efi-lockdown patch causes -EPERM for some debugfs files even though CONFIG_LOCK_DOWN_KERNEL is not set
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Ubuntu on IBM z Systems |
Fix Released
|
High
|
Canonical Kernel Team | ||
linux (Ubuntu) |
Fix Released
|
Undecided
|
Kamal Mostafa | ||
Cosmic |
Fix Released
|
Undecided
|
Kamal Mostafa | ||
Disco |
Fix Released
|
Undecided
|
Kamal Mostafa |
Bug Description
== Comment: #0 - Dominik Klein <email address hidden> - 2018-12-10 03:58:10 ==
There seems to be a bug in the efi-lockdown patch as applied on top of vanilla for Cosmic kernels:
http://
Also seems to be present for Disco as of today:
http://
The problem is that part of the patch modifies kernel behavior independently of CONFIG_
Vasily Gorbik has already analyzed the problem and has posted a proposed fix here:
https:/
https:/
CVE References
tags: | added: architecture-s39064 bugnameltc-173993 severity-high targetmilestone-inin--- |
Changed in ubuntu: | |
assignee: | nobody → Skipper Bug Screeners (skipper-screen-team) |
affects: | ubuntu → kernel-package (Ubuntu) |
affects: | kernel-package (Ubuntu) → linux (Ubuntu) |
Changed in ubuntu-z-systems: | |
status: | New → Triaged |
importance: | Undecided → High |
assignee: | nobody → Canonical Kernel Team (canonical-kernel-team) |
Changed in linux (Ubuntu): | |
status: | New → In Progress |
Changed in linux (Ubuntu Cosmic): | |
status: | New → In Progress |
assignee: | nobody → Kamal Mostafa (kamalmostafa) |
Changed in linux (Ubuntu Disco): | |
assignee: | Skipper Bug Screeners (skipper-screen-team) → Kamal Mostafa (kamalmostafa) |
Changed in linux (Ubuntu Disco): | |
status: | In Progress → Fix Committed |
Changed in linux (Ubuntu Cosmic): | |
status: | In Progress → Fix Committed |
Changed in ubuntu-z-systems: | |
status: | Triaged → Fix Committed |
Changed in ubuntu-z-systems: | |
status: | Fix Committed → Fix Released |
------- Comment From <email address hidden> 2018-12-10 05:24 EDT-------
This problem was introduced with 18.10...