drivers/efuse/efuse: Drivers Registered With World Write Permissions(Part 1)

Description:

In kernel builds, any unprivileged process running on the NuttX device
can open /dev/efuse and attempt to read/write fuse content. Reading the
fuses may provide valuable information to an attacker controlling the user
process. The write operation, in extreme cases where the fuse blocks are
not locked, may brick the device.

This is part of https://github.com/apache/nuttx/issues/19410

Compiles ok.

Signed-off-by: Catalin Visinescu <catalin_visinescu@yahoo.com>
This commit is contained in:
Catalin Visinescu 2026-07-12 03:13:00 -04:00 committed by Alin Jerpelea
parent 0d2993dd87
commit 8d2b71d127
75 changed files with 85 additions and 85 deletions

View file

@ -1174,7 +1174,7 @@ static int csefree(FAR struct csession *cse)
void devcrypto_register(void)
{
register_driver("/dev/crypto", &g_cryptoops, 0666, NULL);
register_driver("/dev/crypto", &g_cryptoops, 0660, NULL);
#ifdef CONFIG_CRYPTO_CRYPTODEV_SOFTWARE_CRYPTO
swcr_init();