More secure temporary files for Linux
Summary
In 2013 Linux 3.11 allowed temporary files that are not visible in the file system at all. For this purpose the open() and openat() system calls received the O_TMPFILE flag. This removes the basis for attacks in which attackers gain higher privileges via predictable names of temporary files, for example using symlinks.
Ideas
- A file without a name in the directory cannot be redirected by a symlink.
- Symlink attacks exploit predictable file names in shared directories such as /tmp.
- If required, the file can still be given a name later using linkat().
Insights
- Some classes of bugs are better eliminated by a new interface than by many individual fixes.
- Security also comes from taking away the names attackers aim at.
Facts
- O_TMPFILE was introduced with Linux 3.11.
- The extension concerned the open() and openat() system calls.
References
Critique
- The report does not explain that O_TMPFILE requires support from the file system in question.
Recommendations
- For temporary files, use O_TMPFILE or mkstemp() instead of home-made file names.
- Give services private /tmp directories, for example via PrivateTmp in systemd.
Links to the original source and the Web Archive open in a new tab.