[gnome-desktop/gnome-3-26] thumbnailer: fix incomplete TIOCSTI filtering



commit e93ab93c33fc0fbbdb28e8014e6ca18791ed9896
Author: Michael Catanzaro <mcatanzaro igalia com>
Date:   Sat Apr 13 13:57:36 2019 -0500

    thumbnailer: fix incomplete TIOCSTI filtering
    
    Fixes #112
    
    See also: https://github.com/flatpak/flatpak/issues/2782

 libgnome-desktop/gnome-desktop-thumbnail-script.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
---
diff --git a/libgnome-desktop/gnome-desktop-thumbnail-script.c 
b/libgnome-desktop/gnome-desktop-thumbnail-script.c
index 99d83ac2..f61bf59d 100644
--- a/libgnome-desktop/gnome-desktop-thumbnail-script.c
+++ b/libgnome-desktop/gnome-desktop-thumbnail-script.c
@@ -333,7 +333,7 @@ setup_seccomp (GPtrArray  *argv_array,
     {SCMP_SYS (clone), &SCMP_A0 (SCMP_CMP_MASKED_EQ, CLONE_NEWUSER, CLONE_NEWUSER)},
 
     /* Don't allow faking input to the controlling tty (CVE-2017-5226) */
-    {SCMP_SYS (ioctl), &SCMP_A1(SCMP_CMP_EQ, (int)TIOCSTI)},
+    {SCMP_SYS (ioctl), &SCMP_A1(SCMP_CMP_MASKED_EQ, 0xFFFFFFFFu, (int)TIOCSTI)},
   };
 
   struct


[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]