fuse 'default_permissions' check ignored by kernel

Bug #244319 reported by Neil Wilson
4
Affects Status Importance Assigned to Milestone
linux (Ubuntu)
New
Undecided
Unassigned

Bug Description

When mounting a fuse filesystem (such as glusterfs) with the 'default_permissions, allow_others' options, the kernel will completely ignore the default_permissions check and allow anybody to manipulate any file on the mounted filesystem.

I think this is due to a shadowing bug described here: http://readlist.com/lists/vger.kernel.org/linux-kernel/93/468712.html

I've downloaded the latest hardy kernel source and it appears that fs/fuse/dir.c remains unpatched (line 906).

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.