ring-buffer: Prevent overflow of size in ring_buffer_resize()
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / kernel / user_namespace.c
index 9da8cbbcd9859537059c543b1ceb5bc826e0fee3..3f2fb33d291aa8739ab09a2f63d090695787c765 100644 (file)
@@ -814,6 +814,11 @@ static bool new_idmap_permitted(const struct file *file,
                        kuid_t uid = make_kuid(ns->parent, id);
                        if (uid_eq(uid, cred->euid))
                                return true;
+               } else if (cap_setid == CAP_SETGID) {
+                       kgid_t gid = make_kgid(ns->parent, id);
+                       if (!(ns->flags & USERNS_SETGROUPS_ALLOWED) &&
+                           gid_eq(gid, cred->egid))
+                               return true;
                }
        }