> LPE: On distributions such as RHEL, /dev/kvm is world-writable (0666), so an unprivileged user can also use this vulnerability as a reliable LPE to gain root.
Why on Linux device files are accessible by untrusted applications?
Why on Linux device files are accessible by untrusted applications?
Would they potentially be a solution to sudo's all-or-nothing granularity in this domain?
Which is precisely why many kinds of kernel feature should be exposed as operations on device nodes, not as system calls usable out of thin air. UGO and ACL permissions work on device nodes!
So as a responsible user I am slowly writing my own sandboxes, struggling with lack of documentation and designing workarounds.
That's been the case forever: /dev/null, /dev/zero, /dev/stdin, ...
2: Because it's desirable for users to be able to run VMs.