News: 0001653675

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

eCryptfs Sees Fixes For Potential Malicious Intent, Some Dating Back To Its 2006 Debut

([Linux Storage] 4 Hours Ago eCryptfs)


The eCryptfs stacked cryptographic filesystem implementation for the Linux kernel to transparently encrypt files saw a number of bug fixes for the Linux 7.3 kernel. A number of these bug fixes deal with potential maliciously-crafted data and vulnerable going back to the 2006 introduction of eCryptfs as this option known for its use on Ubuntu home directory encryption and Chrome OS.

The eCryptfs code is now hardened and fixed against maliciously crafted metadata in the lower encrypted file. There is also hardening and fixes for malicious kernel to/from user-space miscdev communication. There are also locking fixes, a fix for displaying encrypted filename related mount options, avoiding unnecessary memory allocations, and other improvements.

Some of these security fixes date back to commit 237fead61998, which is when eCryptfs was being introduced to the mainline kernel all the way back in 2006. At least some of these bugs appear to have been uncovered using AI tooling.

More details on these eCryptfs fixes for Linux 7.3 can be found via [1]this pull request .



[1] https://lore.kernel.org/lkml/aoeaX-Z7eSZuYP1A@elm/



Mike's Law:
For a lumber company employing two men and a cut-off saw, the
marginal product of labor for any number of additional workers
equals zero until the acquisition of another cut-off saw.
Let's not even consider a chainsaw.
-- Mike Dennison
[You could always schedule the saw, though - ed.]