bk99.de entertain the web since 1997

More secure temporary files for Linux

Summary

In 2013 Linux 3.11 allowed temporary files that are not visible in the file system at all. For this purpose the open() and openat() system calls received the O_TMPFILE flag. This removes the basis for attacks in which attackers gain higher privileges via predictable names of temporary files, for example using symlinks.

Ideas

  • A file without a name in the directory cannot be redirected by a symlink.
  • Symlink attacks exploit predictable file names in shared directories such as /tmp.
  • If required, the file can still be given a name later using linkat().

Insights

  • Some classes of bugs are better eliminated by a new interface than by many individual fixes.
  • Security also comes from taking away the names attackers aim at.

Facts

  • O_TMPFILE was introduced with Linux 3.11.
  • The extension concerned the open() and openat() system calls.

References

Critique

  • The report does not explain that O_TMPFILE requires support from the file system in question.

Recommendations

  • For temporary files, use O_TMPFILE or mkstemp() instead of home-made file names.
  • Give services private /tmp directories, for example via PrivateTmp in systemd.

Read the original article

Search the Web Archive