Skip to content
Snippets Groups Projects
user avatar
Stephen Smalley authored
Prohibit all but a specific set of whitelisted domains
from writing to /data/dalvik-cache.  This is to prevent
code injection into apps, zygote, or system_server.

Inspired by:
https://www.nowsecure.com/blog/2015/06/16/remote-code-execution-as-system-user-on-samsung-phones/


which depended on system UID apps having write access to
/data/dalvik-cache (not allowed in AOSP policy but evidently
in those device policies).  Prevent this from recurring.

Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
(cherry picked from commit d9bf7b3f)

Change-Id: I9219ddc3af44c909af90ba694e96565f99d8190c
1bcff87c
Name Last commit Last update