Proxying Wayland for security

Simon Ser contact at emersion.fr
Wed Jul 28 09:51:53 UTC 2021


Please read the (lengthy) discussion at [1].

[1]: https://gitlab.freedesktop.org/wayland/weston/-/issues/206

In particular, the "get_credentials → PID → executable path" lookup is
racy. PID re-use allows a malicious process to be recognized as another
executable.


More information about the wayland-devel mailing list