tech-kern archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: pass-through linux ioctl for mfi(4)



On Sun, Sep 16, 2012 at 03:23:22PM +0200, Manuel Bouyer wrote:
> Hello,
> the attached patch adds a pass-through ioctl interface, with the
> necessery linux compat code, for mfi(4). This allows to run the
> linux binary of the MegaCLI tool provided by LSI logic.

This ioctl is extremely dangerous.  The driver passes the command
to the device firmware with no parsing or access control of any
kind.  Are we really sure we want to support this?  It is a
truly gaping security hole.

Thor


Home | Main Index | Thread Index | Old Index