2001 From: Damien Miller Date: Fri, 20 May 2016 09:56:53 +1000 Subject: [PATCH] Deny lstat syscalls in seccomp sandbox Avoids sandbox violations for some krb/gssapi libraries. --- sandbox-seccomp-filter.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/sandbox-seccomp-filter.c b/sandbox-seccomp-filter.c index d132e2646..2e1ed2c52 100644 --- a/sandbox-seccomp-filter.c +++ b/sandbox-seccomp-filter.c @@ -103,6 +103,12 @@ static const struct sock_filter preauth_insns[] = { offsetof(struct seccomp_data, nr)), /* Syscalls to non-fatally deny */ +#ifdef __NR_lstat + SC_DENY(lstat, EACCES), +#endif +#ifdef __NR_lstat64 + SC_DENY(lstat64, EACCES), +#endif #ifdef __NR_fstat SC_DENY(fstat, EACCES), #endif