diff options
Diffstat (limited to 'Documentation')
-rw-r--r-- | Documentation/security/credentials.rst | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/Documentation/security/credentials.rst b/Documentation/security/credentials.rst index 282e79feee6a..b7482f8ccf85 100644 --- a/Documentation/security/credentials.rst +++ b/Documentation/security/credentials.rst @@ -548,6 +548,10 @@ pointer will not change over the lifetime of the file struct, and nor will the contents of the cred struct pointed to, barring the exceptions listed above (see the Task Credentials section). +To avoid "confused deputy" privilege escalation attacks, access control checks +during subsequent operations on an opened file should use these credentials +instead of "current"'s credentials, as the file may have been passed to a more +privileged process. Overriding the VFS's Use of Credentials ======================================= |